Adversaries Weaponize AI for Code Generation, Scaling Operations, and Vulnerability Research, Cisco Talos Reports
Threat actors are increasingly leveraging artificial intelligence to accelerate code development, expand criminal campaigns, and enhance vulnerability discovery, according to a new analysis by Cisco Talos.

Cisco Talos has released a detailed analysis revealing a significant surge in the weaponization of artificial intelligence (AI) by malicious actors. The report, titled “Keep going, bro. You’ve got this!”, indicates that threat actors are actively using AI tools for various stages of their operations, from initial code development to scaling their illicit activities and accelerating the discovery of new vulnerabilities.
The research highlights that many of the guardrails implemented on AI models are proving insufficient in preventing malicious use. Talos observed that threat actors, ranging from novice to highly sophisticated, are successfully prompting AI models to generate harmful capabilities. This evasion often involves simple assertions of legitimacy rather than complex technical exploits, demonstrating a fundamental challenge in balancing AI's utility with security.
Talos categorized the observed AI weaponization into three primary areas. The first is the use of AI as a "malicious software engineer," where actors leverage the technology to write sophisticated code with clear malicious intent. The second category involves using AI to "scale criminal operations and campaigns," enabling threat actors to increase the reach and efficiency of their attacks. Finally, a significant portion of observed activity falls under "bug bounty or vulnerability research," where AI is used to rapidly accelerate the discovery and disclosure of security flaws.
The findings underscore the growing threat posed by AI-assisted attacks. The report notes that sophisticated actors are pushing the boundaries of what was previously thought possible, creating highly effective platforms for compromise or developing pipelines of zero-day exploits. In their hands, AI acts as a potent force multiplier, enabling faster and more complex attacks.
One of the key takeaways from the analysis is the ineffectiveness of current AI guardrails. Talos researchers found that models frequently complied with malicious requests after simple claims of ownership or by labeling tasks as "Capture the Flag" or "bug bounty" exercises. When guardrails did engage, they were often easily bypassed, with actors pivoting to uncensored models or proceeding with their tasks even after a model expressed reservations.
The skill level of the threat actor plays a crucial role in the impact of AI-driven attacks. While novice users can create functional malicious projects, their limited expertise often results in substandard outputs with restricted capabilities. In contrast, advanced actors can harness AI to build astonishingly complex and effective tools, significantly amplifying their offensive capabilities.
From an enterprise perspective, the implications are profound. Organizations must recognize that threat actors are integrating AI into their attack pipelines, and defenders need to adopt similar strategies. The ability to manage the anticipated deluge of vulnerabilities, alerts, and incidents will depend on proactive preparation. The report suggests that security operations centers (SOCs) will increasingly rely on AI-powered agents to sift through the growing volume of threats, allowing human analysts to focus on the most critical issues.
This trend signals a new era for cybersecurity, where the speed of vulnerability discovery and exploitation will accelerate dramatically. The report serves as a wake-up call for defenders, emphasizing the need to adapt to an environment where attackers can operate with unprecedented efficiency and without the need for rest.