AI Is Killing the Zero-Day and Stalking You Instead
Why the AI security arms race favors defenders, and why the future of hacking looks less like exploiting code and more like AI-automated OSINT and social engineering.
AI Code Security
According to CVE.org, there have been 35,872 new CVEs published so far in 2026. Comparing that to 48,244 for all of 2025, we can do some advanced statistical analysis and determine that if this trend holds there will be roughly 415,146 new CVEs published in 2027. I’ve made a graph of my analysis:

Now, obviously that’s not going to happen. Anyone who has spent time in the security industry knows that graphs and metrics like this are great at raising shareholder value, but not actually how the world works. This graph is a little better, and is closer to what will actually happen:

That spike in new CVEs is real, and is a direct result of one thing: AI has gotten pretty darn good at static code analysis in the last year. Reading through a codebase looking for known-vulnerability patterns is exactly the kind of narrow, well-defined task AI is good at, and it’s tearing through years of backlog as a result. A code security review that used to take a person weeks or months now takes an agent minutes. Even sophisticated projects with experienced, security-conscious maintainers (like the Linux kernel, for instance) aren’t immune, since modern models can comb through the codebase and surface things that got overlooked for years.
However, the plateau at the end is equally real, and much more important. The reality is that once AI clears out that backlog there’s simply less left to find. It stands to reason that at some point AI will have cleared out so many new and existing vulnerabilities that there just won’t be that many left to be found and exploited. Unfortunately, that doesn’t mean attackers are just losing. It means the fight moves somewhere code security tools can’t follow it. Right now, there is so much hype around whether Claude Mythos can hack the Pentagon, but what happens to the balance of power between attackers and defenders once code itself stops being the soft target?
So, who actually benefits from this advancement?
There are exactly three ways of answering that question.
- The hackers benefit the most because it closes the skill gap.
- The defenders benefit the most because it fixes problems faster.
- It’s a wash because both sides get equally stronger.
The Hackers
Many people in the cybersecurity industry are of the opinion that threat actors (bad guys) are the ones who will most benefit from the advent of cybersecurity AI tooling. That isn’t an incorrect assessment. There have been many documented examples of threat actors using AI to develop zero-day vulnerabilities. Google’s Threat Intelligence Group (GTIG) recently confirmed that they had identified a threat actor that had developed a zero-day vulnerability in this way. While AI is getting more sophisticated (and the attacks are as well), the most common use of AI by hackers is as a way to bridge the gap in their knowledge of exploitation. No longer does a script-kiddie need to actually know how to run cybersecurity tooling to detect and exploit vulnerabilities. Now, they can point an AI agent at a site and have the agent look for those vulnerabilities. GTIG has even observed actors prompting models to build out detailed org charts of a target company’s finance and HR departments, all in service of “higher-fidelity phishing lures tailored to individuals with administrative privileges or access to sensitive data.”
The Defenders
Others in the cybersecurity industry believe that AI advancement will end up positively impacting defenders more than attackers. By leveraging AI, defenders can find code vulnerabilities, logic errors, and system misconfigurations at a rate previously impossible. It is amazing what a small team properly leveraging AI can actually accomplish. In 2025, Google’s “Big Sleep” AI agent autonomously identified a critical SQLite zero-day, and actually resolved it before it could be exploited. Google called it the first time an AI agent had been used to “directly foil efforts to exploit a vulnerability in the wild.”
But Big Sleep isn’t operating on a level playing field, and that’s kind of the point. Defenders pointing AI at their own codebase get to hand it the source, the test suite, the commit history, and whatever legacy knowledge is sitting around in Slack and Jira tickets. Attackers get a black box and whatever they can scrape off the internet. That home-field advantage isn’t new, security teams have always had it, but AI is what actually lets them use all of it at once instead of a few engineers manually working through it. That’s a structural advantage attackers just don’t get to have.
Net Zero
Finally, there is the argument that both attackers and defenders are being made just as strong as each other. Earlier this month, I read an interesting blog post from a security engineer about Claude Mythos. Jake’s argument is that “both attackers and defending software engineers would have the same net advantage, resulting in a net-zero change for the game theory behind attacking infrastructure”. This was a very interesting way to look at the problem, and it’s probably more correct than most people think.
Why Code Security is Defense Leaning
While it is true that AI augments the capabilities of both attackers and defenders, my opinion has always been that the defenders actually have more to gain from AI specifically in the realm of code security. As AI continues to get more and more sophisticated, and adoption of AI cybersecurity tooling becomes the industry standard, I believe that we are going to see a steep reduction in the existence of code vulnerabilities. Eventually, AI agents will be able to detect and resolve the vast majority of code vulnerabilities and logic bugs. It doesn’t matter how advanced an AI hacker is if there are no vulnerabilities in the code.
Now, obviously we are never going to get to a point where software never has vulnerabilities. Anyone trying to sell you on that future is lying. There will always be vulnerabilities in software. The point I am making is that AI is getting better and better at removing code vulnerabilities specifically. This is a large subset of existing and possible vulnerabilities, however. Over time, software will naturally trend towards being more and more secure, requiring larger and larger investments from attackers to use AI to find vulnerabilities and exploit systems.
This is where I think Jake’s net-zero framing needs a caveat. I don’t think attackers and defenders are staying locked in an even fight so much as the fight itself is being redistributed. Defenders are winning the code war. But that doesn’t mean the overall balance of power is staying flat, it just means the fight is relocating somewhere else entirely. If code stops being the path of least resistance, attackers will just pivot to what is. And the next path of least resistance isn’t a computer. It’s a person.
So What’s Gonna Happen?
Generally, I try to refrain from making guesses about hypothetical futures. That being said, I actually feel somewhat confident in this prediction. My guess for the future of AI in cybersecurity is that social engineering will take the throne. Social engineering is already the most widely used exploit on Earth. The vast majority of cybersecurity risk comes from people, not computers.
Last month, I wrote a postmortem on BYUCTF2026 where I mentioned my experience using AI agents to automate the solving of Open-Source Intelligence (OSINT) CTF challenges. As a self-proclaimed OSINT enjoyer, over the last year I have been astonished at how rapidly AI agents have improved in their ability to solve OSINT challenges. At this point, you can give an agent about 50% of OSINT CTF challenges, and it will one-shot them. Another 20% need human interaction to lead it along. The last 30% can not yet be solved with AI. AI will only get better at OSINT, which is why I believe that the future of AI cybersecurity attacks will revolve around an agent doing automated OSINT to assist in the creation of social engineering attacks.
The AI Generated Hack of the Future
This is how I suspect the AI generated social engineering attack of the future will work. We can split this into two parts.
OSINT Profile Analysis
The first step in any good social engineering attack is gathering intelligence on your target. If you’ve never tried doing this to yourself online, you will probably be bothered by just how much information about you is out there on the open internet. Using a simple web browser and OSINT skills, an AI agent would be able to look deep into your online presence. It could find where you work, where you live, what you do for fun, where you went to dinner with your wife last week, what league your 11-year-old daughter plays softball in, etc. With all of this data about you, creating a profile about who you are as a person is pretty simple. Enjoy my extremely advanced graphic showing how this works:

I believe that the best approach will likely be using multiple agents with specific tasks. Agent #1 can be extremely cheap, with its only real purpose being to find relevant data and scrape it. Agent #2 does a lot of the legwork of analyzing the scraped data, and creating a coherent profile. This is probably the most expensive part, as this analysis can get pretty large.
Phishing Campaign
That personalized profile matters a lot. Generic phishing works because a small percentage of people fall for a bad Nigerian-prince email. Personalized phishing doesn’t need a percentage, it just needs to know you well enough to sound like someone you already trust. An email that references the restaurant you went to last week, or asks about your daughter’s softball tournament, doesn’t trip the same mental alarms a “Dear Valued Customer” email does. You’re not being asked to trust a stranger. You’re being asked to trust something that already sounds like it knows you, because it basically does.
That’s the actual shift here. The old model of phishing was volume, spray a million emails and hope a handful land. The new model is precision, one extremely well-informed email aimed at exactly the person likely to click it. That style of social engineering is not new. Very smart researchers have been combating spear phishing for decades. The difference is that unlike a human social engineer, an agent can build that kind of profile and write that kind of email for thousands of targets simultaneously, at basically no marginal cost.

Right now, most commercial frontier LLMs are pretty hesitant to actually do any of this, but getting around these safeguards is pretty trivial if you know how to ask. With a little bit of persistence and luck, you can get most LLMs to do whatever you want them to but I don’t think that’s a permanent state of affairs. Guardrails on individual models will keep improving. Even so, the moment even one capable open or fine-tunable model doesn’t have them, the whole safeguard conversation becomes kind of moot because the bar to run this pipeline drops to whoever’s willing to look for the model that follows orders.
What does this mean?
Anyone who tells you that they know what AI is going to do is lying to you. Not even Sam Altman or Dario Amodei truly knows where AI is heading. As such, I could very well be 100% incorrect. However, I do truly believe that social engineering is the attack of the future. AI will only make social engineering attacks easier and easier to pull off. The bright side is that AI is also being used to defend against social engineering attacks. Just like with code security, attackers doing OSINT-driven social engineering get a black box (in a different sense). They’re scraping public data, guessing at what will work, and hoping it is realistic. Defenders, meanwhile, get to see the attack after it’s already been tried a thousand times against a thousand other companies. We even have things like AI deepfake detection at firms like Sensity AI and Reality Defender, anomaly detection with companies like CrowdStrike and Microsoft, and even using AI in security awareness training at KnowBe4.
So maybe the real answer isn’t “attackers win at social engineering because we fixed all of our code.” It’s probably just that the fight relocates again, and this time the question is whether detection systems can generalize as fast as personalized attacks can be generated.
All hope is not lost, but I do believe that this is the future of cyber attacks. While the tech world is so caught up with whether or not Claude Mythos can hack the Pentagon, it has largely ignored the longer term issue.
Autonomous social engineering is the future.