Cybercriminals, spies, researchers, and corporate defenders are increasingly using AI, feeding into an escalating cat-and-mouse game of finding software flaws
good and bad actors leveraging AI in cybersecurity arms race Stephen E. Arnold / Beyond Search : News Flash from the Past: Bad Actors Use New Technology and Adapt Quickly Bluesky: Kevin Collier / @kevincollier : I've rolled my eyes for years at hyperbolic claims of AI revolutionizing cyber, but especially after Vegas this year I think it's now time to call it: Hackers of every stripe are using LLMs now. Jake Williams / @malwarejake : Respectfully, I think a large part of that is the innate drive to understand how LLMs work, and as a result what they will (and critically, won't) be good at. — This is a group that grew out of learning how a system worked specifically so they could find poor engineering decisions and break it. Jake Williams / @malwarejake : In that same vein, I regularly see hackers finding LLMs fitting their workflows where businesses struggle to do the same. — I think that's more about the user than the tool (and in some situations, even the use case). @wylienewmark : I'm sorry to do this with a quote-skeet of a reporter I actually respect, but: USING LLMS IS NOT THE SAME THING AS “HACKING WITH AI”. LLM usage to support basic software development is now utterly ubiquitous but the fear we've seen of “AI-enabled intrusions” still has not come to pass. …
Context & Ripple Effects
AI use in offensive security has been building since researchers reported ChatGPT-assisted hacking tools and malware code in 2023. More recently, coverage of AI-assisted “vibe hacking” connected mainstream-model misuse to a faster security contest.
This story broadens that arc beyond criminals: researchers, intelligence actors and corporate security teams are all incorporating LLMs into workflows for finding, exploiting and fixing flaws. The significance is not that automation guarantees successful intrusions, but that it is becoming a common capability on both sides.
First-order effects
- Security teams must assess AI-assisted discovery and remediation alongside AI-assisted attack development, while attackers gain another tool for researching targets and code.
- LLM providers and corporate defenders face more immediate pressure to monitor misuse and distinguish useful security research from harmful activity.
Second-order effects
- As defenders automate more vulnerability triage and testing, attackers have incentives to adapt techniques and seek model access or prompts that evade safeguards; the reported weaponization of Claude in a data-extortion scheme illustrates the abuse pressure on providers.
- Open-source maintainers and security teams may face more low-quality automated submissions as well as potentially useful reports, increasing the cost of validation and prioritization.
Third-order effects
- If AI remains embedded across offensive and defensive workflows, vulnerability management is likely to become a contest over the speed and quality of human-supervised automation rather than a purely human expert process.
- The dual-use character of general-purpose models will keep governance focused on misuse controls and transparency, while preserving legitimate research access; the corpus does not establish that AI-enabled intrusions are yet broadly dominant.
The trend: Cybersecurity is becoming a dual-use AI competition in which the same general-purpose models can accelerate software research, exploitation and defense.