REPORTS

AI Security 2026

July 23, 2026

In May 2026, Sophos found an attacker running what amounted to a software development operation inside a customer’s network. Around a dozen AI agents, coordinated through a commercial coding assistant, were writing and testing malware against Sophos, CrowdStrike, and Windows Defender endpoint protection, each on its own virtual machine. The operation produced nearly 80 modules and more than 70 evasion techniques, every result committed to version control and improved on the next pass. The same operator later used the output to deploy ransomware and steal data.

While the tradecraft itself wasn’t new, the agents turned weeks of manual iteration into days of automated iteration, and that change is the subject of this report. AI is changing the speed and shape of security operations more than it is changing the fundamentals of intrusion. Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock.

SHARE:
Price: FREE

About the Provider

Sophos
Sophos Group plc is a British security software and hardware company. Sophos develops products for communication endpoint, encryption, network security, email security, mobile security and unified threat management.

TOPICS

AI Security