AI Cyber Threats Continue to Evolve and Increase
The news from AI has been good and bad – AI agents continue to help businesses with repetitive tasks, programming, marketing, and much more; but AI agents also continue to help hackers and fraudsters perpetrate criminal activity. Some recent accounts include:
- An AI platform itself, Hugging Face, reported that it was the victim of an anonymous AI agent which collected cloud data and credentials[1];
- A vulnerability in the WordPress platform discovered by a researcher using a publicly available AI model uncovered a serious security issue[2]. The discovery apparently cost about $25 to discover. The flaw involved a series of steps, each of which resulted in its own Critical Vulnerability and Exposure (CVE) being issued for each one:
- The Batch API Desynchronization Bug (CVE-2026-63030)
- The SQL Injection Sink (CVE-2026-60137)
This allows for cache poisoning and admin hijack, which then allows a full site takeover;
- There are many reports of AI being used for phishing and other social-engineering scams.
- Finally, the sheer number of vulnerabilities is up year-to-date:
- Chrome (+563.2%),
- VMware (+180.9%),
- Apache (+170.3%),
- Mozilla (+156.9%),
- HPE (+132.3%), and
- F5 (+113.8%)
The National Institute of Standards and Technology (NIST), which monitors and publishes new CVEs, has reported that submissions in Q1 2026 were a third higher than the same quarter last year. In fact, year over year submissions of CVEs increased for the past several years. The graph below contains the number of CVEs over the past 10 years:
The number of CVEs for 2026 is very close to 2025 and we are only halfway through the year!
To protect yourself:
- Know the platforms, applications, software, and operating systems your company is using and periodically check for new vulnerabilities;
- Know where sensitive data is located and how to keep data segregated until access is necessary;
- Update systems on a regular basis;
- Know what actions or what help third-party providers will offer if a vulnerability is discovered on their systems;
- Know the limitation of liability provisions in your agreements;
- Know what your insurance may / may not cover; and finally,
- If keeping up with all of this seems too difficult, consider hiring a managed service provider (MSP) to help.
[1] https://huggingface.co/blog/security-incident-july-2026
[2] https://cybersecuritynews.com/critical-wp2shell-rce-vulnerability/ (In 2026, between 472 million and 595 million websites use WordPress globally.)


