AI-Powered Phishing Surges as CISOs Struggle with Incident Coordination
82.6% of phishing emails now use AI, while 90% of security leaders report poor incident response readiness.
AI Now Embedded in the Majority of Phishing Attacks
A recent report found that 82.6% of phishing emails analyzed between September 15, 2024 and February 14, 2025 exhibited some use of AI. This marks a significant shift in attacker tactics, with artificial intelligence becoming standard across phishing campaigns rather than an exception.
Critical Gaps in Incident Response Readiness
A Sygnia CISO survey on state of IR readiness uncovered alarming weaknesses in organizational preparedness:
- 90% of respondents would struggle to coordinate stakeholders during a major incident
- 75% say uncertainty around legal and comms involvement delays decision-making during incidents
These findings suggest that even as AI-driven attacks accelerate, many organizations lack the internal coordination and clarity needed to respond effectively. The combination of faster, AI-powered attacks with slower, uncertainty-laden decision-making creates a dangerous gap that attackers can exploit.
Source: The Hacker News
Developments since publication
-
Microsoft released patches for 570 security flaws on Tuesday, July 15, 2026, as part of its monthly Patch Tuesday release. Source
-
This was a record number of security vulnerabilities in a single monthly release for Microsoft. Source
-
At least two of the 570 vulnerabilities are classified as zero-days, meaning they were exploited before Microsoft was made aware of them. Source
-
One Windows Server bug allows hackers to escalate privileges from a limited user to a system administrator. Source
-
A SharePoint bug has been actively exploited by hackers to compromise organizations, according to CISA warnings. Source
-
Microsoft expects its future monthly security patch batches to be higher in number than before due to AI-powered vulnerability discovery. Source
-
Windows boss Pavan Davuluri stated that AI helping defenders discover more issues will result in a higher volume of security updates in each release. Source
-
99.9% of AI vulnerability alerts with an available fix remain unpatched according to Orca Security's 2026 State of AI Security Report. Source
-
81.2% of companies running AI packages have at least one known vulnerability according to Orca Security's report. Source
-
74.1% of companies running AI packages have at least one critical CVE according to Orca Security's report. Source
-
Colorado's amended AI law takes effect on January 1, 2027. Source
-
China has expanded its cybersecurity framework with AI-specific requirements and mandatory labeling of AI-generated content. Source
-
Check Point AI Security recorded a roughly fivefold increase in detections of large malicious prompt-injection payloads between March and May 2026. Source
-
A single operator ran Claude Code and GPT-4.1 in parallel to breach nine Mexican government agencies between late 2025 and early 2026, producing more than 5,000 executed commands and exposing roughly Source
-
US Government CISA required agencies to remediate the highest-risk vulnerabilities within three days. Source
-
India's CERT-In advised organizations to patch critical systems within 12 hours. Source
-
A critical flaw in Ollama left roughly 300,000 internet-facing model servers leaking prompts, keys, and environment variables. Source
-
GreyNoise recorded around 91,000 attack sessions probing LLM deployments in a single quarter. Source
-
One service sold more than 10,000 AI-generated fake IDs capable of passing bank KYC checks across 56 countries. Source
-
A North Korean-linked group used AI-fabricated personas to get operatives hired inside Western companies as legitimate remote employees, generating close to 800 million dollars for the regime's weapon Source
-
High-risk GenAI prompts doubled from 2 percent to 4 percent over the past year. Source
-
Microsoft patched 64 bugs in February 2026, 81 in March, 169 in April, 120 in May, and 206 in June 2026. Source
-
Jeremy Chapman, a director at Microsoft 365, recommended deploying Windows updates within less than three days as the deferral period for quality updates. Source
-
Microsoft's AI system MDASH achieved an 88.45% success rate for identifying bugs in Windows code. Source
-
Claude Mythos found 271 verified security vulnerabilities in Firefox and over 400 in Cloudflare. Source
-
Attackers are using AI to quickly exploit vulnerabilities in Windows 11 Source
-
Microsoft recommends not delaying Windows updates for more than three days Source
-
Microsoft patched 206 bugs in June 2026 Source
-
Once a vulnerability is publicly documented, AI can help attackers analyze the issue and develop an exploit within hours Source
-
Microsoft's AI system MDASH achieved an 88.45% success rate in finding vulnerabilities Source
-
74.1% of companies running AI packages have at least one critical CVE Source
-
99.9% of AI vulnerability alerts with an available fix remain unpatched Source
-
81.2% of companies running AI packages have at least one known vulnerability Source
-
56% of AI adopters have deployed agent frameworks into production Source
-
51.5% of AI adopters use AI to build custom applications Source
-
64% of AI adopters have deployed vector databases that connect LLMs to internal documents, customer records, and proprietary knowledge Source
-
Businesses using retrieval-augmented generation operate an average of 3.78 vector databases Source
-
Nearly 30% of AI adopters store at least one AI key in an insecure location Source
-
Between 87% and 98% of organizations across the three major cloud providers have not configured customer-managed encryption keys for their AI services Source
-
EU AI Act introduces additional requirements for high-risk AI systems beginning on August 2, 2026 Source
-
Anthropic's Claude Mythos has discovered thousands of critical flaws across every major OS and browser in just a few months Source
-
Claude Mythos created working exploits without human guidance and enabled autonomous attacks at speed and scale Source
-
Claude Mythos shrank the window between a software flaw's discovery and its weaponization to mere hours Source
-
In an AI-driven environment, the handoff time between an initial intrusion and a secondary threat actor has collapsed from eight hours to 22 seconds over the past three years, according to Google's M- Source
-
Anthropic's Claude Mythos discovered thousands of critical flaws across every major OS and browser in just a few months, creating working exploits without human guidance. Source
-
A vulnerability disclosed in Apple's Hide My Email service allowed users' real email addresses to be unmasked; in limited tests with volunteers, 100% of Hide My Email addresses were exploitable. Source
-
Anthropic said it does not consider the Claude Cowork sandbox escape to be a security issue because exploitation requires pre-existing local code execution on the host. Source
-
A phishing campaign impersonating law enforcement targeted small businesses across Europe, Asia, the Middle East, and the U.S. with fake INTERPOL investigation emails; the campaign did not use a fixed Source
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the now-patched Microsoft Defender vulnerability known as BlueHammer (CVE-2026-33825) was exploited in ransomware attack Source
-
The U.S. State Department is offering a reward of up to $10 million for information leading to the identification or location of threat actors associated with UNC5792, a cyber group linked to the Russ Source
-
UNC5792 has been linked to widespread phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leadership, and allied personnel. Source
-
Telegram-based Millenium RAT is offered as malware-as-a-service for $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase. Source
-
A malicious Chromium-based extension impersonating Perplexity AI attracted 10,000 installs before being taken down by Google. Source
-
Anthropic plans to remove hidden code it added to Claude Code to detect unauthorized distillation efforts by checking the base URL environment variable for overrides and checking system time zone and Source
-
Opera introduced Paste Protect, a security feature designed to block ClickFix-style attacks that deceive users into executing malicious commands through social engineering. Source
-
The Cloud Security Alliance (CSA) report 'The Vulnerability Storm: Building a Mythos-ready Security Program' was co-authored with SANS, OWASP and more than a dozen CISOs. Source
-
CISOs should prepare for a flood of patches addressing AI-discovered vulnerabilities that attackers could exploit within hours. Source
-
Given the sheer number of vulnerability discoveries from AI, organizations will not be able to patch their way out of the crisis and must instead focus on containing fallout. Source