VYPR
trendPublished Aug 17, 2026· 1 source

AI Shifts Cybersecurity Battleground: Defenders Gain Edge in Vulnerability Race, but Social Engineering Risks Rise

Mandiant's Charles Carmakal highlights AI's dual role in cybersecurity, noting defenders currently lead in vulnerability discovery while AI-driven social engineering and supply chain attacks pose growing threats.

The cybersecurity landscape is undergoing a significant transformation as artificial intelligence becomes a more prominent tool for both attackers and defenders. Charles Carmakal, chief technology officer at Mandiant Consulting, part of Google Cloud, observed that while adversaries are increasingly leveraging AI for vulnerability discovery and exploit development, defenders currently maintain an advantage in this critical race.

Carmakal's insights, shared at Black Hat USA 2026, suggest that the immediate and most pressing risks are not solely technical. He pointed to a growing gap in human defenses, particularly concerning AI-enhanced social engineering. Previously, foreign accents in phishing calls or help desk interactions could serve as a tell-tale sign of malicious intent. However, AI-powered voice synthesis now allows attackers to mimic credible American, Canadian, and British accents, making these attacks far more convincing and harder to detect by employees and IT support staff.

Beyond social engineering, Carmakal emphasized the evolving threat posed by AI in other attack vectors. Data theft and extortion are increasingly supplanting traditional ransomware attacks, largely due to improvements in Endpoint Detection and Response (EDR) solutions that make ransomware deployment more difficult. This shift means that attackers are focusing on exfiltrating sensitive data and then extorting victims, rather than encrypting their systems.

Nation-state actors, according to Carmakal, are continuing to target edge devices such as firewalls. These devices often lack the robust EDR coverage found on endpoints, making them attractive targets for espionage and disruption. The compromise of these perimeter devices can provide attackers with a crucial foothold into an organization's network.

Furthermore, Carmakal stressed the critical importance of addressing software supply chain risks. These risks can expose developer credentials, cloud environment access, and ultimately lead to widespread compromise if malicious code is injected into software development pipelines. The SolarWinds attack and the Colonial Pipeline disruption serve as stark reminders of the devastating impact of supply chain compromises.

Carmakal, who leads a team of incident responders and consultants, has extensive experience investigating major breaches attributed to both nation-state actors and organized criminal groups. His work involves not only responding to incidents but also advising organizations on how to bolster their cybersecurity defenses against sophisticated threats.

The current dynamic, where AI aids defenders in finding vulnerabilities faster, is a temporary reprieve. As AI capabilities advance, the balance could shift. Organizations must therefore focus on a multi-layered security strategy that includes technical defenses, robust human training against social engineering, and vigilant oversight of their software supply chain to mitigate the evolving risks.

Synthesized by Vypr AI