AI Cyber Threats: What Defenders Need to Know
72,000 CVEs are projected to be published in 2026, while the median time from vulnerability disclosure to in-the-wild weaponization has fallen to well under 24 hours.
Those two figures capture a growing challenge for defenders: more vulnerabilities to manage and less time to respond.
Marc and Corey explore findings from Microsoft’s 2026 Digital Defense Report, including how AI is accelerating attacks, why identity security matters for AI agents, and where strong security fundamentals can make the biggest difference.
What are the key cybersecurity takeaways?
For security teams and MSPs, several trends stand out:
- Vulnerability volumes are rising, with approximately 72,000 CVEs projected for 2026.
- The median time from disclosure to real-world weaponization has fallen to well under 24 hours.
- AI is helping accelerate vulnerability research, social engineering, and attack automation.
- AI agents introduce additional identities, permissions, and access that organizations must secure.
- Familiar weaknesses, including unpatched systems and excessive privileges, remain opportunities for attackers.
Together, these trends reinforce the need to identify exposures quickly and prioritize action based on risk.
Faster vulnerability exploitation demands faster prioritization
Vulnerability management often assumes organizations have some breathing room after a vulnerability becomes public. That window is shrinking.
Marc highlights a finding from Microsoft’s report that the median time to in-the-wild weaponization has fallen to well under 24 hours. For defenders, this compresses the time available to assess exposure and take protective action.
The Citrix NetScaler vulnerabilities discussed by Marc and Corey illustrate the challenge. At the time of the discussion, only about 10% of vulnerable, exposed systems had reportedly been patched, despite active exploitation.
For security teams and MSPs, the practical lesson is to prioritize internet-facing systems and actively exploited vulnerabilities. When a patch is unavailable, temporary mitigations and closer monitoring become especially important.
AI increases the value of security fundamentals
AI can help attackers carry out familiar techniques faster and at greater scale. Reconnaissance, vulnerability research, command generation, and social engineering can all benefit from increased automation.
That makes foundational controls more valuable.
Asset visibility, timely patching, secure configurations, identity protection, and continuous monitoring help reduce the weaknesses attackers can exploit. As attack activity accelerates, gaps in those controls can become costly more quickly.
Defenders should also evaluate where AI can support their own operations, particularly in analyzing information, investigating suspicious activity, and reducing repetitive work.
Human judgment remains essential in AI-assisted research
One example Marc and Corey discuss involves a 16-year-old security researcher investigating an exposed Microsoft internal service.
The researcher used an AI assistant during the investigation and identified a problem with JSON Web Token validation. AI helped advance the research, but human intuition was necessary to move it forward when the assistant reached a limit.
The researcher questioned how a user principal name field behaved and manually tested an alternative value. That step helped uncover access the AI had failed to identify independently.
The lesson for security teams is straightforward: AI can accelerate investigation, while human reasoning remains essential for challenging assumptions, interpreting context, and validating results.
AI agents need identity security and oversight
AI agents can interact with applications, use credentials, execute code, and access sensitive information. Those capabilities make their identities and permissions an important security consideration.
Marc and Corey explore the possibility of attackers “living off the AI,” using legitimate agent capabilities to carry out malicious activity.
Organizations adopting AI agents should understand:
- What each agent can access.
- Which credentials and permissions it uses.
- What actions it can perform without human approval.
- How its activity is monitored.
- How access can be revoked if something goes wrong.
Least privilege and clear accountability should be part of deployment planning, especially when agents can interact with business systems or sensitive data.
Social engineering extends beyond the inbox
The discussion also examines ClickFix attacks and voice phishing through collaboration platforms.
ClickFix campaigns commonly use deceptive prompts, such as fake CAPTCHA instructions, to persuade people to execute malicious commands. Voice phishing exploits trust in familiar communication channels and seemingly legitimate requests.
AI can support these techniques by improving impersonation, tailoring messages, and making fraudulent interactions more convincing.
Security awareness should prepare employees to question unexpected requests across email, messaging, collaboration platforms, and phone calls. Requests involving credentials, payments, software installation, or command execution deserve particular scrutiny.
What should defenders prioritize?
Security teams and MSPs should focus on reducing exposure and shortening response time:
- Identify exposed assets. Maintain visibility into internet-facing systems and critical services.
- Prioritize remediation by risk. Address actively exploited vulnerabilities and high-impact exposures promptly.
- Strengthen identity controls. Apply least privilege and protect human and machine identities.
- Monitor AI agents. Track their access, permissions, and behavior.
- Update security awareness. Prepare employees for impersonation and malicious instructions across multiple channels.
- Use AI with human oversight. Validate findings and maintain accountability for security decisions.
AI is increasing the pace of cybersecurity activity on both sides. Defenders can respond by combining faster analysis with disciplined security practices and informed human judgment.
🎧 Listen to Marc and Corey’s full discussion.
Follow WatchGuard for practical threat intelligence and subscribe to Secplicity for expert insights that help turn emerging risks into informed security decisions.