AI-powered attackers compress months of hacking into hours
Palo Alto Networks researchers document a 10-hour breach that exploited 50 vulnerabilities—work that previously required two weeks.
Frontier AI models accelerate cyberattacks beyond defensive capacity
Cybersecurity researchers are tracking a fundamental shift in the attacker-defender balance as advanced AI models enable threat actors to compress weeks of reconnaissance and exploitation into single-digit hours.
Palo Alto Networks' Unit 42 threat intelligence team disclosed findings from an active investigation where an adversary used AI to exploit 50 separate vulnerabilities and attack paths in just 10 hours. The attacker gained initial access, moved laterally through the target organization, escalated privileges, and exfiltrated data—activities that typically require two weeks when performed by human operators, according to Sam Rubin, senior vice president of Unit 42 Consulting and Threat Intelligence.
The disclosure came during a media briefing in New York where researchers shared insights from months of controlled testing with Anthropic's Project Glasswing and OpenAI's Daybreak program. During those evaluations, Palo Alto security testers discovered the volume of vulnerabilities they would normally identify over a full year.
Why it matters
This compression of attack timelines creates an asymmetric advantage for adversaries that most enterprise security operations cannot match. Organizations built around detection and response workflows measured in days now face threats that complete full attack chains in hours. The implication: traditional security architectures that rely on human-speed triage and remediation are structurally mismatched to AI-accelerated offense.
Lone actors gain nation-state capabilities
The democratization of sophisticated attack capabilities represents a second-order risk. Sherrod DeGrippo, vice president of threat intelligence at Unit 42, noted that a single threat actor equipped with frontier AI models can now execute operations at the sophistication level previously associated with well-resourced nation-state groups or organized criminal syndicates—without requiring extensive technical training or operational experience.
This capability expansion effectively multiplies the number of actors who can conduct high-impact intrusions, while simultaneously increasing the attack surface each organization must defend.
Three-month warning window closing
In May, Palo Alto Networks projected a three- to five-month window before adversaries would begin exploiting vulnerabilities at unprecedented speeds using frontier AI. More than three months into that timeline, researchers now report those expectations are materializing in live environments.
"Here we are, five months in and we're starting to see the wave of this coming now," Rubin said during the presentation.
Palo Alto Networks joined approximately 100 security and technology companies in signing an open letter calling for immediate action to address weaponized AI threats.
The findings were first reported by Cybersecurity Dive, which attended the August briefing in New York.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call