For years, cybersecurity has talked about what AI-powered attacks might look like. We don't have to imagine anymore. Over the last 90 days, we've watched AI-assisted and increasingly autonomous attacks move from research environments into the real world. We've seen an agentic ransomware campaign. We've seen AI used to repeatedly modify malware until it could evade defenses. We've seen AI agents escape evaluation environments and reach real companies and government systems. We've seen credentials, cloud infrastructure, APIs, VPNs, databases, source code, and trusted services pulled into attack paths.
Our Vectra AI Security Research team did excellent work breaking down the Hugging Face incident. But the bigger story isn't Hugging Face. It's the pattern forming around it. In just the last quarter:
- JadePuffer showed an AI agent progressing through an extortion campaign from reconnaissance through credential theft, lateral movement, encryption and ransom.
- Midnight Blizzard-linked activity showed AI being used in a closed loop to test malware against defenses, modify it when detected and redeploy it until it worked.
- OpenAI evaluation agents reached real-world infrastructure, including Hugging Face and Australia's Medicare statistics environment.
- Anthropic, Meta and Google each disclosed examples of AI agents escaping intended test boundaries and gaining unauthorized access to real organizations.
- Other incidents demonstrated AI agents being used for package attacks, coding-assistant abuse and multi-stage enterprise intrusions.
Different incidents. Different models. Different techniques. Same lesson: AI is changing the speed and scale of attack. It isn't changing what attackers ultimately have to do. Once inside, an attacker still has to understand the environment, find and use credentials, escalate privilege, move laterally, communicate and eventually reach something valuable. The tools change. The exploits change. The models change. The behavior doesn't.
Behavioral AI Reveals How AI Attacks Actually Unfold
That's the part I think matters most for defenders. Look at many of the individual actions inside these attacks and they aren't obviously malicious. A cloud API call, token request, login, service account accessing a workload, new VPN connection, Kubernetes request or reused password can all be legitimate on their own. So the better security question isn't simply, “Is this action malicious?” It's “Does this behavior make sense for this identity, in this environment, right now?”
That's where behavioral AI matters. Rather than waiting for a known signature or indicator, behavioral AI looks at what an entity is actually doing. Is it discovering the environment? Abusing credentials? Escalating privilege? Moving laterally? Establishing command and control? Accessing something it normally doesn't? Moving data in an unusual way? The point isn't to know every technique an AI-powered attacker might invent next. It's to understand when behavior starts to look like an attack.
And increasingly, the identity behind that behavior isn't necessarily a person. The AI enterprise is operated by human users, service accounts, workloads, machine identities, APIs, automation and now AI agents. Every one of them can be trusted. Every one of them can also be abused. Security therefore has to understand the behavior of both human and non-human identities.
Why Network + Identity Are Critical to AI Attack Detection
This is why I believe Network + Identity has to become the foundation for defending the AI enterprise. Network gives you the runtime truth of what's actually happening: which systems are communicating, where lateral movement is occurring, which protocols are being used, how data is moving and how behavior is changing as an attack progresses. Identity gives you the other half of the story: who — or increasingly, what — is behind that activity. Is it a person, service account, workload, machine identity, cloud identity or AI agent? What privileges did it exercise? Which trust relationships did it use? Does that activity make sense for what that identity normally does?
You need both because attackers don't respect our security product categories. They don't stay neatly inside endpoint, identity, cloud, network or SaaS. They move from identity to cloud, cloud to workload, workload to network, network to internal infrastructure, on-premises to SaaS and from one trusted identity to another. No endpoint alert alone sees that whole story. Neither does an identity event, cloud alert or network detection in isolation. The attack exists in the connections between them.
That's where Attack Signal Intelligence becomes important. It connects those behaviors across identities, systems, domains and time so defenders can understand the attack as it is actually unfolding.
Five alerts may be one attack
I think security has spent too much time celebrating how many things we can detect. Detection isn't the problem anymore. Understanding is. One system detects unusual cloud discovery. Another sees suspicious privilege use. Another identifies a new credential. Another finds lateral movement. Another flags unusual SaaS access. Five products may generate five alerts in five different queues, but that doesn't necessarily mean you have five problems. You may have one attacker moving through five parts of the environment.
AI-driven Attack Signal Intelligence stitches those behaviors together. It combines behavioral AI with network and identity context to understand who or what is involved, how the activity is connected and where the attack is going next. That distinction matters because AI attackers aren't waiting for an analyst to manually correlate five consoles. They can observe, reason, act, adapt and try again at machine speed. Defenders need the same ability to understand and act at speed.
This is also where I think the conversation about AI in the SOC gets interesting. I'm incredibly optimistic about what AI can do for defenders, but putting an AI agent on top of thousands of disconnected alerts doesn't magically solve the problem. It may just help us summarize noise faster. AI is only as good as the signal underneath it.
Give an AI agent disconnected alerts, weak context and incomplete attribution, and you're asking it to make sense of a bad hand. Give it behavioral detections tied to the right human or non-human identity, enriched with network and identity context and correlated across on-premises and cloud environments, and now AI can do something much more valuable. It can reconstruct how an attack progressed, identify affected identities and systems, explain why the behavior matters, prioritize what deserves attention, recommend the next action and help automate investigation and response.
That's how I think about fighting AI with AI. Not AI on top of alerts. AI on top of trusted Attack Signal Intelligence.
This is why Attack Signal Intelligence was built
At Vectra AI, our conviction is pretty simple: AI-driven Attack Signal Intelligence rooted in Network + Identity is how defenders fight AI-powered attacks with AI. It applies behavioral AI to human and non-human identities. It understands behavior across on-premises and cloud environments. It operates in runtime while the attack is actually unfolding. And most importantly, it connects behaviors across identities, systems and domains so humans — and increasingly the AI agents working alongside them — can understand the attack fast enough to do something about it.
Because the objective isn't more alerts. It isn't even more detections. The objective is answering the question every security team ultimately needs answered: Are we under attack right now?
The last 90 days should make one thing pretty clear: AI attacks aren't something we're preparing for five years from now. They're here, and they're going to get faster. The models will change. The vulnerabilities will change. The attack techniques will change. AI will make it easier for attackers to experiment, adapt and operate at a scale humans simply couldn't before.
But attackers still have to act. They still have to use identities. They still have to communicate across networks. They still have to move through the environment. And that behavior still tells the story.
That's why I don't think the advantage in the AI era will come from trying to predict every new AI attack technique. It will come from continuously understanding who and what is operating across the enterprise, how they're behaving and when that behavior becomes an attack.
Network tells us what happened. Identity tells us who or what did it. Behavioral AI tells us when it matters. Put those together and you have the trusted signal defenders — and their AI — need to fight AI-speed attacks at AI speed.
You can read more posts from Mark Wojtasiak, here on the Vectra AI blog.

.jpeg)