Security teams rank AI-powered attacks among their biggest concerns, but new research suggests organizations may be overlooking established attack techniques while struggling with transparency after breaches.

By The Grey Ghost

WHAT’S HAPPENING

Bitdefender’s 2026 Cybersecurity Assessment found that security professionals rank AI-related threats among their leading concerns.

Respondents identified self-mutating malware (55.9%), public LLM data leakage (53.5%), and AI-driven evasion techniques (52.5%) as high or extreme risks.

But Bitdefender’s threat intelligence indicates attackers are currently using AI largely to enhance existing techniques rather than replacing them with entirely new forms of attack.

One example is Living off the Land (LOTL), where attackers abuse legitimate tools already present inside systems. Bitdefender says these techniques appear frequently in high-severity attacks, yet only about one in five surveyed security professionals ranked LOTL among their top priorities.

WHY IT MATTERS

The findings highlight a potential cybersecurity blind spot.

Organizations may understand emerging AI risks while simultaneously directing attention away from established techniques attackers are already using.

Cyber resilience also extends beyond technology.

Among respondents who reported experiencing a breach during the previous 12 months, 55.2% said they were instructed to keep it confidential despite believing authorities should have been notified. Among U.S. respondents, that figure reportedly reached 68.6%.

WHO BENEFITS

Security Teams Focused on Real-World Threat Intelligence — Organizations aligning defenses with observed attacks may allocate resources more effectively.

Governance and Compliance Leaders — Increased attention to breach disclosure could strengthen their role in incident-response planning.

WHO LOSES

Organizations Chasing Threat Headlines — Concentrating heavily on emerging AI risks could leave established attack methods underprioritized.

Weak Incident-Response Cultures — Internal pressure surrounding breach disclosure can create regulatory, governance, and reputational risks beyond the original cyberattack.

WHAT HAPPENS NEXT

AI-related cyber threats will continue evolving, but organizations will also have to defend against less novel techniques that remain effective today.

The larger cybersecurity challenge in 2026 may therefore be less about knowing what the risks are—and more about turning that knowledge into operational resilience when an attack actually happens.

Stay Sharp

Subscribe to follow the Trend newsletter and more.

Have a tip or idea?

Pass along insights or story ideas on AI, startups, and business. Focused on signal over noise, impact over headlines. Facts. Trends. Consequences. Always.