On September 22, Microsoft announced that it had disrupted a cybercrime platform called “EvilTokens.” Launched in February 2026, the service was used within just a few months to compromise more than 12,000 email accounts across over 10,000 organizations worldwide. The victims spanned a wide range of industries, including finance, real estate, construction, healthcare, and education. Microsoft seized 50 websites associated with the operation and blocked more than 150 domains, while two men suspected of involvement were arrested in the UK.

https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/

What distinguished EvilTokens from conventional cybercrime tools was how deeply AI was embedded in the attack process. Once an account was compromised, AI analyzed the victim’s inbox to identify conversations involving payments and invoices and to understand roles and trust relationships within the organization. It could determine who had the authority to move money, whom to impersonate, and whom to approach. In other words, AI took over the work of extracting information that attackers would previously have had to uncover by manually reading through large volumes of email.

The attack process itself was also packaged as a single service. EvilTokens was sold for an initial fee of $1,500 plus $500 per month, providing everything from account compromise and email analysis to target selection and fraud preparation in one place. Microsoft’s investigation also found indications that AI-assisted coding had been used to build significant portions of the platform itself. AI was being used both to build the attack tools and to carry out the attacks.

For this reason, Microsoft did not view EvilTokens as simply another phishing tool that happened to use AI. In the past, even after compromising an account, an attacker still had to read through large numbers of emails to understand an organization’s structure and financial flows. AI can now dramatically reduce the time required for that work. Microsoft warned that once an email account has been compromised, organizations should assume that criminals can understand what is inside it in “minutes, not days.”

The important change is not so much the emergence of an entirely new hacking technique as the reduction in the time and labor required to carry out existing attacks. Phishing, account compromise, and email-based financial fraud have all existed for years. What has changed is that AI is beginning to take over some of the analysis and decision-making that attackers previously had to perform themselves. A single attacker can examine more accounts and organizations, while spending less time identifying suitable targets. The attack itself may not be new, but the conditions now make it possible to repeat existing forms of cybercrime faster and at greater scale.

This change does not benefit attackers alone. If AI can rapidly analyze vast amounts of information and identify anomalies, the same capabilities can also be used to discover vulnerabilities and prevent attacks. On the defensive side of cybersecurity, efforts are already growing to use AI to uncover vulnerabilities that would be difficult for humans to find quickly.

AI Is Finding Vulnerabilities Faster, Too

Every month, Microsoft releases its regular security updates on what is commonly known as “Patch Tuesday.” It is a familiar routine for IT teams at companies and public institutions, addressing security issues found across Windows, Office, and other Microsoft products. But the number of vulnerabilities addressed in the September update was unusual. Although the exact count varies slightly depending on methodology, roughly 972 vulnerabilities were patched, making it the largest update on record. More than 110 were classified as Critical, and the update also included vulnerabilities that were already being exploited in real-world attacks. Nor was the surge limited to September. In 2026 alone, Microsoft has patched 2,760 vulnerabilities, more than twice the total for all of last year.

So did the number of vulnerabilities themselves suddenly increase that dramatically?

Not necessarily. Another possibility is that we are simply finding more problems that previously went undetected. The way the security industry searches for vulnerabilities has been changing rapidly, and AI is at the center of that shift.

Traditionally, security researchers had to examine enormous amounts of code, identify suspicious sections, and verify one by one whether they could actually lead to an attack. It is work that requires considerable time and expertise. AI is now beginning to take over parts of that process.

A representative example is “MDASH,” which Microsoft unveiled in May. Rather than assigning every task to a single AI model, MDASH uses more than 100 specialized AI agents that divide the work of analyzing code. One agent may identify a suspicious area, while another reviews it and checks whether it could realistically be exploited. In effect, it extends through AI agents the kind of divided review process traditionally carried out by teams of security experts.

https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark

MDASH is already being used to discover vulnerabilities in real products. According to Microsoft, 16 vulnerabilities involving Windows networking and authentication that were identified through security research using the system were included in the company’s May security update. AI is moving beyond experiments in assisting security researchers and beginning to take part in the actual process of finding vulnerabilities in deployed products.

Of course, this alone cannot explain the roughly 972 vulnerabilities patched in September. Nor does that figure indicate how many of those vulnerabilities were discovered by AI. Many factors influence the number of vulnerabilities found, including the expanding range of products and increased security research activity.

What matters more than the number itself is the changing way vulnerabilities are discovered. There is a practical limit to how much code humans can examine directly. With AI, much larger volumes of code can be reviewed repeatedly, suspicious areas can be identified, and the scope of what security researchers need to inspect can be narrowed. Rather than completely replacing human security research, AI is expanding the amount of ground that researchers can cover.

Seen this way, the recent increase in discovered vulnerabilities takes on a somewhat different meaning. Finding more vulnerabilities can mean that more problems exist, but it can also mean that we are becoming capable of detecting problems that were previously difficult to uncover. AI’s impact on cybersecurity is not simply that another defensive technology has been added. It is beginning to change both the time required to discover vulnerabilities and the scale at which they can be searched for.

This creates an interesting symmetry with EvilTokens. EvilTokens reduced the time attackers needed to analyze compromised accounts and identify targets. With MDASH, AI is being used to reduce the time required to search vast amounts of code for vulnerabilities and verify them.

On one side, AI is helping attackers. On the other, it is helping defenders find the very weaknesses that could be used in attacks more quickly.

AI Attacks, and AI Defends

This shift is not limited to Microsoft. On the same day that EvilTokens was disclosed, cybersecurity company Palo Alto Networks also announced a new AI-powered security service. Using models including Anthropic’s Claude and OpenAI’s GPT family, the service continuously examines web applications, APIs, and cloud environments to identify vulnerabilities and potential attack paths. When it finds a problem, it analyzes the cause and suggests ways to fix it.

https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-delivers-anthropic-s-mythos-and-openai-s-gpt-5-6-to-customers-with-unit-42-continuous-frontier-ai-defense

At first glance, this may not sound like an entirely new technology. Cybersecurity has long used automated systems to detect anomalies and handle repetitive tasks. So what changes when AI enters the picture?

The difference lies in what is being automated. Traditional security automation has been particularly effective at detecting problems based on predefined rules and conditions. More recent AI systems, however, are beginning to take on the task of analyzing multiple sources of information together and assessing how a particular weakness might actually lead to an attack. The scope is expanding from simply asking whether “something unusual is happening” to considering “how this problem could actually be exploited.”

The approach presented by Palo Alto Networks reflects this shift. Rather than scanning a system once and stopping there, AI continuously examines it for paths that an attacker could exploit. The goal is not only to detect a problem after something has happened, but to examine the system from an attacker’s perspective before an attack occurs.

But this capability is useful to attackers as well. Microsoft has explained that AI can go beyond identifying individual vulnerabilities to connecting separate weaknesses into an attack path and determining whether they can actually be exploited. If defenders can use AI to examine systems from an attacker’s perspective, actual attackers can use the same technology to search for ways in.

This is where the boundary between attack and defense becomes interesting. Their objectives are completely opposed, yet the tasks assigned to AI can look remarkably similar: examine a system, find weaknesses, explore multiple possibilities, and narrow them down to paths that can actually be used. The same capability can become either an offensive or defensive tool depending on who is using it.

Rather than creating entirely new forms of cyberattack or defense, AI is beginning to take over some of the searching and analysis that humans previously had to perform themselves. Attackers can find ways to strike faster, while defenders can discover vulnerabilities faster. Ultimately, what AI is changing in cybersecurity is the speed of both attack and defense.

What Matters After Discovery Is Response Time

Finding a vulnerability does not mean the problem is immediately solved. Its actual risk must be assessed, a fix must be developed, and the change must be tested to make sure it does not affect other functions before it can be deployed. Companies and institutions cannot address hundreds of problems at once, which means they also have to decide which ones to tackle first.

The 972 vulnerabilities discussed earlier should also be viewed in this context. As AI helps uncover more problems at greater speed, the number of issues that security teams must review and assess also increases. Faster discovery does not automatically make the subsequent process of validation, remediation, and deployment any faster.

That is why the ability to decide what to fix first is becoming just as important as the ability to find more vulnerabilities. Teams need to prioritize based on factors such as whether a vulnerability is already being exploited and how severe its potential impact could be, so that the most dangerous problems can be addressed sooner.

If AI is accelerating both attack and defense, faster vulnerability discovery alone will not be enough. The judgment and response that follow discovery must be able to keep pace as well.