AI-Driven Attack Paths in Enterprises Surge by 386%: New Insights from Cogent Security
Growing Threat Landscape for Enterprises
A recent analysis by Cogent Security has uncovered a notable surge in AI-exploitable attack paths within enterprises, highlighting significant shifts in the cybersecurity landscape. With the rise of AI technologies, new vulnerabilities are emerging that were previously impractical for human attackers to exploit. This transformation poses serious challenges to traditional security measures and strategies.
Details of the Report
The report, titled "Beyond the Human Horizon," examined data from over 43 million enterprise assets and 1.2 billion observed vulnerabilities, misconfigurations, and identity-related issues across the diverse digital settings of more than 50 Fortune 1000 companies. The findings indicated that in August 2026 alone, enterprises discovered an average of 45 new attack pathways directed towards their critical assets. Of these, only 11 were deemed viable for human attackers, whereas a staggering 34 existed solely for AI agents.
Insights on Attack Path Viability
This research has significant implications, demonstrating that AI can identify and exploit vulnerabilities far more efficiently than human operatives. The report indicates that the formation of machine-viable attack paths has surged by 386% year-over-year, compared to a modest 38% increase for paths viable for human attackers. Thus, for every attack mechanism that a human could realistically target, three new paths are emerging that predominantly attract AI intervention.
AI agents can handle more complex and extended attack paths, traversing multiple security domains without the limitations that typically restrain human attackers. In fact, the average machine-viable attack path was found to be significantly deeper, cutting across at least eight assets and involving five distinct trust boundaries, compared to four and two, respectively, for human-viable paths.
Key Findings and Statistics
The study highlighted several critical findings regarding attack paths, including:
1. Depth and Persistence: Approximately 83% of machine-viable attack paths remained present in an environment for more than 30 days, often relying on medium and low severity vulnerabilities that are usually overlooked by traditional security protocols.
2. Low-Intensity Vulnerabilities Leading to Critical Threats: Notably, 7% of critical attack paths in the dataset were created solely by chaining together low and medium severity vulnerabilities, which are often neglected in remediation priorities.
3. Cross-Domain Challenges: Over 64% of attack paths were found to traverse across different security domains, such as endpoint, identity, and network infrastructures, rendering them hard to detect using a single security tool. This necessitates a collaborative approach, as reconstructing these critical paths required integrating data from multiple security sources.
Implications for Cybersecurity Teams
As Vineet Edupuganti, CEO and co-founder of Cogent, pointed out, “AI agents are creating attack paths that security teams have never had to worry about before.” The emergence of these new pathways emphasizes a fundamental need for organizations to reevaluate their cybersecurity strategies and the tools they employ. Security teams must adapt to this evolving threat landscape by bolstering their defenses against AI-driven vulnerabilities that previously went unnoticed or unaddressed.
The Road Ahead
In conclusion, Cogent's report illustrates a crucial pivot in how enterprises must approach cybersecurity in a world increasingly influenced by artificial intelligence. Continuous advancements in AI will further complicate the security landscape, potentially leading to the emergence of even more innovative and challenging attack vectors. Organizations must remain vigilant, adapt strategies to detect these new attack paths, and implement robust defenses against the evolving capabilities of AI in cyberattack execution.
To read the full report and access in-depth analysis, visit Cogent's official website.