AI News Feed
Market watch
Cybersecurity

AI compresses attacker handoff time to 22 seconds, analysts say at Black Hat USA

At Black Hat USA, AI-driven attacks now leave defenders just 22 seconds to respond, making cyber resilience a business imperative.

Jon Oltsik, analyst in residence at theCUBE Research, cited Mandiant’s “M-Trends 2026” report showing that the median interval between an initial access event and the handoff to a secondary threat group fell from more than eight hours in 2022 to just 22 seconds in 2025. As the response window contracts beyond what human-only teams can match, defenders need contextual intelligence to close the AI security skills gap, Case added.

One insight from the event is that cyber resilience now demands context and dynamic control. With frontier AI models compressing response times and autonomous agents able to access sensitive systems and improvise toward their goals, static entitlements are insufficient. Oltsik warned that agents may exhibit “rogue behavior,” making non-human and agentic identities a critical, dynamic challenge. Visibility into agent actions is the necessary first step toward oversight.

Another insight concerns broadening cyber defense across development, operations and enforcement. David Weston, corporate vice president of AI security at Microsoft, pointed to safer software construction using memory-safe languages and formal verification. He said Microsoft used agents for this work and achieved a massive production increase. The process caught a vulnerability that would have been “pretty catastrophic” had it shipped, even though it passed all tests and human expert analysis. Apple had a similar case, he added.

Once software is in production, resilience depends on breaking down data barriers between security and engineering teams. Emilio Escobar, chief information security officer at Datadog, said a unified context for both teams is essential. When both see the same data through different lenses, they can identify common root causes and prioritize fixes based on runtime exposure and business importance rather than severity scores alone.

Looking beyond enterprise systems, Fortinet’s cybercrime bounty program extends Crime Stoppers International’s anonymous reporting model to cyber threats for the first time. The program aims to close the accountability gap and slow the growth of the cybercrime industry by helping law enforcement identify and hold attackers accountable.