Close Menu
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
AI Leaders Are Calling for a Slowdown. Trump’s Team Says It’s on Them

AI Leaders Are Calling for a Slowdown. Trump’s Team Says It’s on Them

14 September 2026
Hope Sci-Fi Movie Images Offer Exclusive Look at Alien Invaders

Hope Sci-Fi Movie Images Offer Exclusive Look at Alien Invaders

14 September 2026
What happens after a town de-Flocks

What happens after a town de-Flocks

14 September 2026
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact
Facebook X (Twitter) Instagram Pinterest VKontakte
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release
Tech News VisionTech News Vision
Home » AI Cyberattacks Are Outrunning Enterprise Defenses
What's On

AI Cyberattacks Are Outrunning Enterprise Defenses

News RoomBy News Room14 September 2026Updated:14 September 2026No Comments
Facebook Twitter Pinterest LinkedIn Tumblr Email
AI Cyberattacks Are Outrunning Enterprise Defenses

Cybersecurity has reached an inflection point as machine-speed attacks increasingly outpace human response.

AI-driven attacks are testing perimeter defenses and overwhelming manual triage, forcing security teams to rethink defensive playbooks built for human-speed threats.

In an open letter issued in late August, OpenAI, Anthropic, Google, Microsoft, AWS, and more than 100 technology leaders warned governments and enterprises that AI-enabled threats will grow more sophisticated in the coming months. Declaring that the “status quo won’t be enough,” the coalition identified weak authentication, excessive permissions, misconfigurations, and legacy technical debt as prime targets for machine-driven exploitation.

Threat actors are using AI to discover vulnerabilities, chain exploits, and conduct social engineering at scale. Defending against those tactics requires security teams to move beyond raw alert counts toward exploitability-driven patching, cross-silo visibility, and stronger security fundamentals.

Many enterprises are already struggling with those fundamentals, according to David Brauchler, technical director and head of AI and ML security at NCC Group.

“AI has raised the floor of what attackers consider low-hanging fruit, and these businesses can no longer afford to hide security behind obscurity,” Brauchler told TechNewsWorld.

AI Threat Warning Comes Amid Rising Attacks

The open letter follows a series of high-profile cyberattacks and disclosures that the signatories say demonstrate the growing urgency.

Water and wastewater utilities in at least seven states reported cyberattacks beginning in late July, some of which disrupted water operations, according to an FBI and EPA public service announcement. OpenAI also disclosed a July security experiment in which AI agents gained unauthorized access to Hugging Face while attempting cybersecurity tasks in what researchers believed was a secure testing environment.

Against that backdrop, the letter urged frontier AI and technology companies to “provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.”

No timeline or mechanism for providing broader model access is specified. The coalition also called for governments, enterprises, cybersecurity professionals, and AI companies to collaborate on testing defenses against increasingly capable models.

Policymakers are also considering how to respond to those risks. In July, Reps. Ted Lieu, D-Calif., and Nathaniel Moran, R-Texas, introduced the AI Kill Switch Act, which would require companies operating certain advanced AI systems to maintain the technical capability to restrict access to or shut down those systems when necessary.

AI Attacks Put More Pressure on Passwords

Thi Nguyen-Huu, CEO of the cybersecurity company WinMagic, argued that organizations should rethink one of cybersecurity’s most basic assumptions: the traditional login.

“A stronger password helps against guessing, and attackers no longer guess,” he told TechNewsWorld. “Beyond that, attackers take the credential rather than guess it — reusing what leaked from an old breach — and where a second factor is in place, they attack it directly.”

Rather than relying primarily on passwords or portable authentication tokens, Nguyen-Huu urged companies to adopt methods that cryptographically verify users and endpoints together. Such systems can bind authentication keys to device hardware and validate security conditions throughout a session.

He pointed to mutual Transport Layer Security (mTLS), in which client and server authenticate each other using digital certificates, as an established model for machine-to-machine authentication that could increasingly be applied to users without requiring manual certificate management.

Robbie Mueller, technical lead for cybersecurity at application security platform ArmorCode, said AI-driven attacks intensify a problem enterprises already face: security teams are finding vulnerabilities faster than they can fix them.

Mueller said the average enterprise runs more than 40 security scanners that collectively produce millions of findings, while security teams remediate only about one in 10 open vulnerabilities each month.

“It’s a capacity problem. Finding problems has never been easier. Fixing them is the hard part … unclear ownership, competing priorities, and teams that don’t share a queue,” he told TechNewsWorld.

Attack Speed Widens the Remediation Gap

Mueller said that if attack volume and speed increase while enterprises’ ability to triage and remediate vulnerabilities remains flat, the gap will compound. The critical measure, he argued, is not the number of findings but which vulnerabilities can be chained into a viable path to a valuable target.

“Once you kill that path, the risk goes away, either by remediating a link in it or by putting a mitigating control in front of it,” he explained.

Mueller also identified weak authentication as a prime target for automated attacks, particularly when high-value systems remain protected by passwords alone.

“We keep seeing the same failure modes: short or predictable passwords, credential reuse across accounts, and vulnerability to phishing that no amount of policy has fixed,” he said.

Nguyen-Huu said authentication risks don’t end once a user successfully logs in because many systems then issue session credentials that can become targets themselves.

“The token exists to spare the user from authenticating again on every request. So, the attack moves to that token. A bearer token can be copied. Protecting it opens an attack surface of its own — identity provider, browser, redirect, endpoint — a second surface beyond the login,” he explained.

Enterprise Efforts Fall Short

Brauchler said increasingly automated threats should give security teams additional leverage to address longstanding security backlogs with executives and boards.

For security-mature organizations, Brauchler recommended using AI tools and security partners to accelerate vulnerability discovery while simultaneously reducing the time required to patch identified flaws.

The seven CX technologies transforming business performance in 2026

“AI tools still do not provide sufficient reliability to operate without human oversight, and a fully automated patch-to-production pipeline can quickly introduce new vulnerabilities,” he said.

Brauchler said organizations should identify bottlenecks in patch management so teams can review, validate, and deploy mitigations closer to the rate at which vulnerabilities are discovered.

Mueller said improving authentication does not require a wholesale security rebuild and can begin with a strategy for moving toward passwordless authentication.

“Getting rid of the password isn’t a someday goal; it’s overdue,” he said.

Prioritizing Risk Over More Security Tools

Mueller recommended prioritizing phishing-resistant multifactor authentication (MFA), including passkeys and hardware security keys, for high-value systems. Password managers can serve as a bridge for systems that cannot immediately move to passwordless authentication, he added, with migration plans aligned with NIST authentication guidelines.

Mueller said the starting point for confronting AI-driven threats is not adding more security tools but understanding the systems and exposures already in place.

“From there, the priority has to shift from raw vulnerability counts to real-world exploitability and business impact,” he said.

According to Mueller, enterprises cannot close the gap simply by adding people or scanners. Instead, he recommended shifting the focus from the number of findings to the risks they create, while automating routine steps such as triage, ownership routing, ticket creation, escalation, and verification.

“Most of the delay between disclosure and remediation lies in the hand-offs. Close those gaps, and you buy back capacity without adding people,” Mueller said.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Microsoft says ‘people matter more than AI’ following safety concerns

Microsoft says ‘people matter more than AI’ following safety concerns

14 September 2026
The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

14 September 2026
AI Leaders Are Calling for a Slowdown. Trump’s Team Says It’s on Them

AI Leaders Are Calling for a Slowdown. Trump’s Team Says It’s on Them

14 September 2026
What happens after a town de-Flocks

What happens after a town de-Flocks

14 September 2026
Editors Picks
Microsoft says ‘people matter more than AI’ following safety concerns

Microsoft says ‘people matter more than AI’ following safety concerns

14 September 2026
The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

14 September 2026
Nintendo’s GameCube Turns 25 Years Old Today

Nintendo’s GameCube Turns 25 Years Old Today

14 September 2026
AI Cyberattacks Are Outrunning Enterprise Defenses

AI Cyberattacks Are Outrunning Enterprise Defenses

14 September 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
Tech News Vision
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2026 Tech News Vision. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.