Cybersecurity · Monday, 27 July 2026
01 · Briefing · what happened
AI turned up on both sides of the security fight this week
Attackers are using AI to write sharper scams at scale, and defenders are shipping AI tools to find flaws faster - each answering the other, with breaches rolling on all the while.
Key takeaways
- Two-thirds of ransomware victims this year said AI made the attack more effective, while defenders like Capital One released free AI tools to find and fix flaws - both sides escalating at once.
- The ransomware surge (up 25% over the year) is driven mostly by more criminal groups and easier entry, not by AI itself - AI sharpens attacks rather than starting them.
- Ordinary breaches kept rolling: Suno (55M+ accounts), Ernst & Young, and a provider to 2,000+ US hospitals were all hit - change reused passwords, because one breach becomes many.
The story of the week in security is not one breach. It is that AI has arrived on both sides of the fight at once - and neither side is pulling ahead.
The attackers got a force multiplier
Two-thirds of organisations hit by ransomware this year said AI made the attack more effective, according to a Proofpoint survey published July 22
The gain is mostly in the lure. AI writes convincing phishing emails - fake messages that trick you into handing over a password or clicking a bad link. It does this at a scale and polish no human team could match
The clearest sign of the shift came earlier this month. OpenAI disclosed that a combination of its own frontier models had autonomously broken into the AI firm Hugging Face
The defenders shipped back
The same week, Capital One released VulnHunter, an AI tool it built in-house, free for anyone to use
That is the shape of an arms race. Attackers automate the finding of weak spots; defenders automate the finding and patching of the same weak spots. GitHub and PyPI, two places developers get their code, added new time-based defences against tampering the same week
The honest complication
It would be tidy to say AI is why attacks are surging. It isn’t the main reason. Ransomware researchers at Black Kite counted 7,551 known victims over the year to March 2026, a 25% rise, with attacks up 60% in the second half
But they pinned the growth on plainer causes: more criminal groups (over 60 new ones), a lower barrier to entry, and attacks aimed at smaller, less-defended targets
Attackers are also hiding inside the AI tools
A subtler thread: some malware now hides inside the AI tools people already trust. Researchers described early malware, dubbed Sandworm_Mode, built to exploit trusted AI workflows so its activity looks like ordinary work
Meanwhile, the ordinary breaches roll on
None of the AI drama stopped the plain thefts. The AI music service Suno was breached, exposing more than 55 million user accounts
If you have an account with any breached service, change that password - and change it anywhere you reused it. That reuse is how one breach quietly becomes five. A study this month found more than a third of ransomware victims who paid were squeezed for money again anyway
The week’s lesson is not that AI has handed the win to attackers, or to defenders. It is that both now hold the same new tool - and the fight, for all the new speed, sits about where it did.
02 · Lesson · why it matters
You can run as hard as you like and still stay in the same place
When two rivals both get faster, the effort climbs but the gap between them barely moves - each new advantage is answered before it pays off.
Two sides, one new engine
This week the same tool showed up in both camps. Attackers used AI to write sharper scams at a scale no human team could reach. Defenders used AI to find and patch the flaws those scams aim at. Capital One even gave its finding-tool away for free.
Read the two halves together and something odd appears. Both sides are now much faster than a year ago. Yet the thing that matters - whether attackers get in or defenders keep them out - sits about where it did. Everyone sped up. Nobody pulled ahead.
The Red Queen
Biologists have a name for this, borrowed from a children’s book. In Through the Looking-Glass, the Red Queen tells Alice that here, it takes all the running you can do just to keep in the same place.
They use it for predators and prey. Faster gazelles favour faster cheetahs, which favour faster gazelles again. After thousands of years, both are quicker - and the cheetah catches its dinner about as often as before. The improvement is real. The advantage is not, because the other side improved too.
Security runs on the same loop. Any edge one side gains is a problem the other side is now paid to solve. A cleverer scam trains a cleverer filter. A cleverer filter trains a cleverer scam. The position holds; only the speed changes.
Why the effort still rises
If nobody pulls ahead, why not stop spending? Because stopping is the one move that loses. The runner who slows down doesn’t stay level - they fall behind, fast, while the other keeps going. So each side keeps paying the full cost of the race just to hold its ground.
That is the quiet trap of an arms race. The spending isn’t foolish - each step is a sane answer to the other side’s last step. But the sum of all those sane steps is two exhausted rivals in the same relative spot, having poured in far more than either wanted to. The rational moves add up to a result neither chose.
You can see why this week’s honest voices mattered. Researchers noted the ransomware surge isn’t mainly AI’s doing - it’s more criminal groups and easier entry. That’s worth hearing, because in a race it’s tempting to blame the newest weapon and pour everything into matching it, when the ground has shifted for plainer reasons.
Where you are standing
It’s easy to read all this as a fight between firms and criminals, fought somewhere far away. It isn’t. You are on the field.
The 55 million accounts spilled from one music service this week were ordinary people’s. The convincing scam email that fooled a company can just as easily land in your inbox, now written by the same engine. When the attackers’ tools get faster, the fake message you receive gets better. When defenders’ tools get faster, the service holding your data has a better chance of catching the break-in first. Both accelerations reach your screen.
And there is no seat above the race, not even for the people building the AI on both ends. The same models one firm ships to defenders are turned into weapons by others; the firm that publishes a free defence tool also runs, somewhere, a service that gets breached. Nobody is outside the loop looking down. The engineers, the criminals, the companies, and you are all inside the same accelerating machine, and no single seat can see the whole of it.
That is the humbling part. The race will not be won, and it will not stop. Knowing that changes what winning even means - not getting permanently ahead, which no one can, but running well enough, today, to stay in place. The task isn’t to escape the loop. It’s to keep pace inside it with your eyes open, and to remember that everyone else on the field is running just as hard, for exactly the same reason.
03 · Lab · your turn
Run to stand still
Rehearse an arms race - escalate and the attacker matches you for a fortune, hold and you fall behind, so the position stays level while the cost only climbs.
04 · Hope · carry this
No one wins an arms race, but notice which side gives its best tools away for free. A defence built once and shared with everyone is stronger than one kept locked in a drawer.
More from Cybersecurity