top of page

The Cybersecurity Arms Race: How AI Is Used to Attack and Defend Networks Simultaneously

The Cybersecurity Arms Race: How AI Is Used to Attack and Defend Networks Simultaneously

The Cybersecurity Arms Race: How AI Is Used to Attack and Defend Networks Simultaneously

By Alex Rivera, Senior Technology Reporter. This publication verifies claims against primary sources including Reuters, Bloomberg, and official vendor disclosures.

AI tools now generate phishing emails that achieve click rates above 85 percent.

Security teams face the same tools used against them.

This shift began gaining speed in early 2025.

Attackers adopted large language models for rapid content creation.

Defenders responded with automation in security operations centers.

The result is a direct contest between the two sides.

Attack tools reach new speed

LLM assisted malware now writes code variants in hours instead of weeks.

One group used synthetic voice calls to impersonate executives.

The calls bypassed voice checks in multiple firms during 2025 tests.

Attackers feed prompts into models to craft messages that match target industries.

They test the output against open source filters before sending.

The process repeats until evasion succeeds.

These steps allow small teams to run campaigns once limited to larger groups.

Reports from CrowdStrike (2025 Global Threat Report) show volume increases of more than 200 percent year over year.

Defense platforms apply the same models

AI SOC platforms scan logs and flag anomalies in real time.

They train on labeled incident data to prioritize alerts.

Teams using these platforms report a drop in mean time to respond from days to minutes.

The platforms connect to endpoint data and network traffic streams.

They generate suggested actions for analysts to review.

This setup keeps humans in the loop while speeding initial triage.

Vendors in this space include CrowdStrike (Falcon), Palo Alto Networks (Cortex XSIAM), and Microsoft (Sentinel).

Their shared claim is that models handle the first pass better than rule based systems alone.

Security teams select practical mixes

Most teams now run both attack simulation tools and defense automation.

They test their own email filters with generated phishing samples.

They run internal red team exercises that use LLM code generators.

The goal is to measure detection rates before real incidents occur.

One common setup pairs an AI SOC platform with endpoint detection software.

Analysts review flagged items and update rules based on model output.

This hybrid approach appears in recent surveys of enterprise security groups.

It balances speed with human oversight.

Limits and remaining gaps

Attack models still produce detectable patterns in some cases.

Voice synthesis fails on live calls when background noise differs.

Defense models create false positives that tire analysts over time.

Teams report alert fatigue when models flag every minor change.

Neither side has reached consistent dominance.

The contest continues with each side adjusting after each wave of incidents.

What to monitor next

Watch for new model releases that claim better evasion or detection scores.

Track regulatory moves on synthetic media rules.

Note earnings reports from security vendors that break out AI feature revenue.

Observe large breach post mortems for signs of LLM involvement.

These signals will show which side gains ground in the coming months.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

For better AI experience,

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

​Add Search Bar in Your Brain

Just Ask remio

Remember Everything

Organize Nothing

bottom of page