AI-generated cyber attacks to hit firms soon, warn experts
Wed, 2nd Sep 2026 (Today)
Security specialists at ArmorCode and NCC Group warned that many organisations are unprepared for a rise in AI-generated cyber attacks, echoing a broader industry warning that such attacks are likely to reach companies soon.
Both argued that the central problem is not simply identifying weaknesses but fixing them quickly enough. Security teams already face large backlogs, fragmented systems and competing internal priorities, leaving many organisations exposed if attack volumes increase.
Robbie Mueller, Technical Lead, Cybersecurity, at ArmorCode, said many companies lack the resources to match the defences of businesses built around AI. In his view, the issue is less about technical sophistication than operational capacity.
"An organization built around AI has every reason to run state of the art defenses. Most companies don't have that luxury, and that's exactly why this shouldn't be framed as an AI sophistication problem. It's a capacity problem. The average enterprise already runs more than 40 security scanners producing millions of findings, and even under normal conditions, organizations can only remediate roughly one in ten open vulnerabilities in a given month.
"Finding problems has never been easier. Fixing them is the hard part, and the obstacle is as often internal as it is technical: unclear ownership, competing priorities, and teams that don't share a queue. So if the volume and speed of what's coming increases while the ability to triage and fix stays flat, the gap doesn't just grow, it compounds.
"What matters is not the number of findings but which ones chain together into a viable path to something an attacker actually wants. Kill that path and the risk goes away, either by remediating a link in it or by putting a mitigating control in front of it. That requires a unified view across AppSec, infrastructure security, cloud security and DevSecOps, because the path almost always crosses those boundaries and these silos are exactly why nobody sees it end to end.
"To deal with the threat, the starting point isn't more tooling, it's knowing what you actually have.
"From there, the priority has to shift from raw vulnerability counts to real world exploitability and business impact. A high severity score sitting on an asset nobody can reach is a lower priority than a moderate one that's internet facing and already being probed. That means leaning on business context, evidence of active exploitation, and not treating a CVSS score as the whole story," Mueller said.
Backlog pressure
The comments highlight a long-running problem in corporate cyber security: organisations often deploy multiple scanners and monitoring tools, but remediation remains slow and uneven. Structure matters, Mueller said, because attackers do not operate within the silos that separate application security, infrastructure, cloud teams and software delivery functions.
His remarks suggest a shift in emphasis from the total number of alerts and vulnerabilities to the combinations of weaknesses that could form a credible attack route. In practice, that means assessing exploitability, exposure and business importance rather than relying on severity scores alone.
David Brauchler of NCC Group made a similar argument, saying many businesses still struggle with basic security practices. He said the prospect of more automated and advanced threats should prompt executives and boards to address unresolved weaknesses, particularly in governance and patch management.
"For organizations, a sizeable number of businesses fall short in standard security hygiene, from governance to patch management. The emergence of automated, advanced threats should serve as a catalyst for security teams to address their backlog of challenges, leveraging these risks as strong motivators for executives and boards. AI has raised the floor of what attackers consider a 'low-hanging fruit,' and these businesses can no longer afford to hide security behind obscurity.
"Security-mature organizations should look instead toward velocity, increasing the rate of vulnerability discovery using AI tools and security partners, while reducing time-to-patch along the way. Worth considering, AI tools still do not provide sufficient reliability to operate without human oversight, and a fully automated patch-to-production pipeline can quickly introduce new vulnerabilities. To that end, these organizations should look to address bottlenecks in their patch management process and ensure that their teams can review, validate, and deploy vulnerability mitigations as quickly as discovery teams can report them," Brauchler said.
Human oversight
Brauchler's comments underline a more cautious view of AI inside security operations. While AI can help teams find vulnerabilities faster, he said it should not be trusted to run without human review, particularly where automated fixes could create fresh risks in production systems.
That reflects a wider debate in cyber security over whether AI will mostly benefit defenders through automation or attackers through speed and scale. Here, both specialists stressed that internal process failures may prove just as damaging as technical shortcomings if organisations cannot validate, prioritise and deploy fixes faster.
Brauchler also pointed to risks for the public, particularly from scams that use AI-generated content to appear more convincing. He said deepfake tools and automated phishing could produce tailored messages and impersonations at a scale that was previously harder to achieve.
He listed practical steps for consumers, including using multi-factor authentication or passkeys, independently verifying urgent requests, checking sender domains carefully and avoiding links in unexpected emails. He also urged people to pause and confirm suspicious messages with trusted contacts rather than responding immediately.
"For consumers, AI's risk often falls into the realm of spam and scams. With deepfake technologies, attackers can impersonate loved ones, generate custom phishing campaigns, and generate highly responsive content customized for a victim without any human-in-the-loop.
"Online safety best practices are more relevant than ever:
* Apply multi-factor authentication or passkeys to online accounts.
* When a figure of supposed authority like a bank or loved one calls with a request, hang up and call back using their official number from their website or contacts list.
* Double check email senders and make sure the domain is correct.
* Instead of clicking links in unexpected emails, navigate to the main site manually through a search engine.
* And when faced with a seemingly urgent request, contact a trusted friend or family member to double check.
"Any of us can be victims of scams in the wrong place, time, or mindset," Brauchler said.