AI broke cybersecurity: here’s what one pentester wants fixed first

Less has changed at the vulnerability level than the headlines suggest, and more has changed at the speed and coverage level than most defenders have adjusted for. Field notes from a working pentester on what to fix first.

Pentesters spend their working hours doing what real attackers do, on a schedule, with a report due at the end. That vantage point is useful right now, because it separates what has actually changed in offensive practice from what is just AI marketing noise. The honest answer: less has changed at the vulnerability level than the headlines suggest, and more has changed at the speed and coverage level than most defenders have adjusted for.

What has genuinely gotten easier for attackers

Reconnaissance and enumeration used to be the slow, unglamorous part of an engagement: mapping subdomains, correlating leaked credentials, reading through a target’s public code for hardcoded secrets. AI-assisted tooling has compressed that phase dramatically. Work that took a day of manual grinding now takes an hour of prompting and review.

Report writing and pretext generation have also gotten faster, which sounds cosmetic but is not: it means more engagements per tester, and for attackers, more targets per campaign.

What has not changed

Getting from initial access to meaningful impact still depends on the same misconfigurations it always has: flat networks, over-permissioned service accounts, unpatched internal systems, and credentials reused across environments. AI tooling accelerates the path to the door. It has not made the doors easier to walk through once you are inside.

The fix that matters most: assume faster reconnaissance

If an attacker’s map of your external footprint used to take them a week to build and now takes an afternoon, the honest response is not a new tool purchase. It is closing the gap between something appearing on your attack surface and you knowing about it. A forgotten staging subdomain that used to sit unnoticed for months is now found on day one by anyone running the same enumeration an attacker runs.

The fix that matters second: stop assuming lateral movement will be slow

Segmentation, least privilege, and credential hygiene were always good advice. They are now load-bearing in a way they were not before, because the phase of an attack that used to buy defenders detection time, an attacker fumbling around a network they do not know well, is the phase getting compressed hardest by AI-assisted tooling.

What to leave alone

Do not rip out signature-based tooling entirely; it still catches the large volume of unsophisticated, automated attacks that make up most real-world traffic. Do not chase every new AI-labeled security product either. The fundamentals that closed real gaps five years ago still close the same gaps today. What has changed is the cost of leaving them open.

Free Download

Stop experimenting. Start shipping.

The prompt patterns and bot blueprints our cohort learners use to automate real workplace tasks, including Copilot prompts that hold up.

Free PDF · No spam · Unsubscribe anytime

Send me the prompt pack

Leave a Reply

Your email address will not be published. Required fields are marked *