
Every week brings a fresh headline about AI supercharging cyberattacks, usually accompanied by an unstated assumption: that criminals now have some novel, almost magical capability. Dray Agha, who leads security operations at Huntress and spends his days watching real intrusions unfold in real time, offers a more grounded, and arguably more alarming, picture. The change isn’t that attackers can do fundamentally new things. It’s that the things they’ve always done now happen at a speed and scale that breaks the assumptions most security programmes were built on.Â
Here, he walks through what that compression actually looks like on the ground, why AI-powered defence isn’t a simple answer to AI-powered offence, and what he thinks security leaders are still getting wrong.Â
When people say AI is making cyberattacks worse, what do you think they usually get wrong about how that’s actually playing out?Â
People assume attackers are using AI to create entirely new super-weapons. From what we observe of cybercriminal tradecraft at Huntress, attackers simply use it to do the tedious work faster and at scale. They automate target research and initial access so they can hit thousands of organisations at once.Â
Can you walk through, in practical terms, what “compressing the timeline from vulnerability to impact” looks like? What used to take days or weeks now takes hours or minutes?Â
Previously, when a new vulnerability was announced, criminals spent days writing exploit code and scanning for victims manually. Today, a cybercriminal can point automated tools at generating usable code and scanning the entire internet for vulnerable systems within minutes of public release. The window between a patch becoming available and an active compromise has effectively collapsed to zero.Â
Is there a specific pattern you’ve observed where AI-accelerated timing was the decisive factor, rather than a new technique?Â
We consistently see attackers compromising networks through carefully cultivated phishing attempts, where AI has curated a convincing social engineering email or website. The decisive factor is the speed and specificity AI gives cybercriminals. They can research a company and its stakeholders, craft phishing pages and fake websites using its branding, and build lures that trick users into handing over passwords or running malicious commands.Â
Which parts of the attack chain are attackers using AI to accelerate most right now? Reconnaissance, exploit development, lateral movement, something else?Â
Reconnaissance and initial outreach are seeing the biggest acceleration right now. Attackers use automated tools to scrape employee data, write tailored social engineering emails, and discover exposed network assets. Once they’re inside a network, hands-on-keyboard human tradecraft still dominates lateral movement.Â
How is this changing the calculus for identity, endpoint, and remote-access gaps specifically? Why are those three areas under the most pressure?Â
These three areas form the primary entry points into any organisation. Attackers focus on weak passwords, missing multi-factor authentication, and unpatched edge devices because they offer the fastest path inside. When automated tools scan these access points continuously, any small gap is guaranteed to be found immediately.Â
Are attackers using AI in more mundane ways, like automating phishing at scale or faster scanning, more than exotic ways like AI-generated exploits? Which should defenders be more worried about?Â
Mundane automation is by far the bigger threat today. Custom AI exploits sound dramatic, but high-volume phishing and rapid vulnerability scanning are what actually breach networks every day. Defenders should focus on basic security hygiene rather than worrying about theoretical, sci-fi-style threats. Â
There’s a common assumption that the answer to AI-powered attacks is AI-powered defence. Where does that assumption break down?Â
Software alone cannot understand business context or decide if an unusual administrative action is legitimate. Algorithms generate thousands of alerts, but human analysts must still investigate and make the final decision. Relying entirely on automated defence without human oversight simply creates a false sense of security. You cannot agentically abdicate accountability. Â
If AI, automation, and human expertise need to work in symphony, what does that actually mean in practice? What’s the human doing that the AI can’t?Â
The work we do at Huntress is a good case study. Machines provide speed, but humans provide direction and accountability. We leverage automation to handle the repetitive noise, filtering out benign activity and collecting context on suspicious events, while the human analyst provides judgment, nuance, and critical thinking when deciding how to respond without disrupting business operations.Â
How does more than a decade of real attacker behaviour data change what AI-assisted defence can actually catch, versus a system trained on theoretical threat models?Â
Real historical data grounds security models in what adversaries actually do, rather than what they might do. Theoretical models often trigger endless false alarms on rare edge cases that criminals rarely use. Training on genuine operational data helps systems spot subtle patterns of compromise accurately without overwhelming defenders. Â
What’s one thing security leaders are still underinvesting in because they don’t yet appreciate how much the timeline has compressed?Â
Rapid patch management and asset discovery are still severely underfunded in most organisations. Many leaders still operate on monthly patch cycles, which leaves them exposed for weeks after a vulnerability is made public. When attackers move in minutes, fundamental patch speed becomes the most critical control you have.Â
Where do you expect this arms race to go in the next 12 to 18 months? Does the timeline keep compressing, or does it plateau once both sides are using AI?Â
The timeline for initial discovery will plateau, because network scanning can only go so fast. The next shift will be automated containment, where defensive systems isolate compromised endpoints instantly. Success will depend on which side can execute its response loop faster. At Huntress, we’re experimenting with what ‘minimum viable disruption’ looks like for response in an agentic world. We want threats contained at machine speed, with a conscientiousness toward the human and business needs disrupted by heavy-handed containment. Â
Is there a genuinely underappreciated risk here that isn’t getting much media attention yet?Â
It’s spoken about, but it isn’t the headline. The major risk is defender burnout caused by sheer alert volume. As automated attack tools generate constant low-level noise, internal IT teams struggle to keep up with investigation duties. That constant fatigue leads directly to missed warnings and delayed response times. Â
If you had to give one practical, non-vendor-specific piece of advice to a CISO reading this, what would it be?Â
Enforce multi-factor authentication rigorously on every remote access portal and administrative account. At Huntress, we see roughly 70% of active cybercriminals break into VPNs and identities because MFA and additional authentication hurdles are completely absent. If an attacker cannot easily bypass your identity controls, all their speed and automation cannot get them through the front door. Strong identity verification ruins their criminal business model instantly.
What comes through in Dray’s answers is a consistent theme: The AI security story centres on speed and scale collapsing the margin for error, rather than any exotic new attack capability. The fundamentals such as MFA, rapid patching, strong identity controls matter more than ever, not less, precisely because AI has removed the delay that used to give defenders room to catch up. For security leaders, the takeaway isn’t to chase the newest AI-powered tool, but to make sure the basics can’t be exploited in the minutes attackers now have to work with.Â
 Â



