NewsTradingSentimentEventsCommunityBriefing
Tech

AI Accelerates Vulnerability Hunting While Expanding Attack Risks

By Tech Desk · 2026-09-20 · 2 min read
A magnifying glass hovering over a complex, tangled web of glowing digital threads
Illustration: Tradingbird

Artificial intelligence is dramatically shortening the time required to find and exploit software flaws, shifting the balance of power in cybersecurity.

The landscape of digital security is shifting rapidly as artificial intelligence compresses the timeline for discovering software vulnerabilities. What once required teams of experts and months of dedicated effort can now be achieved by a single researcher in a matter of days. This acceleration is not merely a matter of speed; it fundamentally changes the resources needed to identify weaknesses in major commercial platforms.

According to a survey of thirty security professionals conducted by GN technics/ai (en-US), this technological leap has democratized capabilities that were previously reserved for nation-state actors. While the efficiency of finding bugs has increased, the attack surface has simultaneously expanded, creating a complex environment where defenders must adapt to new tools and threats.

Democratizing Advanced Cyber Capabilities

Historically, building a functional proof of concept for a security flaw was a significant bottleneck, often taking months of implementation work. Today, commercial AI tools have condensed these timelines drastically. Researchers report that small teams, or even individual engineers, are now uncovering zero-day flaws in widely used software such as Zoom, Google Cloud, and Microsoft Copilot.

This shift means that sophisticated attacks no longer require government-level resources. A single researcher using accessible AI models can replicate what used to be a multi-month project for a specialized team. This accessibility lowers the barrier to entry for both offensive and defensive operations, making the cybersecurity field more accessible but also more competitive.

The Limitations of Automated Detection

Despite the speed, AI is not infallible. A significant portion of the surveyed companies noted that while AI excels at detecting surface-level issues, it often struggles with deeper context. The technology can hallucinate findings or generate false confidence, which makes verifying the truth a critical skill for human researchers.

Experts compare the current situation to the early days of automated fuzzing, where basic vulnerabilities are quickly found but deeper issues remain. AI can throw a lot of computational power at a project to find low-hanging fruit, but it may also fabricate results or pursue incorrect hypotheses for extended periods. Therefore, independent human judgment remains essential to distinguish genuine threats from algorithmic noise.

Shifting Focus to Context Manipulation

As traditional credential theft becomes less effective due to stronger authentication methods, attackers are pivoting toward manipulating trusted contexts. Security leaders suggest that adversaries no longer always need to steal passwords. Instead, they seek influence over trusted systems or processes to bypass security controls.

This change implies that securing the perimeter is no longer sufficient. Defenders must now account for how AI-driven attacks can exploit trust relationships and contextual data. The trade-off of using AI for speed is a heightened need for rigorous validation and a deeper understanding of how attackers might leverage trusted components within a system.

Based on reporting by calcalistech.com, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories