SANS at RSAC 2026: For the First Time, All Five Most Dangerous Attack Techniques Are Powered by AI
At RSAC 2026, the SANS Institute revealed a historic milestone: for the first time, all five of its most dangerous attack techniques are driven by artificial intelligence, including AI-generated zero-day exploits for as low as $116 and autonomous attack chains that can finish in under 10 minutes.

SANS Institute researchers reveal five most dangerous AI-powered attack techniques at RSAC 2026 in San Francisco
Each year at RSAC Conference, the SANS Institute delivers one of the most anticipated sessions in cybersecurity: its annual briefing on the five most dangerous new attack techniques. But 2026 marks a milestone that even veteran attendees did not see coming. For the first time in the session's history, all five techniques share a single common thread — artificial intelligence.
"We would be lying to you if we pointed out a trend in attacks that did not involve AI," said Ed Skoudis, President of SANS Technology Institute and session moderator, addressing the packed audience. "That is just where we are in the industry."
1 — AI-Generated Zero-Days: From Scarcity to Surplus
Zero-day exploits once belonged exclusively to well-funded nation-state actors with teams of specialist researchers behind them. That barrier to entry has been shattered. Joshua Wright, faculty fellow and senior technical director at SANS, revealed that independent researchers have discovered AI-generated zero-days in widely deployed production software for as little as $116 in AI token costs — a dramatic reduction from the millions that sophisticated actors previously invested.
"Attackers were already faster than us," Wright said. "AI has made the gap unbridgeable at our current pace."
Wright described the "industrialisation" of zero-day exploits through AI as shattering assumptions that such attacks are rare events, warning defenders to prepare for a wave of AI-designed zero-days arriving on a weekly basis. Tech Prescient The prescription: accelerated patch management, automation, and AI-powered defensive tools — ideally deployed before the next wave arrives.
2 — Software Supply Chain: Your Vendor's Vendor's Vendor
Two out of three organisations were affected by a software supply chain attack over the past year, Wright said, with surges in both third-party involvement in breaches and the volume of malicious packages published to open source registries.
Among the examples cited: the Shai-Hulud worm has infected more than a thousand open source packages and exposed 14,000 credentials across 487 organisations. Separately, a China-affiliated group compromised the Notepad++ update infrastructure for six months, selectively delivering backdoors to targets in the energy, finance, government and manufacturing sectors.
"Your attack surface is not the software you chose. It is the entire ecosystem of suppliers behind it," Wright said. His advice: demand not just a software bill of materials (SBOM) but verifiable proof of how software was built — and treat every update channel and developer tool as a potential supply chain risk.
3 — OT Complexity and the Root Cause Crisis
Robert Lee, SANS Institute fellow and CEO of Dragos, described a growing accountability crisis in operational technology (OT) security — one where critical evidence of intrusions simply evaporates because adequate monitoring is never in place to begin with.
Lee pointed to the December 2025 attack on Poland's distributed energy resources — which Dragos attributed with moderate confidence to the Russia-linked group ELECTRUM — as a sobering case study. The attack targeted distributed energy resources including wind farms, solar installations and combined heat and power facilities. Investigators confirmed disruption had occurred, but there was no visibility into what the threat actor was doing inside the systems following the breach because of a lack of OT monitoring in place.
In another case, a state-level threat actor with intent to destroy equipment and cause casualties had been targeting a facility with no visibility into its own infrastructure. A month later, the facility exploded. Investigators still cannot determine whether it was a cyberattack or an accident.
"Governments are not going to be comfortable not knowing what happened in their critical infrastructure and why someone died," Lee said. "That scenario is unacceptable, and it is already happening." He warned that the investment in OT visibility cannot wait for the next catastrophe to force the issue.
4 — The Dark Side of AI in Digital Forensics and Incident Response
Heather Barnhart, head of faculty and senior forensics expert at SANS, brought a warning from the digital forensics and incident response (DFIR) frontlines. Organisations deploying AI in investigations without proper training, validation frameworks and investigative discipline are setting themselves up for failure — and potentially making incidents worse, not better.
AI does not know what to look for and cannot interpret evidence the way a trained human analyst can. A confident but incorrect AI verdict wastes time, wastes resources and can send a response down entirely the wrong path.
"Most breaches don't fail because of tools," Barnhart said. "They fail at decision points. AI cannot be the decision point."
She also reminded the audience that AI is being weaponised against vectors few organisations are actively monitoring — including AI notetaking tools — meaning the attack surface has ballooned well beyond the traditional network perimeter.
5 — The Race to Autonomous Defence
Lee returned for the session's final technique, presenting data showing that AI-driven attacks now move 47 times faster than human-operated approaches. A threat actor can take a stolen credential and escalate to full admin control in an AWS environment in under 10 minutes.
Lee cited a documented campaign from November — designated GTG 1002 and attributed to a Chinese state-sponsored group — that targeted more than 30 government and financial organisations. The operation used AI tools to automate up to 90% of the attack process, including reconnaissance, exploitation and lateral movement inside networks, with much of the damage carried out without any human involvement.
The answer, Lee argued, is to build equivalent speed on the defensive side. He pointed to Protocol SIFT — an open source experimental initiative from SANS built on the widely used SIFT Workstation — which uses AI to organise workflows, surface insights and coordinate tools while keeping humans in the validation and decision-making seat. In one response exercise involving a sophisticated two-week attack scenario, an analyst using Protocol SIFT wrapped up the entire investigation in under 15 minutes — identifying the malware, mapping attacker movements, aligning activity to known frameworks and determining next steps.
"The goal is to accelerate analysts, not replace them," Lee said. "They have their artificial intelligence. Now we build ours."
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.