It seems like every week there’s another headline claiming AI is transforming cybercrime.
One week it’s supercharging vulnerability discovery, the next it’s autonomously breaking containment. And, apparently, the next step will be “fully automated agentic breaching systems”.
So where does the hype end and truth begin? And what do security teams need to stay ahead of any real AI-led changes to the threat landscape?
Let’s find out.
What does AI do for attackers?
Call us old-fashioned, but we do like to see some evidence to back up big claims. But so far, evidence seems to be in short supply.
Even Microsoft's 2026 Digital Defense Report, which has a fairly alarmist take on AI, notes that target selection, operational decisions, and complex intrusions remain manually driven in most campaigns. And, a little disappointingly, the evidence that frontier models can “fully autonomously orchestrate complex attacks” was a test that “took place in a mock company computer system with no defenders”.
Not exactly a slam dunk for AI-assisted cybercrime.
Still, it’s one thing to be sceptical. What we don’t want to be is complacent.
There is no doubt that cybercrime groups are using AI to assist a range of functions, including reconnaissance, vulnerability discovery, and exploit development. It has become popular to say that AI is “changing the economics of cybercrime,” which appears to be true in several ways.
Notably, AI tools have reduced the cost-barrier to entry for certain attack vectors. Techniques and capabilities that were previously off-limits for small criminal groups (such as reversing a binary to autonomously find weaknesses rather than simply buying an exploit from a dark web marketplace) are increasingly viable options.
And note that these are cost barriers being breached, not just technical barriers. It has always been possible to buy the skills necessary to enact highly sophisticated attacks. AI tools have made certain capabilities cheaper, more widely available, and also faster to implement. So, while there’s (very) limited evidence of “fully autonomous AI attacks”, it would be foolish to imagine that AI isn’t having a significant impact on cybercrime operations.
Even if attackers only use AI and automation for reconnaissance, they will inevitably find gaps faster than they could in the past. And realistically, many attackers will use AI wherever possible to improve the speed and scale of their attacks. So, even in lieu of fully autonomous attacks, bad actors are gaining benefits from AI tooling that defenders will need to account for.
Two frontiers of vulnerability management
A lot of the conversation about attacker vs. defender speed centers on patching known CVEs. There’s a lot to investigate there, and we’ll be releasing a paper next week that details our findings.
Today, we’re focused on issues you can’t fix with a patch: flaws in your own applications and APIs, such as logic errors, broken access controls, and authentication weaknesses.
These are vulnerabilities that can potentially be uncovered and exploited more quickly by attackers using AI tools, but which are still reliant on slow, human-driven testing mechanisms to find and fix.
The 3 clocks problem
Your exposure window for CWEs and vulnerabilities in your internet-facing assets can be measured using three clocks:
- How fast your attack surface changes due to releases, new code, new APIs, etc.
- How fast your security adapts to those changes, through testing and remediation.
- How fast attackers can exploit gaps between #1 and #2.
Clearly, as defenders, what we want is a faster version of #2. But what we’re actually getting is acceleration in #1 and #3. This creates an ever-lengthening window of exposure.
Rate of attack surface change is one of the few things in cybersecurity that has lived up to vendor claims. It just keeps moving faster and faster, and unsurprisingly, that makes security quite difficult.
For example, developers merged an average of 43.2 million pull requests a month on GitHub in 2025, up 23% on the year before. Much of that acceleration is AI-assisted, but of course, faster code isn’t necessarily safer code. The same GitHub report found Broken Access Control overtook Injection as the most common CodeQL alert in 2025, flagged in more than 151,000 repositories, and up 172% year-on-year. GitHub partly credits this rise to AI-generated scaffolds, which skip critical auth checks.
And, as we’ve already noted, AI tools can (and do) enable attackers to find and exploit gaps more quickly. For instance, here’s a measured take from the Technical Director for Security of AI Research at the UK NCSC, who concluded that for the time being:
“AI is being used to increase the speed rather than the sophistication of cyber attacks”.
We like this quote for several reasons.
- Definite language. “AI is being used to…”, not “we expect to see…”.
- Recency. It’s from June 2026, so it accounts for the latest developments in AI models.
- Source. It’s from an expert who doesn’t have a financial incentive to exaggerate.
So, even the more moderate claims about AI-powered attacks suggest cause for concern. And that leaves us with undesirable change in clocks #1 (attack surface change) and #3 (exploit speed).
What about clock #2?
The results, but not the process
The second clock measures how quickly security teams can find and fix flaws in their attack surface. And naturally, this relies on security testing, such as scanners, ASM tools, red teaming, and pentests.
For many years, pentesting has been among the best ways to uncover exploitable non-CVE vulnerabilities. However, the process surrounding pentests (which has long been a pain point) has become a major obstacle to security outcomes.
From scoping and SoW to scheduling delays and back-and-forth comms, we recently published an article that details these challenges. But the upshot is that waiting a minimum of 6-8 weeks from first contact to results is simply not feasible when the rate of attack surface change and exploitation are both accelerating.
What security teams need from pentesting
For obvious reasons, losing testing depth to improve speed is not an acceptable trade-off. Shallow, fast scanning already exists, and while useful, it doesn't find more complex exploitable issues that attackers can use to compromise your systems.
No, security teams still need highly quality pentesting, but with some caveats:
- Deep testing that finds exploitable vulnerabilities, including the business logic and chained issues that scanners can’t find.
- Flexibility to cover a wide range of scopes, from a single new API to a full application, so you can achieve full coverage instead of limiting testing to your crown jewels.
- On-demand testing that fits your schedule (rather than a supplier's availability).
- Same-day results, so your exposure window is kept to an absolute minimum.
- Findings that integrate directly with your existing workflows, so your security and development teams can assign and action issues with ease.
In short, security teams need the results of quality pentesting, but without the process.
Closing the exposure window
Agentic Pentest was built to meet security teams’ need for on-demand, high-quality testing. It helps security teams ensure their security program can adapt at a rate that keeps pace with attack surface change and shrinking exploitation timelines.
It does this by retaining the depth of traditional pentesting while eliminating the process delays and frustrations:
- No scheduling delays. Choose your scope and launch a campaign immediately.
- Same-day results. Test around your release schedule, and get findings to developers while the code is still fresh in their minds.
- No PDFs. Findings appear directly in the YesWeHack Vulnerability Center, where they can easily be assigned, tracked, and remediated using your existing workflows.
- Consistent report scoring. Every finding follows the same format and risk assessment, so prioritisation is straightforward.
- Exploitable findings only. Every issue is validated and reproduced before it's reported. If exploitability can't be proven, it doesn't make the cut. No filler, no noise.
- Prove coverage and methodology. The Activity Report records what was tested and how, which leads were investigated, and why each was progressed or discarded. So you can prove thorough testing has occurred even when your secure scopes return few or no findings.
At the same time, Agentic Pentest campaigns come in at less than half the cost of a comparable traditional pentest.
To see Agentic Pentest in action, get in touch.



