By Teri Robinson
The conversation around AI and cybersecurity is often dominated by predictions about autonomous attacks, rapidly evolving threat actors, and entirely new categories of risk. But the reality on the ground is more nuanced. While attackers are experimenting with AI and using it to accelerate familiar activities, Chris Yule, Senior Director of the Sophos Counter Threat Unit, told Tech Channels that fully AI-driven attacks are not yet a widespread threat in the wild. For now, both attackers and defenders are exploring the technology's capabilities, creating what he describes as “a bit of an arms race from a defense point of view.”
That experimentation is already beginning to reshape security. AI models can identify not only individual software vulnerabilities but chains of vulnerabilities that could become dangerous when combined. At the same time, legitimate AI agents are behaving in ways that security systems historically associated with malicious actors, complicating behavioral detection and forcing defenders to think more deeply about intent and context. Organizations may also need to prepare for an accelerated cycle of vulnerability discovery, patching, and potential exploitation.
Yet amid the focus on emerging AI risks, the immediate threat landscape remains remarkably familiar. Ransomware continues to have significant impact, and many successful attacks still begin with stolen credentials, missing multifactor authentication, or unpatched vulnerabilities. Looking ahead, however, AI could alter everything from the economics of cyberattacks to the security of the open source software ecosystem. In this conversation, Yule separates current reality from emerging risk and explores what defenders should be preparing for next.
Q. Considering the hype and handwringing going on today, what are you actually seeing from attackers when it comes to AI?
A. From the attack point of view, the key thing is we're definitely not seeing AI-driven attacks in the wild. So, the recent stories from OpenAI and Anthropic, they're the exception though maybe a portend of things to come, and what the models are going to be doing. But it's not impacting people today.
Q. How are threat actors using AI today then?
A. We’re seeing AI being used by threat actors in much the same way as we're all using it. They're still experimenting. There was one report we put out that earlier this year we saw one group, probably Russian-based, who were basically using AI to develop EDR killers—software that could kill the EDR. And they basically set up an environment with our EDR on it, so we could see them running the thing and then iterating with AI to develop things. It was pretty cool, but again, just like us, using AI to sort of iterate faster. There’s nothing particularly novel about what we're doing.
Q. What are cybercriminals discussing about AI on the dark web?
A. Our dark web team is seeing lots of people talking about it and offering API keys for sale. How do we get around the restrictions and things like that? But again, nothing particularly earth-shattering or novel. They're experimenting, we're experimenting. It's a bit of an arms race from a defense point of view.
Q. What are AI models already capable of finding from a defensive security perspective?
A. So we are running the models against all our source code to see what we can find, it is finding vulnerabilities as you would expect, and so we're definitely very impressed with the models. They are living up to what we expected.
We're seeing it be able to not just identify vulnerabilities but also chains of vulnerabilities. It says “we found it, but this sequence of things could be dangerous.”
Q. What does that capability mean for organizations trying to manage vulnerabilities?
A. It allows us to get ahead of the curve and see what these things are going to find that have been unexplored. Our message to our customers has been making sure you're well instrumented to identify patches, apply them quickly because we're going to be in the cycle of lots of vulnerabilities being exposed. AI potentially reverse engineering patches to identify exploits and things like that. So while this has been a key message for years that you have to be able to patch quickly, it's only going to be more important now.
Q. Could AI permanently accelerate the vulnerability lifecycle?
A. What's going to be interesting is what we don't know is beyond that. Are we going to get this wave of vulnerabilities that get patched, and like we find stuff in our software, we can patch it, and then all the vulnerabilities are closed, and we all move on, and things calm down? And or is it just going to accelerate with more and more esoteric vulnerabilities? So that's kind of the big question mark that we're sort of bracing for at the moment.
Q. Can defenders identify whether activity was generated by AI?
A. So one, the obvious stuff: are there any tells of AI stuff, simple things like our scripts that are being used and do they have emojis in there? Because most developers don't use emojis in code, but AI Claude loves creating emojis. Again, we can use that as an indication that this is AI-generated. But then, lots of people are using AI legitimately, so it doesn't necessarily mean it’s malicious. It could be good. It could be a network defender using it.
Q. Why is legitimate AI activity creating a new detection problem for security teams?
A. We're also finding that legitimate AI usage, which is doing crazy things that humans don't normally do, is triggering a lot more of our detection rules that are trained to look for bad things because we're looking for malicious activity, things that normal people don't do. But a network defender using an AI agent is suddenly doing things that a malicious actor used to do.”
We’re having to fight that battle now, and it's the sort of philosophical exercise where we're seeing alert volume go up as legitimate AI and what's actually malicious versus what's good. That’s a big challenge for the industry going forward as we start to blur the lines between what malicious actors do and what legitimate network defenders are doing.
Q. Does AI require defenders to move beyond traditional behavioral detection?
A. We’ve also got the standard signature—if you see this, then this means this. But then we've invested a lot in behavioral rules. But it's a lot of those behavioral rules that are starting to trigger with legitimate, benign AI agents. So, there's really that new dimension of we have to more firmly identify, like start looking at intent. Can we identify rather than look at one malicious behavior? Can we start to chain together and correlate things that suggest a series of things that is malicious versus what might be benign? I think that's going to be a big challenge for the industry.
Q. What does increased AI activity mean for security operations centers?
A. For our security operations center, it’s how many alerts that we are raising that they have to look at. So, definitely there's a cost there as we have more volume that the SOC has to look at. But that's for us to manage and still make sure we're delivering the outcomes for our customers; that we're assessing everything that we know is genuinely benign or if it’s something malicious, so that's a challenge. But our customers shouldn't necessarily be feeling the effect of that if we're doing our job properly. That’s the kind of balancing act that we have to find.
Q. Will AI-driven attackers necessarily operate at machine speed?
A. Initially, our theory was this is going to be machine-driven speed rather than human-driven speed. Now, that does look different if it's an AI-driven attacker. So, is it going to be compressed timelines? Actually, it's not that compressed because it's just different because the AI agents still need to take what they've learned and then do that whole “I'm going to do this, and I'm chaining this. Now I'm thinking about this.” So, it still takes time for AI to know what to do next.
Q. Could defenders deliberately make attacks more expensive for AI agents?
A. We’re looking at deception. If you can expand the list of things it has to do, then you're in the world of “we only have to spend less tokens than the attacker because we're more resourced than they are today.” For threat actors, there's a legitimate challenge because they don't have unlimited resources. They probably can’t use the frontier models because they're locked down for malicious activity, so you're looking at the open source models, running those on bare metal hardware. There's only so much activity that they can do. So if we can expand the cost of that, then that's potentially an area that we can win against the bad guys.
Q. Does AI really democratize cybercrime if using it still costs money?
A. The economic cost of AI is something that everyone is starting to wrestle with. Yeah, we're all becoming addicted to the use of AI as companies, as enterprises, but we're starting to wrestle here: how many tokens are we spending? How do we pay for this? Could cost increase in the future? So, the threat actors actually are going to be facing exactly the same costs and challenges. This feels like, on the surface, democratizing access to all this maliciousness, but there is still a cost associated with that.
Q. Are attackers finding ways around the cost of commercial AI services?
A. We’ve seen people stealing companies' API keys for OpenAI and use them to get unfettered access. If suddenly you had a threat actor that had access to that, we would see that spike very quickly and would be able to lock that down. That will probably become less of a factor over time as we get more mature in understanding what we're spending in these different spaces.
Q. With so much attention focused on AI, what threat should organizations still be most concerned about today?
A. Ransomware continues to be the thing to be worried about. It's the thing that we see most often that has the most impact. So persistent.
Q. What does the current ransomware ecosystem look like?
A. We try to track all the ransomware groups. We generally are seeing about 50 active groups a month continuously. We're seeing about four, four to six new groups appear every month. So obviously, the fifth is staying fairly constant. As we see new groups, old ones die off.”
Q. Are ransomware groups succeeding because of sophisticated new techniques?
A. Again, there’s nothing particularly new or novel about what they're doing. It's still exploiting vulnerabilities and stolen credentials from info stealers. Last month there were 11 million stolen credentials available on the Russian market for sale. About four years ago, that was about two million. In most ransomware instances we see, it will start with someone just logging into a VPN server or something that's not two-factor authentication-enabled. Or, it will be an exploit of a firewall that wasn't passed or something like that.
Q. Are you seeing ransomware groups experiment with different attack paths?
A. The interesting one is TeamPCP. In terms of some of the more interesting tactics, they've been doing the open source software supply chain. They’re compromising NPM modules in open source then having a whole chain of things where they compromise a vulnerability scanner. Then a bunch of companies downloaded and installed that. From there the group stole secrets and compromised further victims. They have been taking a novel approach to ransomware rather than just the usual info-stealer and vulnerability exploit.
Q. Why could open source software become particularly vulnerable to AI-enabled attacks?
A. TeamPCP is demonstrating there is a lot of trust and vulnerability in the open source community, so you have to trust. Every company is using open source software. You're not always rigorously monitoring everything, every package that you're downloading. If you start getting AI involved in that, and start understanding the sphere and where the vulnerabilities are and can I socially engineer vulnerabilities, that's one area that you could see explode with the use of AI that we haven't really spoken about much before.
Q. What makes the open source ecosystem potentially difficult to defend as AI becomes more capable?
A. It’s a whole ecosystem based on trust and based on humans being able to monitor what's going on. That we trust all the submissions that are going on, and that humans will catch that.
Q. Could AI itself become part of the defense against malicious AI contributions?
A. What we need to do is like we're doing with Mythos and others, having the models look at the AI submissions, so that if there's malicious AI submitting things, the AI models can track that. I'm not heavily into the open source community. I don't know how much they're doing with that, but it's definitely an area we need to be looking at.
AI is beginning to change cybersecurity, but the interview suggests that its most significant impact may initially be acceleration rather than reinvention. Threat actors can use AI to iterate more quickly, while defenders can employ the same technology to identify vulnerabilities and potentially uncover complex chains of weaknesses. That dynamic creates an arms race in which both sides are experimenting with the same rapidly advancing capabilities.
For defenders, one of the more immediate challenges may be determining intent. Legitimate AI agents can perform unusual actions that resemble malicious behavior, triggering detection rules built around assumptions about how humans normally operate. As that distinction becomes less clear, identifying an isolated suspicious action may no longer be sufficient. Security teams may increasingly need to correlate sequences of activity and determine whether the intent behind that behavior is benign or malicious.
There may also be new opportunities for defenders. AI-driven attacks still consume compute, time, and tokens, and attackers do not necessarily have unlimited access to the most capable models. Yule raises the possibility that deception could deliberately increase the work an attacking agent must perform, potentially turning the economics of AI into another defensive tool.
At the same time, organizations cannot allow anticipation of future AI threats to distract them from the risks already causing damage. Ransomware remains persistent, and familiar weaknesses such as stolen credentials, unpatched systems, and inadequate authentication continue to provide attackers with paths into organizations. Meanwhile, emerging risks—including AI-assisted exploitation of trust within open source ecosystems—give defenders another reason to prepare for what comes next.
The central challenge, then, is to prepare for AI without getting ahead of the evidence. Organizations need to strengthen the fundamentals that matter today while developing the detection, patching, behavioral analysis, and AI-enabled defensive capabilities they may need tomorrow. As attackers and defenders continue to experiment, the advantage may ultimately belong to those that can distinguish the hype from the threat—and adapt quickly when experimentation becomes operational reality.