The images in this article were generated with artificial intelligence. How we publish
Technology has always extended the distance between decision-makers and executes; now that distance has become mobile. The so-called IA agents are no longer attendees who write a mail or sketch an explosion for a human to execute: they are systems that can pursue a step-by-step objective, make routine operational decisions and complete campaigns without constant intervention. The real change is not that the tools are better, but they move from writing to acting., and that transition transforms both new attackers and experienced operators.
For opponents without technical training, the availability of smart agents means that expertise becomes less relevant: intention and access to the right tool is sufficient. This can be called, with crudely, "Kiddie script service": an economy where sophisticated attacks emerge from unexperienced hands. At the same time, experienced groups find in these agents a speed and parallelism lever that compresses weeks of work in hours. More competent attackers and much faster attacks explain why the risk area is expanding today faster than traditional defences.

A pedagogical and dangerous example is autonomous social engineering: an agent collects public information about a target, manufactures a credible profile and then another agent starts and manages a personalized conversation until the goal is achieved. What disappears is not the infrastructure - it remains the reputation of the sender or technical signals - but the language and scale tracks that previously facilitated detection: unique, correct and rooted messages in real facts. The silent death of the classic phishing "tells" requires the movement of detection to authentication and reputation controls and the assumption that these controls will be under tension.
Automation is not limited to emails: the generation and channelling of exploits by models that know how to interact with environments and correct themselves changes the vulnerability equation. Linking models with CVE databases or with asset telemetry allows an agent to prioritize white, select exploits and propose executions with an appearance of judgment. But here comes the epistemological failure: the agent predicts plausibility, does not verify context. Trust "what seems" to work; lack the prudence to confirm that the service is accessible or the affectable version and that creates different risks for attackers and defenders.
For organizations the response cannot be only perimetric or purely regulatory. Practical experience shows that ordering policies and hardening systems is necessary but insufficient until someone tries to break them with the same tools that attackers use. In this sense, strategies for governance, protection and use of IA must coexist: govern to define limits, protect critical platforms and use IA to test and strengthen defenses. A policy is theory; the actual test occurs when an operator - internal or external - puts it under pressure with real tools.
In operational terms, there are concrete measures that reduce the exposure window: strengthen authentication and signed in mail (SPF, DKIM, DMARC) and combine these barriers with detection based on session and behavior authenticity, maintain asset inventories and robust telemetry that allow for correlated suspicious activity, and increase the practice of red-blue exercise to include IA agents as part of emulation. But none of these lines work without the critical human element: the ability to judge to discriminate between a plausible conclusion and a verified truth. The last effective barrier remains a person's informed decision.
It is also essential to incorporate model risk management into the supply chain: to audit model suppliers, to limit code generation capacities in productive environments, to control access to APIs and to prevent sensitive telemetry from leaking to automatic recovery systems. Similarly, defending itself requires security teams to learn to use agents: not to delegate responsibility, but to understand the emerging signatures of the "monoculture" of attacks and to be able to replicate, anticipate and mitigate common tactics before they climb.

The convergence of adversaries in patterns generated by the same models creates a defensive opportunity if it is exploited with intelligence: detection of repetitive features in delivery chains, analysis of conversational behavior and correlation of operating activity that identifies automated templates. However, advanced actors will vary these templates, so the defense should combine anomaly detection, updated threat intelligence and continuous emulation exercises. The advantage is not only on who has the tool, but on who knows how to force it and how to read its failures.
At the organizational level, the recipe goes through three inseparable fronts: clear governance with operational limits and responsibilities, technical protection of infrastructure and data, and use of the IA for authorized and proactive defensive offensive. Integrating these pieces requires investment in practical training (not just frameworks and policies) and in real simulations where human decisions are tested under the pressure of agents acting for themselves. Institutions such as SANS offer training routes, and public-private reference frameworks such as those developed by NIST help structure the risk management of IA.
The final message is simple and demanding: the weapon can aim alone; the judgment is not. The strategic bet of the coming years will be to cultivate the human criterion, to continuously adapt the defenses to the pace of automation and to test our walls with the same tools used by the adversaries.. Without this combination, organizations will be only one step behind, and in security that step is often enough to turn an intrusion into a greater commitment.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...