Visualização de leitura

Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks

Vulnerability Exploitation

Vulnerability exploitation has officially become the leading cause of cybersecurity breaches for the first time in nearly two decades, according to the latest Data Breach Investigations Report (DBIR) released by Verizon. The findings highlight how artificial intelligence is rapidly reshaping the threat landscape, enabling attackers to weaponize software flaws faster than security teams can respond. The 19th edition of the DBIR revealed that 31% of all recorded breaches now begin with vulnerability exploitation, surpassing stolen credentials as the most common attack entry point. Researchers warned that AI-driven automation is dramatically reducing the time between vulnerability disclosure and active exploitation, shrinking defensive response windows from months to just hours. The report paints a broader picture of an evolving cybersecurity environment where AI-powered attacks, mobile-focused social engineering, shadow AI usage, and supply chain compromises are all expanding organizational risk.

Vulnerability Exploitation Surpasses Stolen Credentials

For years, stolen usernames and passwords remained the primary method used by cybercriminals to breach corporate systems. However, the latest DBIR findings show a major shift in attacker behavior. Researchers found that threat actors are increasingly prioritizing vulnerability exploitation because AI tools can quickly identify weak systems, automate reconnaissance, and accelerate exploit development. According to the report, attackers are now moving much faster after vulnerabilities become public. Organizations that previously had weeks or months to deploy security patches are now facing exploitation attempts within hours of disclosure. Security experts said this trend is creating significant pressure on security operations teams already struggling to manage patching priorities across complex environments. Daniel Lawson, Senior Vice President of Global Solutions at Verizon Business, said the growing speed of cyberattacks reinforces the importance of strong cybersecurity fundamentals. “While the velocity of cyber threats driven by AI and faster vulnerability exploitation is increasing, the foundational principles of security and strong risk management remain the most effective defense,” Lawson said.

AI Reshaping the Cyber Threat Landscape

The report repeatedly emphasized the growing influence of artificial intelligence on cybercrime operations. Researchers noted that AI is not only helping defenders identify vulnerabilities more efficiently, but also allowing attackers to automate exploitation at unprecedented scale and speed. The DBIR warned that AI-assisted attack workflows are creating what researchers described as a “capacity crisis” for many security teams. Organizations are being forced to process increasing numbers of vulnerabilities while facing shorter remediation timelines. The report recommended that enterprises:
  • Strengthen patch management programs
  • Reduce overall attack surface exposure
  • Integrate AI into secure-by-design frameworks
  • Expand defense-in-depth strategies
  • Improve visibility into internet-facing assets
Researchers also highlighted rapid growth in AI bot activity across the internet. According to the report, AI bot crawler traffic is increasing by 21% month over month, while human-driven traffic growth remains almost flat at just 0.3%.

Mobile Social Engineering Attacks Rising

Beyond vulnerability exploitation, the DBIR identified major changes in social engineering tactics. As users become more cautious about traditional phishing emails, attackers are increasingly shifting toward mobile-based scams involving text messages and voice calls. The report found that conversational and interactive mobile attacks now achieve success rates roughly 40% higher than traditional email phishing campaigns. Researchers said attackers are leveraging:
  • Fake SMS messages
  • Voice phishing calls
  • Messaging app impersonation
  • Mobile account verification scams
Cybersecurity analysts warned that mobile devices continue to represent a major blind spot for many organizations because security monitoring on smartphones often remains less mature than on corporate desktops and servers.

Shadow AI Creates New Data Leakage Risks

Another major concern highlighted in the DBIR involves the rapid rise of “shadow AI” usage inside organizations. The term refers to employees using unapproved artificial intelligence tools without formal oversight from security or compliance teams. According to Verizon’s findings, frequent use of AI platforms by employees surged from 15% to 45% within a single year. Researchers said shadow AI has now become the third most common cause of non-malicious data leakage incidents. Security experts warned that employees may unknowingly expose:
  • Confidential corporate data
  • Customer information
  • Source code
  • Internal business documents
  • Sensitive communications
The report stressed that organizations need clearer governance policies around AI usage as adoption continues accelerating across workplaces.

Supply Chain Breaches Continue to Grow

The DBIR also documented a significant rise in third-party and supply chain compromises. Researchers found that breaches involving external vendors increased by 60% compared to previous reporting periods. Third-party involvement now accounts for 48% of all recorded breaches. As organizations rely more heavily on cloud providers, software vendors, and outsourced services, attackers are increasingly targeting weaker links within interconnected supply chains. The report concluded that the cybersecurity industry is entering a period where resilience, rapid response capabilities, and basic security hygiene remain critical despite rapid advances in AI-powered attack techniques. While artificial intelligence is changing the speed and scale of cyber threats, researchers stressed that organizations must continue focusing on foundational cybersecurity practices to defend against the growing wave of vulnerability exploitation and AI-driven attacks.

Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

Shadow AI Is Growing in Silence

By Niall Browne, CEO and Founder, AIBound
Shadow AI is accelerating alongside artificial intelligence (AI) adoption at a pace that has outgrown most enterprise governance models. Artificial intelligence (AI) adoption is accelerating at a pace that has outgrown most enterprise governance models. According to the World Economic Forum, 87% of organizations report that AI-related vulnerabilities are now the fastest-growing cyber risk. Part of this surfaces with  employees increasingly deploying autonomous AI agents that connect to MCP servers and external AI that security teams have never assessed, quietly piping sensitive corporate data into systems no one in IT has ever audited — and no one in the C-suite knows exist. This increase in Shadow AI is creating systemic enterprise risk that can lead to unforeseen costs. Compliance frameworks like the Artificial Intelligence Act of the European Union (EU AI Act) take full effect this year introducing penalties up to 7% of global annual revenue for unmanaged AI. As regulatory frameworks begin to align with the realities of increased AI adoption, enterprises need to account for decentralized AI usage that operates outside traditional controls. This requires software that allows greater visibility, organization, and control into how AI is used and tracked across environments.

Shadow AI Is Creating a New Enterprise Attack Surface

The traditional security stack was built for a world that no longer exists — one with known assets, centralized systems, and software that asked permission before it ran. As new tools are introduced independently, usage levels evolve quickly without system checks or visibility into how these tools interact with sensitive data. Research indicates that 75% of CISOs have discovered unsanctioned GenAI tools in their environments, and only 5% feel confident they could contain compromised AI agents. Because of how easy these platforms are to access and require little onboarding, adoption is happening across teams at a rapid rate without IT involvement. Other security issues lie with employees integrating workflows with personal AI agents. These deployments allow sensitive information to be leaked or directly inputted into agents without security knowledge. Without a system in place for organizations to continuously track and evaluate how AI is being used across their enterprise systems, CISOs are left without visibility of their attack surfaces. The result is a slow-motion breach: data leaking, compliance crumbling, and governance reduced to a slide deck nobody enforces. Recurring data leaks and breaches via AI reveal the need for solutions that address this gap. Popular AI agents like ChatGPT for example, revealed a ‘ShadowLeak’ vulnerability that allowed sensitive email data to be breached through a zero-click attack. Other short lived features that rolled out last year allowed conversation sharing, leaving employee info, internal corporate strategies, and other sensitive data to be shared and indexed by search engines. Although this option only was available for a day, it was estimated that over 100,000 private chats were affected and able to be viewed with a simple search, allowing any sensitive information inputted to be publicly accessible. Other recent breaches include a Microsoft 365 Copilot bug allowing AI assistants to summarize emails labeled confidential, bypassing data loss prevention policies set up by organizations. Microsoft confirmed that a code issue allowed confidential emails data to be accessed despite organizational securities put in place. These agents are live and operational with local access to files, systems, commands, and APIs capable of executing tasks and retrieving data without clear oversight control. As AI usage continues to expand at accelerating rates, organizations need a way to better understand how these tools are used across their environments. No CISO has ever defended a perimeter they couldn't see. Shadow AI is the new perimeter — and most security teams are flying blind. Without a comprehensive inventory and control of AI usage, security teams are unable to accurately assess risks and enforce policy to maintain compliance.

Shadow AI Demands Continuous Visibility and Independent AI Control Planes

This is where adoption of independent AI Control Planes becomes vital. Independent AI Control Planes provides a way to continuously identify and assess AI activity giving security teams the visibility needed to manage emerging risks. It enables organization and categorization of AI usage across enterprises without relying on the manual entry and tracking that existing platforms demand — work no security team in a fast-moving environment can realistically keep up with. It’s undeniable: Shadow AI is not a future problem — it is already running inside your enterprise, on assets you don't own, through agents you never approved, touching data you are responsible for protecting. Every day without continuous, autonomous AI discovery is a day your attack surface grows faster than your governance can chase it. Regulators won't wait. Attackers already aren't. The CISOs who win the next 24 months will be the ones who stop pretending policy equals control and start operating on a simple truth: if you can't see it, you can't secure it — and right now, most of AI is invisible.

Disclaimer: The views and opinions expressed in this guest article are solely those of the author and do not necessarily reflect the official policy or position of The Cyber Express. The information shared is intended for industry discussion and awareness purposes only.

My Really Fun RSA 2026 Presentations!

This blog is perhaps a little bit more like an ad, so if you don’t want to check the ads, consider not reading it.

a very cyber image (Gemini)

But this year at RSA 2026, I’m speaking on three topics: securing AI, using AI for SOC, and sharing lessons about how Google applies AI and other technologies to D&R.

Here are these 3 fun things!

First, I’m doing a presentation on governing shadow AI agents. Believe it or not, this presentation was created mostly before OpenClaw became a thing (but updated for it!). So you may be surprised how well the content aged (think wine!) Attend this if you are struggling with shadow AI, specifically shadow agents at work.

Shadow Agents: A Pragmatist’s Guide to Governing Unsanctioned AI — [STR-W08]

  • Wednesday, Mar 25 1:15 PM — 2:05 PM PDT

It is not the APT! The new threat is the “shadow AI agents” employees already use for work, leaking data and making decisions. Banning them is a losing game. This session will offer a better way: turn this organic behavior into a catalyst for secure progress. Learn to discover, assess, and channel unsanctioned agents into a formal strategy that empowers a team rather than force it underground.

The second is probably the most detailed discussion about how we use AI for detection and response at Google. You probably read our blogs and listen to our talks (especially this), but this time we are revealing a lot more interesting details about the machinery and also how we arrived at the state we’re in. I promise you this will be fun! And detailed too.

This Is How We Do It: Building AI Agents for Cybersecurity and Defense — [PART3-M07]

  • Monday, Mar 23 2:20 PM — 3:10 PM PDT

Presenters will share the playbook for building and scaling AI agents in cybersecurity. Attendees will learn four core lessons: Building trust with the team, prioritizing real problems, measuring value, and establishing solid governance foundations for the agentic SOC.

Finally, the third isn’t a presentation but a discussion that would help you understand the real state of AI in security operations / SOC. This would not be about the slides, but about sharing lessons on what works and what doesn’t.

AI in SecOps: Sharing Lessons Learned for Adoption Maturity — [CXN-R05]

  • Thursday, Mar 26 12:20 PM — 1:10 PM PDT

Attendees in this peer-led discussion will share stories from the AI-powered SOC trenches. Explore real adoption journeys from manual processes to autonomous agents. Share practical use cases on analyst retraining, workflow auditing, malware analysis, remediation automation, RAG pipelines and more. Trade notes on what’s working, what’s breaking, trust gaps, AI hallucinations, and career redesign.

All in all, join me for securing AI and Shadow Agents, learning from Google about detection and response, and comparing the state of practice of AI in the SOC.

See you there!

P.S. Yes, we will also be podcasting from the show.

Related:

RSA 2025: AI’s Promise vs. Security’s Past — A Reality Check”


My Really Fun RSA 2026 Presentations! was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.

The post My Really Fun RSA 2026 Presentations! appeared first on Security Boulevard.

❌