Bottom line: AI is lowering the cost of vulnerability research for attackers, who are increasingly targeting security tools like EDR to disable them rather than simply evade them – forcing defenders to rely on redundant, non-endpoint-dependent detection layers and control of transient assets such as contractor laptops.
AI is lowering the cost of vulnerability research and speeding up attacks, while patch cycles and maintenance windows remain unchanged. Increasingly, attackers are not aiming to stay undetected, but to switch off the security tools themselves.
Cyber defense has long been based on the assumption that attackers try to evade security tools while defenders try to detect them as early as possible. This division of labor is shifting. Professional attackers are increasingly targeting, in a deliberate manner, the very systems that could detect them. Vulnerable signed drivers and legitimate remote management tools have now become a fixed part of modern attack chains used to carry out defense evasion. Marc Elias of the Symantec Threat Hunter Team also attributes this to the success of behavior-based detection: attackers have largely given up trying to make their ransomware undetectable, and instead attempt to directly disable security mechanisms.
For enterprises, this means it is no longer enough to know how well an EDR system detects an attack. What also matters is what happens once that system is disabled. The more detection and response is concentrated on a small number of platforms, the more attractive those platforms become as targets in themselves. OT environments illustrate this problem in an intensified form: controllers typically do not run conventional EDR, so engineering workstations, HMI servers and jump hosts are often the only systems with endpoint detection. If the agent fails there, network visibility – supplemented by process data, historian records, controller diagnostics and remote access logs – becomes an independent observation layer, since a network sensor cannot be removed via a signed driver the way an endpoint agent can.
At the same time, AI is widening the speed gap between attack and defense. Ta-Lun Yen of TXOne Networks demonstrated an LLM-supported workflow for vulnerability research in firmware binaries without debug information: the model helps direct limited reverse-engineering capacity toward the most promising code areas. This does not make vulnerability research trivial, but it does make more efficient use of the scarcest resource – expert time. On the defender side, meanwhile, maintenance windows remain limited, update paths are dictated by vendors, and changes must be tested before rollout. In OT environments, patch cycles can take months or years, which is why simply “patching faster” falls short. Segmentation, controlled transitions, access restrictions and network monitoring are gaining importance as a result.
The attack path does not have to run via the internet. USB sticks, maintenance laptops belonging to external service providers, and firmware files are legitimate points of entry into segmented environments – and precisely for that reason, a risk. Benny Czarny, CEO of OPSWAT, puts it succinctly: attackers do not need to break into the network remotely; they merely need to compromise a file, a device, a service provider, or a step in the maintenance and supply chain. In the ICS/OT Cybersecurity Budget Report 2025, 27.3 percent of respondents who were able to identify an initial attack vector named transient cyber assets such as contractor laptops as the entry point; a further 15.2 percent cited compromised removable media. For CISOs, this raises a concrete governance issue: controlling who is permitted to connect such transient assets to the network, and under what conditions.
Source: www.it-daily.net · Published August 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.