Picture a bank vault where the guards are asleep, the alarms have been disabled from inside, and the thieves aren't even human—they're autonomous robots that picked the locks, bypassed the sensors, and are now moving through the corridors at machine speed while the security team debates whether to call IT or facilities. This is cybersecurity in September 2026.
1Threat intelligence from early September reveals a convergence of autonomous AI-powered attacks, a 700% surge in malicious insider breaches, and persistent APT prepositioning in U.S. critical infrastructure—creating a threat landscape where traditional defense perimeters have collapsed and response times are measured in milliseconds, not hours.
The Machine-Speed Attack Cycle
In November 2025, Anthropic disclosed the first documented large-scale cyber-espionage campaign where an AI-enabled agent conducted the majority of attack operations with minimal human oversight [[81]]. A People's Republic of China-linked threat actor deployed an agentic AI system to autonomously perform reconnaissance, identify vulnerabilities, generate exploit code, move laterally, harvest credentials, and exfiltrate data against dozens of global targets [[81]]. Human operators intervened only at select decision points.
1 2 3 4 5This represents a fundamental shift from AI-enhanced phishing to autonomous attack orchestration. Between March 2025 and February 2026, one in four breaches was AI-enabled, up 56% from the prior year [[64]]. The implication extends beyond speed: agentic AI transforms cyber threats from discrete, human-paced incidents into machine-speed, self-directed campaigns that outpace human-driven incident response.
"Agentic AI transforms cyber threats from discrete, human-paced incidents into machine-speed, self-directed campaigns, making automation, collective defense, and resilience the defining priorities of cybersecurity in the years ahead," according to the New Jersey Cybersecurity and Communications Integration Cell's 2026 threat assessment [[81]].
Counter-Argument: The Human-in-the-Loop Constraint
Skeptics argue that current AI systems lack the contextual reasoning and adaptive decision-making required for truly autonomous cyber operations. The Anthropic disclosure, while significant, represents a single documented case rather than widespread operational deployment. Most AI-generated exploits remain unreliable—VulnCheck reported that while AI-generated proof-of-concept code increased 16.5% year-over-year, much of it did not work reliably [[82]].
1Furthermore, the technical complexity of chaining multiple zero-day exploits, maintaining persistence across heterogeneous environments, and evading advanced detection systems still requires human expertise. The "autonomous" label may overstate current capabilities, serving more as a warning of trajectory than a description of present reality.
The Insider Threat Metamorphosis
While autonomous attacks dominate headlines, a quieter crisis emerged in the first half of 2026: malicious insider breaches jumped from three incidents in all of 2025 to 21 incidents in just six months [[64]]. This 700% increase reflects two converging trends: disgruntled laid-off employees stealing data during exit, and North Korean state-sponsored remote worker placement operations using deepfake videos and AI-generated resumes [[64]].
1 2 3"The raw number doesn't look very big, but when you look at the historical trend line, insiders haven't been big sources of data breaches," said James Lee, president of the Identity Theft Resource Center. "We've never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months" [[64]].
The insider threat now operates at the intersection of economic disruption and geopolitical conflict. Organizations conducting layoffs without robust data loss prevention controls create immediate exfiltration risks. Simultaneously, the FBI-flagged North Korean IT worker scam places state-sponsored actors directly inside U.S. companies with legitimate credentials and system access [[64]].
Zero-Day Industrialization and the Commercial Surveillance Shift
Google Threat Intelligence Group tracked 90 zero-day exploits in 2025, a 15% increase from 2024's revised count of 78 [[82]]. More significantly, commercial surveillance vendors surpassed nation-state espionage groups in attributed zero-day exploitation for the first time—15 zero-days versus 12 for traditional APT groups [[82]].
1 2 3This market shift has profound implications. Commercial vendors operate with different incentives than nation-states: profit maximization, customer acquisition, and rapid exploit development cycles. Unlike state actors constrained by geopolitical considerations, commercial vendors face fewer operational restrictions, potentially increasing zero-day deployment frequency.
China-linked groups remained the most active state-sponsored threat actors with at least 10 attributed zero-days in 2025, double the 5 from 2024 [[82]]. Financially motivated groups were attributed 9 zero-days, up from 5 in 2024, with 2 leading directly to ransomware deployment [[82]].
The NotPetya Precedent: When Prepositioning Becomes Destruction
The current threat landscape mirrors conditions preceding the 2017 NotPetya attack, which caused over $10 billion in global damage including an estimated $1.4 billion impact in New Jersey alone [[81]]. Russian GRU-linked Sandworm APT demonstrated its capability to disrupt critical infrastructure, having previously taken down parts of Ukraine's power grid in 2015 and 2016 [[81]].
1 2 3Today, China-linked Volt Typhoon has maintained persistent access to U.S. water, energy, transportation, and communications systems for over five years [[81]]. The group's objective: gain and maintain covert, long-term access to enable potential disruption or sabotage during a future geopolitical crisis, such as an invasion of Taiwan [[81]]. Like Sandworm before it, Volt Typhoon exploits unpatched vulnerabilities and uses "living off the land" techniques with built-in Windows tools to evade detection [[81]].
The lesson from NotPetya proves insufficient: prepositioning in critical infrastructure isn't espionage—it's preparation for kinetic-effect cyber operations. The average time from vulnerability disclosure to exploitation has decreased from 32 days in 2022 to just 5 days currently [[81]], compressing the window for defensive action.
Counter-Argument: The Resource Allocation Dilemma
Critical infrastructure operators face legitimate resource constraints that make comprehensive defense against APT prepositioning nearly impossible. The NJCCIC's 2026 assessment notes that federal cybersecurity support is contracting, placing greater responsibility on state and local entities already struggling with budget shortfalls [[81]].
1Moreover, the focus on nation-state threats may divert attention from more immediate risks. Ransomware groups caused over 8,000 attacks in 2025 (31% year-over-year increase), with manufacturing, healthcare, energy, and government as top targets [[81]]. For a mid-sized healthcare provider or municipal government, the probability of ransomware far exceeds APT targeting, making resource allocation to counter Volt Typhoon a questionable investment when basic patch management remains incomplete.
Immediate Defensive Priorities
- Zero-Day Exposure Reduction: Integrate CISA's Known Exploited Vulnerabilities (KEV) catalog into vulnerability management immediately. The catalog grew 20% in 2025 with 245 vulnerabilities added, 24 exploited by ransomware groups [[81]]. Prioritize KEV-listed flaws over CVSS scores. 1 2 3 4 5 6
- Insider Threat Mitigation: Implement data loss prevention controls before conducting layoffs. Require dual-approval for sensitive data access. Deploy behavioral analytics to detect anomalous data access patterns during notice periods.
- Critical Infrastructure Hardening: Remove or isolate internet-facing devices running end-of-life software. Volt Typhoon gains initial access through unpatched vulnerabilities in these systems [[81]]. Segment OT networks from IT environments with unidirectional gateways.
- AI-Powered Defense Deployment: Machine-speed attacks require machine-speed detection. Deploy EDR/XDR solutions with AI-based anomaly detection capable of identifying agentic AI attack patterns—rapid lateral movement, automated credential harvesting, and bulk data exfiltration.
Six-Month Outlook: The Regulatory Reckoning
By Q1 2027, expect three converging developments:
1 2 3 4 5 6 7 8 9- Mandatory AI Attack Disclosure: Following the Anthropic disclosure, regulators will require organizations to report AI-enabled breaches separately, creating the first dataset on autonomous attack frequency and impact.
- Commercial Surveillance Regulation: The shift toward commercial vendors in zero-day markets will trigger export control discussions similar to those for dual-use technologies. The Wassenaar Arrangement may expand to cover commercial exploit development tools.
- Critical Infrastructure Mandates: Following Volt Typhoon's persistent access, CISA will likely mandate specific security controls for water, energy, and transportation sectors—potentially including mandatory network segmentation, continuous monitoring, and incident response testing with federal oversight.
The median ransomware demand fell to $100,000 in H1 2026 from $500,000 in H2 2025 [[55]], suggesting either decreased attacker leverage or increased defender resilience. However, with 187 government ransomware attacks in H1 2026 (13% increase) [[55]] and 56.4% of 2025 ransomware CVEs first identified through zero-day exploitation [[82]], the threat continues evolving toward faster, more automated, and harder-to-detect operations.
The Paradigm Shift
September 2026 marks the transition from human-speed to machine-speed cyber conflict. The convergence of agentic AI, insider threats, commercial zero-day markets, and APT prepositioning creates a threat environment where traditional defense-in-depth has collapsed. Organizations must accept that compromise is inevitable and focus on detection, response, and resilience rather than prevention alone.
1The question is no longer whether adversaries will penetrate defenses, but whether defenders can detect and respond at machine speed before autonomous agents complete their objectives. For most organizations, the answer remains no—making the next major incident not a matter of if, but when.