An Extortion Group Has Been Breaking Into Companies Worldwide This Year Using a Tool Built Into Every Web Browser: View Source
AI THREAT DEFENSE GAP RESEARCH SEPTEMBER 2026 · 8 MIN READ
Eighteen months ago, the best publicly tested AI systems could barely get started on a realistic simulated cyberattack.
By early 2026, the best one tested was averaging nearly half of the attack sequence.
The estimated cost of attempting the entire exercise: about $87.
That last number may matter more to a small business than almost anything else in the report.
This is not a story about an AI system independently breaking into a company from beginning to end. The government researchers who ran the tests specifically said today's public models still could not reliably do that.
It is a story about something more immediate: how quickly the cost, skill and time required to perform parts of an attack are falling.
And that creates a problem for businesses whose defenses still move almost entirely at human speed.
The Test Was Designed to Look Like a Real Attack
A UK government cybersecurity agency recently published results from testing advanced AI systems against simulated enterprise environments.
One of the scenarios contained 32 separate steps and was designed to resemble the kind of multi-stage work a skilled security professional might perform while attacking an enterprise network.
Researchers estimated that a human cybersecurity expert would need approximately 14 hours to complete the full exercise.
Eighteen months earlier, the strongest AI systems tested could complete fewer than two of the steps.
By early 2026, the best-performing system averaged 15.6 of the 32 steps when given additional processing time.
Its best individual run reached 22 steps.
No publicly available system tested had completed all 32 steps from beginning to end.
In roughly a year and a half, AI went from barely beginning the exercise to completing a substantial portion of an attack sequence that researchers estimated would require many hours of skilled human work.
Then There Is the $87
The original government report estimated that a full attempt at the exercise cost approximately £65 in AI processing.
At current exchange rates, that is about $87.
Think about what that means economically.
Traditionally, sophisticated cyberattacks have been constrained by something attackers cannot manufacture infinitely: skilled human time.
A person has to research the target. Understand its systems. Test possible weaknesses. Adjust when something fails. Decide what to try next. Repeat the process.
That creates friction.
AI doesn't have to eliminate the human attacker to change the equation.
It only has to make that attacker dramatically more productive.
If an AI system can perform reconnaissance, test weaknesses, interpret results, write code, troubleshoot failed attempts or complete other portions of the attack chain, one skilled person can potentially attempt far more activity than before.
And if each attempt costs tens of dollars rather than hours of specialized labor, attackers can afford to try more often.
That Is the Part Small Businesses Should Pay Attention To
The cybersecurity conversation around AI often jumps immediately to the most dramatic question:
Can an AI system autonomously hack a company?
That isn't yet the most useful question.
A better one is:
How much more attacking can one person do when AI performs part of the work?
Government cybersecurity analysts expect AI to make intrusion activity increasingly efficient, particularly in areas such as reconnaissance, vulnerability research, exploit development and exploitation of known vulnerabilities.
They also warn that the time between a vulnerability becoming known and attackers exploiting it is likely to shrink further.
That matters enormously to a small business.
Because Your Defense Process Probably Still Looks Like This
A vulnerability is disclosed.
A scanner eventually finds it.
Someone reviews the scan.
The finding gets added to a list.
An IT provider or employee decides how important it is.
Someone schedules the work.
The system eventually gets updated.
None of those steps is unreasonable.
The problem is the clock.
If attackers can use automation and AI to identify, test and exploit weaknesses faster, a perfectly reasonable human workflow can become too slow without anyone actually doing anything wrong.
Attacker capability is improving rapidly. Most small-business defensive processes are not improving at the same rate.
The Researchers Also Found Something Reassuring
Today's AI systems still have meaningful limitations.
They can lose track during long operations. Results can vary substantially from one attempt to another. They remain weaker in specialized areas. Complex coordination is still difficult.
And researchers noted something particularly important for defenders: current AI-driven attack activity often creates noticeable security signals.
In an environment with good monitoring and the ability to respond, that activity may be detected and stopped before the AI gets very far.
That means AI has not made basic cybersecurity obsolete.
It may be doing the opposite.
It is making the basics more time-sensitive.
The Same Old Weaknesses Still Matter
AI still needs something to work with.
An exposed system.
An unpatched vulnerability.
A weak credential.
An unnecessary service accessible from the internet.
An administrator account with too much access.
A configuration nobody has reviewed in years.
The government researchers emphasized the same fundamentals defenders have been hearing for years: know what assets you have, maintain strong access controls, configure systems securely and keep useful logs.
What changes in the AI era isn't necessarily what businesses need to fix.
It is how quickly they may need to find and fix it.
What This Means for a Small Business
You don't need to build an AI security laboratory.
You do need to reduce the amount of time between something becoming dangerous and someone doing something about it.
That starts with a few practical questions:
- Do you know what is exposed to the internet right now?
- Do you know which vulnerabilities on your systems are actually being exploited in the wild?
- Do you know when a new critical weakness appears?
- Does someone know which finding should be fixed first?
- Can you tell whether the problem was actually corrected?
If those answers require several people, multiple spreadsheets, a quarterly meeting and an email to an outside provider, that is where the defense gap begins to appear.
AI Is Also Part of the Answer
There is another side to this story.
The same government researchers warning about offensive AI are explicitly encouraging defenders to use AI to increase their own speed and scale.
AI is already being applied to vulnerability discovery, security testing, threat intelligence, alert triage, configuration analysis and other defensive work.
In August, the U.S. National Institute of Standards and Technology went a step further, publishing a draft guide showing ways organizations can use AI to help analyze, plan, implement and monitor progress against the NIST Cybersecurity Framework.
That is the real race.
It isn't humans versus AI.
It is attackers using automation and AI against defenders who either do — or do not — learn to use the same advantage.
How ThreatAngel Helps
ThreatAngel is designed around this widening gap.
Small businesses already have plenty of security information. What they usually lack is a fast way to turn that information into a decision.
ThreatAngel combines your business profile, external exposure, vulnerability findings, operational assessments and current threat intelligence into one view of your security posture.
The ThreatAngel Score turns those signals into something a business owner can understand. The Improvement Center shows what deserves attention and where an improvement can have the greatest impact. Threat intelligence helps separate a theoretical vulnerability from one attackers are actively using.
The goal is not to replace your IT provider or build a miniature security operations center inside every small business.
It is to shorten the path from:
Something changed. → It matters. → Fix this first.
Because attackers are increasingly gaining machine speed.
Small-business defense cannot remain entirely human-speed.
AI does not need to replace the attacker to change cybersecurity. If it makes each attacker faster, cheaper and more productive, the advantage shifts. The businesses best positioned to respond will be the ones that shorten the time between seeing risk and acting on it.
Sources
UK National Cyber Security Centre
Why Cyber Defenders Need to Be Ready for Frontier AI, March 30, 2026.
UK National Cyber Security Centre
Impact of AI on Cyber Threat From Now to 2027.
U.S. National Institute of Standards and Technology
Using Artificial Intelligence for Cybersecurity Framework 2.0 Analysis and Reporting, August 19, 2026.
Dollar conversion note: the UK government source reports an estimated cost of £65 for a full attempt. £65 was approximately $87 USD on September 17, 2026. The dollar figure is rounded and will vary with exchange rates.
ThreatAngel Stands Guard.
```AI-powered threat protection helps SMBs keep pace with modern attacks.
```
Comments
Post a Comment