Skip to main content

Share story

Security

IBM releases 2026 X-Force Threat Intelligence Index on AI-driven attacks

IBM releases 2026 X-Force Threat Intelligence Index on AI-driven attacks Image: Primary
IBM released the 2026 X-Force Threat Intelligence Index. The report shows that cybercriminals are exploiting basic security gaps at dramatically higher rates, now accelerated by AI tools that help attackers identify weaknesses faster than ever. IBM X-Force observed a 44 percent increase in attacks that began with the exploitation of public-facing applications. The increase is largely driven by missing authentication controls and AI-enabled vulnerability discovery. Vulnerability exploitation became the leading cause of attacks. It accounted for 40 percent of incidents observed by X-Force in 2025. Active ransomware and extortion groups surged 49 percent year over year. This marks ecosystem fragmentation, while publicly disclosed victim counts rose roughly 12 percent. Large supply chain and third-party compromises nearly quadrupled since 2020. Attackers increasingly exploit environments where software is built and deployed or SaaS integrations. Mark Hughes, Global Managing Partner for Cybersecurity Services at IBM, said that attackers are not reinventing playbooks but speeding them up with AI. The core issue is that businesses are overwhelmed by software vulnerabilities. The difference now is speed, allowing attackers to bypass humans and move straight from scanning to impact. Security leaders need to shift to a more proactive approach using agentic-powered threat detection and response to identify gaps and catch threats before they escalate. Infostealer malware led to the exposure of over 300,000 ChatGPT credentials in 2025. This signals that AI platforms have reached the same credential risk as other core enterprise SaaS solutions. Compromised chatbot credentials create AI-specific risks beyond simple account access. Attackers can manipulate outputs, exfiltrate sensitive data or inject malicious prompts. This underscores the need to assess enterprise-wide AI adoption and enforce strong authentication and conditional access controls.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from IBM and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

AI Capital
AI Capital

Chinese local governments offer incentives to AI filmmakers

Reuters reports that Chinese local governments are offering computing vouchers, rent waivers and dedicated funding to attract filmmakers using artificial intelligence. These incentives reduce the cost of computing and premises for...

Security AI
Security AI

GitHub Security Lab releases agent workflow for automated fuzz testing

GitHub Security Lab has published a workflow that uses an AI agent to set up and run fuzz tests for C and C++ projects. Given a repository, it selects functions to test, writes test harnesses, runs AFL++, checks which code the tes...