For many small and midsize organizations, the cybersecurity landscape is being reshaped by two very different forces. Longstanding security challenges—exposed systems, inconsistent configurations, unmanaged endpoints, and limited IT resources—remain persistent sources of risk. At the same time, attackers are beginning to use AI to operate with greater speed, scale, and sophistication. The result is an environment where organizations may be confronting next-generation attacks while still working to address fundamental security hygiene.
Jamie Levy, Senior Director, Adversary Tactics, at Huntress, sees that collision firsthand. Attackers continue to exploit basic weaknesses and abuse legitimate remote management tools, but they are also beginning to use AI in more advanced way. As Levy says, attackers who were once “gingerly running” are now “sprinting,” while defenders are still struggling to catch up.
Levy notes a persistent security hygiene gap, the abuse of legitimate tools, AI-enabled attacks, the human dynamics behind successful scams, and why identity and cloud environments are becoming critical areas of risk. It also considers what defenders can do differently
Q. What kinds of basic security weaknesses are you still seeing among smaller organizations?
A. A lot of our customers will have very basic kinds flaws, like RDP open to the internet. Or they don't have an enterprise standard for their machines. The machines can be all over the place, in different types of settings. A lot of times things just open to the internet because the organizations just don't know any better.
They don't install security solutions on all their machines. It’s really easy for an attacker to get in if there's nothing there. Then they're internal to your network.
Q. Why can enterprise security expectations be unrealistic for small businesses?
A. It’s funny because we talk about it on social media, and other companies say, "Well, that's just bad hygiene, and they should just blah blah blah.” They don't realize that this is a company of maybe 10 people, and their nephew is the IT guy.
Q. How are attackers taking advantage of legitimate remote management tools?
A. Sometimes we see remote management tools abused. That makes sense. Why would attackers want to build something from scratch if they can just pull something off the shelf that works really well?
Q. Why does the proliferation of remote management tools make detection more difficult?
A. There are sometimes multiple admins for one MSP, and each one of them wants their own RMM (Remote Monitoring and Management). That just muddies the water, too, because you might have five or six of these RMMs, these remote management tools, on a machine, and you don't know it. That’s something you have to untangle in the end.
Q. What does AI allow attackers to do that was much harder to accomplish before?
A. On the other side, there are more cutting edge-type attacks, specifically uses of AI. The attackers figured out they could utilize Railway, which would basically vibe code an infrastructure. So there are all these different compromised websites.
Once they get access to somebody's email, they basically suck everything down, have the LMM look at this, write, figure out like the contacts who have something valuable. What is this? What is the initial victim? What is their writing style? Then use that to basically target everybody else.
So, it looks legit, but it's not. It's actually the attacker doing an attack.
Q. How does AI change the scale at which attackers can operate?
A. Using AI, they can send thousands and thousands of emails, all your type of screens. They’re not being constrained by anything, so that's where we're going. And it’s really scary because what can be done to combat that?
Q. Is AI widening the gap between attackers and defenders?
A. The whole time as defenders, we're trying to get ahead of the attackers. We're really several steps behind them, and that's the sad part. How are we going to get on the other side of this? Attackers were kind of gingerly running, but now they're sprinting, and we're still trying to catch up with them.
Q. What needs to change if defenders are going to keep pace with AI-enabled attackers?
A. We’re going to have to start thinking outside the box. We're going to have to start utilizing the same types of methods attackers use in order to flip the script. We’re going to have to start being much more aggressive.
Q. What unexpected barriers have you witnessed that prevented a security team from becoming more aggressive?
A. It's really bizarre. Even today [at Black Hat], I'm going to give a talk a little bit later about a case where we had a threat actor that installed our software on their machine, and we were able to see what they were doing. As we're trying to figure out how it got on there, we figured out this is a bad guy. Then we started trying to figure out what they're doing but then the [defenders] also started to feel sorry for the threat actor as if we were being too mean to them by looking at what they were doing,. And I thought that was the most crazy thing. I couldn't believe it. There were even people I had previously respected who said these things on social media. And I felt like that is somebody I can't trust going forward. It's bizarre. Why would you feel sorry for the bad guy?
Q. Will the economics of AI eventually limit attackers?
A. They’re stealing money from people. So they're just going to take the money to pay for [AI use]. I'm sure they have stashes of bitcoins somewhere that they've stolen. So, I don't feel like they're underfunded. They’ll figure out a way.
Q. Are cybercriminals relying exclusively on technical attacks?
A. They probably have other ways.. Obviously, there's a lot of criminals and they're not just doing the technical stuff. They might have somebody who's actually calling people, like the Shiny Hunters does. They do everything. I'm sure that there's other ways that they're getting money, maybe even in less technical ways.
Q. Why do victims continue trusting scammers even when other people warn them?
A. It's so funny that you say that. You can't imagine going through that because you'd think that you'd see the red flags. But the problem is the attackers usually have established a relationship with these people and they will trust that person over any authority that tries to step in and stop them.
I've definitely heard stories of somebody coming in trying to buy gift cards and the cashier or the manager is telling them, "Hey, this sounds like a scam. You probably don't want to do this.” Then they get into an argument about this. They’re dead set, they're going to get these gift cards for this person, which is obviously a scam.
Q. Where should smaller organizations start if they want to strengthen their security posture?
A. Obviously, if you're talking about like you know laptops, computers the more you can harden those laptops, computers, and basically remove the attack surface, that would be the best to do. But some of our customers don't know how to do that. And they need something to just run, and it just takes care of it for them.
Usually, the problem is that something's just dangling out there and nobody knows about it.
Q. Why should identity and cloud security be priorities?
A. Definitely identity should. The cloud stuff is the wild west, and anything that you can do to get a solution in place for that, like having some kind of monitoring for that, would definitely help. Because once an attacker gets ahold of an identity, they can get ahold of anything else. Everything is connected to an intro account tk or a Google account or whatever. If they get that, then they get everything.
People don't realize that, and it's kind of a blind spot for a lot of them. They say, “it's just my email.” But it's not, it’s how you log into everything else.
The interview illustrates that the future of cyber risk will not be defined solely by sophisticated new AI attacks. Organizations must contend with an increasingly complex combination of old vulnerabilities and new attacker capabilities. Basic weaknesses such as exposed services, inconsistent endpoint configurations, unmanaged tools, and inadequate security coverage remain exploitable, particularly for smaller organizations without enterprise-level security teams or resources. AI can amplify that challenge by giving attackers new ways to automate, personalize, and scale their activity.
That evolution also makes the distinction between technical attacks and human manipulation increasingly difficult to maintain. Cybercriminals can combine technology with phone calls, stolen personal information, relationship-building, and other social engineering techniques. Once trust has been established, Levy notes, victims may continue to believe the attacker even when legitimate authorities or other people try to intervene.
For defenders, the response begins with reducing opportunities for attackers. Hardening endpoints, eliminating unnecessary exposure, gaining visibility into cloud environments, and protecting identity are practical priorities. Identity is especially consequential because compromising a single account can provide access to the many other applications and resources connected to it—making what appears to be “just my email” a much broader security risk.
But stronger fundamentals may no longer be sufficient on their own. Levey argues that defenders will also need to “start thinking outside the box” and become more willing to use the speed and methods available to attackers to “flip the script.” The challenge ahead is therefore twofold: close the security gaps organizations already understand while evolving defense quickly enough to keep pace with attackers that are rapidly gaining new capabilities.