Software Flaws Are Now the #1 Breach Cause, and AI Is Making It Worse

Every time I think I have seen it all with Software Flaws Are Now the, something new emerges. For years, hackers made money the easy way: steal a password, replay it somewhere else, walk straight into a system. That era is over. The 2026 Verizon Data Breach Investigations Report shows attackers now prefer exploiting unpatched software over everything else.

They reviewed more than 31,000 incidents, and 31 per cent of breaches began with attackers exploiting a known software flaw. That puts vulnerability exploitation ahead of stolen credentials for the first time on record. The report’s verdict is blunt: AI is fundamentally reshaping cybersecurity.

This matters to anyone running a business or handling customer data. AI is shrinking the gap between a vulnerability going public and it being weaponised from months to hours. Criminal groups and nation-state actors now use generative AI to pick targets, write custom malware, and turn research into attacks at machine speed. The barrier to entry hasn’t just dropped; it has collapsed.

The CrowdStrike data quoted in the report only confirms the trend: AI-assisted cyber attacks rose 89 per cent year-on-year in 2025. Less sophisticated actors suddenly punch above their weight because AI does the intelligence gathering, language translation, and tool building that used to require a specialist crew.

The insider angle is just as worrying. Verizon now cites unauthorised AI use as the third most common non-malicious insider action leading to data loss. Employees are routinely pasting source code, customer lists, and commercially sensitive documents into consumer AI tools that keep, analyse, and sometimes leak that data. Shadow AI is no longer a buzzword. It is an active data loss pathway, and most businesses have no idea it is happening.

Here is what you can do today:

  • Cut patch delays to hours, not weeks. Enable automatic updates on every system you control.
  • Audit AI access. Know which tools your staff use and whether sensitive data is leaving your environment.
  • Require multi-factor authentication everywhere. It is still one of the few controls that works against both credential theft and AI-enhanced social engineering.
  • Upgrade logging and alerting. Assume breaches will happen. Detect them faster by knowing what normal looks like.

Regulators are already moving. In early June, the White House issued an executive order asking CISA, the Treasury, and the National Security Agency to strengthen defences against advanced AI threats and develop voluntary benchmarks for frontier AI models. Financial regulators are separately pushing tighter controls over agentic AI in banking and payments. Privacy rules are following opinion, not leading it.

The uncomfortable truth is that AI is a threat multiplier, not just a business convenience. Hackers who adopt it first will outpace defenders who do not. The time to close that gap is before the breach notification letter arrives.

“We need to fight AI with AI. We need to incorporate them into our practices. We need to bring them into our software development life cycle, in our testing processes, in our cyber defense processes at a scale that we have never done before.” – Nasrin Rezai, Verizon CISO

Related Reading

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.