October 2, 2026
The Verizon Report Just Proved Something Terrifying: Attackers Are Using AI to Exploit Bugs inβ¦
31% of breaches now involve AI-assisted exploitation. I spent 8 months learning at human speed.

By Riya Limba
3 min read
31% of breaches now involve AI-assisted exploitation. I spent 8 months learning at human speed.
I read the Verizon DBIR on a Sunday morning and felt something cold settle in my chest.
The report analyzed 31,000+ security incidents and 22,000+ confirmed breaches across 145 countries. The headline finding: vulnerability exploitation has overtaken stolen credentials as the primary initial access vector β for the first time in DBIR history.
That alone is significant. But the sentence that stopped me was this:
"Attackers are now able to compromise systems within hours instead of the months previously required."
I read it four times. Then I closed the laptop and sat there for a minute.
What I've Been Doing for 8 Months
I've been learning bug bounty at human speed.
Reading docs. Watching tutorials. Testing one endpoint for weeks. Writing reports that take 45 minutes because I'm following a template.
I'm not fast. I'm not efficient. I'm learning.
The Verizon report says the attackers aren't learning at human speed anymore. 31% of confirmed breaches involved AI-assisted exploitation. Not AI writing phishing emails. Not AI generating deepfakes. AI discovering, analyzing, and exploiting software vulnerabilities.
The gap between how fast I learn and how fast attackers operate just became a chasm.
The Hacktron Case Proved This in Real Time
I wrote recently about the Hacktron AI researchers who broke into OpenAI's internal systems using Claude.
They started on July 23. By the morning of July 25 β less than 48 hours β they had remote code execution on OpenAI's forum server and access to internal code repositories.
Three researchers. About $3,000 in API costs. Claude did the heavy lifting: analyzing Docker images, identifying missing patches, building working exploits, adapting them across architectures.
The bug wasn't exotic. It was a missing backport of a security patch in libheif β an image parsing library that Debian hadn't updated. The kind of dependency version gap that exists everywhere.
But the speed was unprecedented. Work that once required months of expertise and a well-resourced team was compressed into days.
And that was white-hat researchers using AI to find bugs responsibly.
What the Verizon Report Says About the Other Side
The DBIR doesn't just document AI-assisted defense. It documents AI-assisted attack.
The report found that attackers are using AI to:
- Identify vulnerable systems at scale
- Analyze patch gaps and dependency chains
- Build working exploits faster than defenders can patch
"Shadow AI" β unauthorized AI tools used by employees β is making it worse. Sensitive internal data, source code, and business documents are being fed into external AI services, creating new exposure surfaces that organizations can't see.
Verizon's recommendation is blunt: "Prioritize vulnerability management, rapid patching processes, and incident response preparedness".
Translation for the rest of us: speed is now the only defense that matters.
Why This Terrifies Me Specifically
I don't have a CVE. I've found one confirmed bug. I'm still learning how to read HTTP requests properly.
The attackers described in the Verizon report aren't waiting for me to catch up. They're using AI to:
- Scan faster than I can learn
- Exploit faster than I can report
- Move laterally faster than I can document
Gartner's 2026 emerging risk survey found that AI-enabled vulnerability discovery is now the top risk facing organizations worldwide. Not ransomware. Not phishing. The speed at which AI can find and weaponize flaws.
I'm learning at human speed in a world that's moving at machine speed.
What I'm Doing Differently
I can't compete with Claude on speed. I can't scan faster than an AI agent. But I can do three things the machines still struggle with.
First, I'm going deeper on fewer targets. AI is good at pattern matching. It's good at scanning known vulnerability classes. It's not good at understanding why an application behaves the way it does. Business logic. State transitions. The weird edge cases that don't show up in scanner output.
Second, I'm documenting everything. The Hacktron researchers used AI to find the bug, but they understood the chain. They knew which dependency to look at. They knew what "missing patch" meant. The AI was a tool, not the skill.
I'm building the skill.
Third, I'm paying attention to what's actually being exploited. Verizon's report says 31% of breaches involve AI-assisted exploitation. That means 69% don't. There's still room for human judgment. There's still room for the kind of bugs that require noticing something that doesn't look wrong β but is.
The Uncomfortable Truth
Verizon's report isn't saying AI has replaced human attackers. It's saying AI has accelerated them.
The Hacktron case shows the same thing on the defensive side: AI can help researchers find bugs faster, but someone still needs to understand what they're looking at.
The gap between learning and exploitation is closing. But it hasn't closed.
I don't know if I'll ever be fast enough to compete with an AI-assisted attacker. But I know I can't quit because the speed limit changed.
I'm adjusting. Slower than the attackers. But still moving.
If you're also learning security in a world that's speeding up faster than you can keep up, I write about what I'm actually figuring out β confusion included. Follow for more field notes from the bottom of the learning curve.