Russian espionage group Midnight Blizzard just demonstrated the nightmare scenario every CISO feared.
They deployed AI agents that monitor whether their malware gets detected by security products.
When it does, the agents autonomously modify, rebuild, and redeploy the malware until it's undetected.
Then they stage it for live operations.
Anthropic's threat intelligence team documented this in a September 10 report covering December 2025 through August 2026.
The defender's cycle used to work like this: detect malware, build signature, deploy block, cost the attacker time and money.
That cycle is now broken.
AI has closed the loop on the attacker's side. They no longer need skilled operators to iterate on evasion. The agents do it autonomously, at machine speed, continuously.
Your SOC was built for a world where attackers operated at human speed. That world no longer exists.
The same report documented Chinese university students running autonomous exploit foundries. AI agents that reverse-engineer security products, find zero-days, and write working exploits. Around the clock. Without human intervention.
One group targeted roughly 50 organizations across education, energy, healthcare, and government.
Audit your threat model today. If it assumes attackers operate at human speed, it is already obsolete.
SOURCE: https://www.anthropic.com/threat-intelligence-report-september-2026
VERIFIED: Anthropic Threat Intelligence Report (Sept 10, 2026), Shattered.io coverage (Sept 13, 2026), BBC News (Sept 11, 2026)
SIGNAL: The cost asymmetry between attacker and defender has permanently shifted. Enterprises still budgeting for human-speed threats are exposed.
AI just inverted the economics of cyber defense. Attackers rebuild faster than you can detect.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments