The business world sees AI as a harbinger of positive developments — a force multiplier that will help organizations automate tasks, accelerate innovation, and improve productivity. But the cyber security community is acutely aware of AI’s double-edged nature. Just as AI helps identify and fix vulnerabilities and strengthen defenses against intrusion, it is also now being used by attackers to plan, execute, and scale attacks with increasing speed and efficiency.
Check Point Research’s second annual AI Security Report illustrates the offensive AI campaigns that AI security leaders are preparing for. Check Point documented a range of incidents where AI autonomously executed vulnerability exploitation workflows, generated thousands of commands during active intrusions, and dramatically reduced the level of expertise required to carry out sophisticated attacks. In one case, researchers analyzed a command-and-control framework that initially looked as though it had been developed by an experienced team over several months. In reality, it was created by a single individual using AI-assisted coding tools, which generated approximately 88,000 lines of working code in under a week.
This new research provides a snapshot of AI threats around the world. But it also serves as a reminder that traditional defense solutions and strategies are no longer sufficient to address today’s increasingly autonomous AI-driven threats.
AI Is Entering the Attack Chain
The traditional cyberattack chain required specialized skills, significant resources, and time. AI is now rapidly compressing all three.
Check Point Research observed AI being used across nearly every stage of modern cyber operations, from reconnaissance, malware development and vulnerability research to credential theft, phishing, and post-compromise activities. While the techniques themselves are often familiar, what has changed is the speed and scale at which they can now be executed. Tasks that once required hours or days of expert work can now be completed in minutes.
Researchers documented intrusions where AI systems executed thousands of actions across dozens of sessions with minimal human direction. In one widely reported breach involving nine Mexican government agencies, a single operator used AI tools that generated more than 5,300 AI-executed commands across 34 separate sessions while exposing approximately 400 million records.
In the nascent AI era, the most dangerous adversaries are no longer necessarily those with the most sophisticated tools, but rather those that are learning to best orchestrate AI systems.
Platforms such as EvilTokens now integrate AI directly into phishing campaigns. Stolen inboxes are automatically analyzed by large language models, personalized fraud messages are generated in the victim's writing style, and fake calendar invitations are created to improve credibility. Voice fraud platforms such as ATHR automate credential-theft calls without requiring a human operator. What was once a high-level cyber operation can increasingly be purchased as a service.
AI Has Become a New Attack Surface
AI is also now increasingly becoming the target of criminals. As organizations work to embed Ai into email systems, browsers, collaboration platforms, software development environments, customer service applications, and enterprise workflows, there must be checks on the AI used within these systems to ensure they’re not becoming part of the problem rather than a solution.
The report identifies two primary categories of risk. The first is unique to AI itself, including prompt injection, memory poisoning, and configuration abuse. The second consists of traditional software vulnerabilities that now affect AI systems and agents operating with expanded permissions and autonomy.
Prompt injection, in particular, has evolved from theory to operational reality. Researchers identified approximately 15,300 indirect prompt-injection payloads hidden across public websites, with roughly 70 percent embedded in non-rendered HTML invisible to human users. Check Point telemetry also showed detections of long malicious prompt payloads increasing roughly fivefold between March and May 2026.
This trend becomes particularly dangerous as organizations deploy AI agents capable of taking actions on behalf of users.
The Rise of the Agentic Supply Chain
AI agents increasingly rely on trusted configuration files, Model Context Protocol (MCP) servers, plugins, skill stores, and external services. These components form the "agentic supply chain,” a new ecosystem of dependencies that expands the enterprise attack surface. Check Point Research found vulnerabilities that allowed attackers to compromise AI coding agents through seemingly trusted project files. Researchers also discovered security weaknesses in 40 percent of the 10,000 MCP servers they reviewed.
Separately, analysis of approximately 46,500 published software packages revealed 428 instances where developers unintentionally exposed sensitive AI configuration files, including live credentials.
AI security is not just about protecting models. It is about securing the broader ecosystem powering autonomous decision-making.
Securing Trust to Better Secure AI
Digital trust is one of the other major takeaways from the Check Point Research report. Human trust has been the focal point of digital trust for decades, with organizations relying on identity signals (voices, faces, documents, and live conversations) to establish trust. But with AI use rapidly expanding across every area of business, confidence in these indicators is waning.
Voice cloning, deepfake video, fabricated documents, and synthetic personas are now routinely used in criminal operations. Researchers documented platforms that automate voice-enabled credential theft, large-scale investment fraud operations driven by AI-generated personas, and sophisticated deepfake campaigns targeting businesses and individuals alike.
One particularly concerning trend involves synthetic workers. Check Point Research highlighted North Korean operations that use AI-generated identities, resumes, facial imagery, and interview personas to secure legitimate employment inside Western organizations. Once hired, these individuals gain authentic access to enterprise systems and cloud environments, turning synthetic identity into operational footholds.
The conclusion is difficult to ignore: a voice, face, document, or video call can no longer serve as definitive proof of identity. AI is accelerating attack development, compressing vulnerability lifecycles, expanding the enterprise attack surface, and fundamentally changing how digital identities are created and verified. At the same time, organizations are deploying AI faster than governance, visibility, and security controls have been adopted. High-risk AI interactions have doubled over the past year, while the average organization now runs roughly ten AI applications every month.
Quickly adopting and deploying AI is not the answer to safe innovation – it must be built with trust as the keystone of these efforts to mitigate risk and maximize upside.
This can be accomplished by implementing AI-native security controls, verifying identities through multiple trusted signals rather than relying on a single indicator, and, perhaps most important, continuously monitoring how AI is being used (not just how it is supposed to be used).
The future runs on intelligence. Preserving and monitoring trust in this future may become the top cyber security mandate of the next five years and beyond.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




