top of page

Unit 42 Warns AI Has Shifted the Balance of Power Toward Attackers

Aug 28
2 min read

Key Findings


  • Agentic AI models have fundamentally shifted the balance of power from defenders to attackers, representing what Unit 42 calls a generational shift in cybersecurity

  • Early waves of AI-powered attacks are already occurring in the wild, with organizations largely unprepared for the threat

  • One documented attack used AI to exploit 50 applications across an enterprise in less than 10 hours, a task that would have taken at least 10 days before AI

  • AI capabilities gated for defense are reaching attackers faster than expected, with frontier model abilities now in malicious hands within months rather than years

  • Attackers are deploying AI across the entire attack chain including malware development, social engineering, ransomware negotiations, and supply chain infiltration


Background


Palo Alto Networks' Unit 42 threat intelligence team has been monitoring both internal testing of frontier AI models and real-world malicious use of commercially available AI tools. In April, Unit 42 estimated that offensive AI capabilities would reach attackers within a year. By late August, just five months later, the team began observing these threats materializing in actual attacks against customers.


The Speed Problem


Traditional security defenses were built over years with the assumption of human-speed attacks. Unit 42 observed a customer attack where an AI-driven attacker systematically exploited vulnerabilities across the enterprise in under 10 hours. Sam Rubin, senior vice president of Unit 42, estimates this would have required at least 10 days using pre-AI methods. Organizations lack the detection and response capabilities to keep pace with machine-speed attacks.


AI Across the Attack Chain


Threat actors are not yet launching fully agentic attacks across all vectors simultaneously, but they are rapidly integrating AI into every component of their operations. Vice President Sherrod DeGrippo noted that AI has seeped into malware development at scale, task delegation, social engineering campaigns, and negotiations with victims. This piecemeal integration is becoming increasingly sophisticated.


Four Emerging Threat Vectors


DeGrippo identified four key areas where the threat landscape is shifting. First, AI acts as a force multiplier for attacker capabilities. Second, identity compromise has become the primary entry vector for breaches. Third, attackers are targeting foundational libraries and software supply chains that are baked into the fabric of digital infrastructure. Fourth, nation-state threat groups are rapidly learning about enterprise system vulnerabilities through AI analysis.


The Readiness Gap


Unit 42's leadership emphasized that no organization is fully prepared for what's coming. DeGrippo stated it would be naive to believe otherwise. She characterized this as a transformative period where how organizations navigate these changes will be make-or-break for many. The traditional defenses built up over years were not designed with AI-driven threats in mind.


Sources


  • https://cyberscoop.com/unit-42-palo-alto-networks-warning-agentic-ai-frontier-models/

  • https://www.socdefenders.ai/item/fe09fd1e-35d4-4d2c-b5cc-88fe649f8473

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page