Library Header Image Library Header Image

The New Speed of Cybercrime


Posted on by Tatyana Sanchez

Key Takeaways:
  • Attack speed has collapsed from 8 hours to 22 seconds, as AI drives faster, more coordinated cybercrime.
  • AI's own hallucinations are creating new attack surfaces—from slopsquatting to phantom domains.
  • As agentic AI adoption grows, human-in-the-loop controls and dedicated governance frameworks are essential.

The collapse: From hours to 22 seconds

Threat actors are increasingly embracing AI to increase the speed and scale of attacks, with an 89% increase in attacks from AI-enabled adversaries. "In a recent 2026 M-Trends report, we've found the median time between initial access and the hand-off to the secondary threat group has dropped from eight hours in 2022 to 22 seconds in 2025," said Sandra Joyce, VP of Google Threat Intelligence at Google Security, in an RSACTM 2026 Conference Keynote.

Cybercriminals now coordinate hand-offs before the initial breach even occurs, whereas before, criminals would breach an organization, steal data, and then look for a buyer afterward. This shift signals a move toward a more industrialized, assembly-line model of cybercrime—one where speed and pre-arranged coordination matter as much as the breach itself.

We're already seeing real-world proof of this shift, infrastructure attacks like Stryker are being targeted by nation-state actors using AI to accelerate reconnaissance and exploitation. Also, MFA phishing attacks continue to increase due to AI tools, especially as hackers utilize AiTM (Adversary-in-the-Middle) attacks to bypass authentication.

That's why it's critical for organizations to build and foster a strong security program and a strong AI governance program. Today, AI governance sits at the center of everything—cybersecurity, privacy, compliance, and business risk.

New AI Attack Vectors

Slopsquatting is a new type of software supply chain attack that exploits AI-generated hallucinations, in which an LLM invents a package name that doesn't actually exist. The model confidently recommends this nonexistent package name and an attacker pre-registers that name on npm, PyPI, or another public registry before a legitimate package can claim it, often loading it with malicious code. When a developer, or an AI coding agent acting on their behalf, later runs the install command the model suggested, it fetches and executes the attacker's package instead of failing safely, since the name now genuinely exists in the registry.

The scale of this danger was highlighted by researchers at the University of Texas at San Antonio, the University of Oklahoma, and Virginia Tech, who found that out of the 2.23 million code samples, 19.7% of the samples they ran contained at least one hallucinated package name—meaning roughly one in five AI-assisted code suggestions points to a package that does not exist.

Phantom squatting is an emerging AI security threat identified by Palo Alto Networks' Unit 42 researchers. This threat applies the same hallucination logic seen in slopsquatting to a new attack vector: large language models (LLMs) consistently hallucinating web domains for legitimate, well-known brands. Threat actors are actively weaponizing this behavior by registering these nonexistent, AI-hallucinated domains to intercept traffic generated by AI systems and unsuspecting users searching for trusted brands.

To measure the scale of this risk, Unit 42 researchers analyzed 913 global brands and executed 685,339 URL queries across multiple configurations of two distinct LLM models. This testing generated 2.1 million hallucinated URLs, of which over 13,229 were confirmed malicious—revealing phantom squatting as a significant and growing AI-driven cybersecurity risk, and underscoring how LLM hallucinations are becoming a systemic vector for domain-based phishing, brand impersonation, and traffic hijacking attacks.

Another newly discovered exploit chain, AutoJack, discovered by Microsoft researchers, turns an AI browsing agent's local service into a delivery vehicle for remote code execution. Once an attacker gets the agent to load their page, the attacker can reach privileged local services on the same machine and spawn a process on the host. No credentials or MFA are needed—the attacker only has to get the agent to open the page. From there, the attacker can utilize a planted link, a URL field, or a prompt injection to launch the attack.

Zero-Human-in-the-Loop is the Real Escalation

Organizations are rapidly utilizing agentic AI to automate workflows and execute tasks on their behalf. Industry analysts project that by 2028, at least 15% of day-to-day business decisions will be made autonomously by AI agents.

Autonomous AI helps organizations offload routine work and focus human attention on higher-value challenges, however, this shift raises a critical AI governance question that Anthropic's AI Safety and Preparedness Framework puts directly: should every capability that can be automated, be automated?

Anthropic has argued that frontier AI development requires predefined safeguards and coordinated response protocols—particularly if future systems begin exhibiting dangerous levels of autonomous capability or self-improvement that could outpace human oversight. This is the foundation of the human-in-the-loop approach to AI security.

A recent security incident underscores why human oversight remains essential. Hugging Face, a leading open-source AI platform, disclosed a security breach involving an autonomous AI agent that accessed internal datasets and credentials by exploiting vulnerabilities in its production infrastructure. While no public-facing models or datasets were affected, attackers compromised internal clusters and cloud credentials. The most concerning thing is that no human directed the attack. This report is the CSA CISO community's initial post-mortem on the first publicly documented [incident of its kind / AI-agent-driven breach].

This breach illustrates how AI-enabled autonomous agents can be exploited to carry out highly sophisticated, multi-stage cyberattacks—reinforcing why continuous human oversight of agentic systems is non-negotiable, not optional.

To mitigate the risks of unsupervised autonomous AI, organizations should establish human-in-the-loop controls as a default requirement for any agentic AI workflow with access to sensitive systems or data. Organizations should also create a separate Agentic Identity and Access Management (IAM) framework specifically for autonomous software acting on behalf of human users and treat AI governance as a fundamentally distinct discipline from traditional software or identity governance, given the unique risk profile of self-directed AI agents.

AI Governance

This human-in-the-loop approach was echoed at RSAC 2026, where Gibb Witham, President of Hack The Box, and Gerasimos Marketos, Chief Product Officer of Hack The Box, presented results from an AI vs. human Capture-the-Flag (CTF) benchmark showing that human-AI collaboration is the best possible strategy. Based on those findings, they recommended organizations:

Identify 2–3 security workflows where their team is experimenting with AI, and map where those workflows still require human validation, escalation, or decision-making.

Define which tasks are safe for AI assistance versus unsafe for autonomous execution.

Redesign at least one workflow around human + AI collaboration, then pilot it and measure speed, quality, and failure patterns.

Putting these practices into place raises a broader question: as agentic AI continues to increase in speed and attack surface, how can organizations keep governance in step? According to a study published by Georgetown University's Center for Security and Emerging Technology, one of the best ways to curb the risk created by overreliance on automated systems is to "create and maintain qualification standards for user understanding," and to design, review, and consistently update AI-related policies.

Several free resources can help organizations put this governance into practice. In an RSAC 2026 Conference presentation, Akila Srinivasan, Member of Technical Staff, Manager at Anthropic highlighted CoSAI, the Coalition for Secure AI—an OASIS open project building open source frameworks, tools, and reference architectures that any organization can adopt to secure AI systems. Srinivasan noted that AI workloads are already in production across most enterprises, but security guidance hasn't kept pace: traditional software security assumes well-defined inputs, known dependency chains, and deterministic behavior, while AI systems depend on large training datasets, complex pipelines, new serialization formats, and natural language interfaces — introducing attack surfaces that existing frameworks were never built to address.

Organizations should look to CoSAI, along with other emerging AI regulations and standards, since it creates and shares practical security guidance, tools, frameworks, and reference architectures that support securing AI systems from development through production.

To learn more about governance around AI, we invite you to visit our RSAC library.

Contributors
Tatyana Sanchez

Senior Coordinator, Content & Programming, RSAC

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs