TIPS #40: It’s Time for Active Defense
Shane Shook
June 23, 2026
- Blog Post
- TIPS
Issue: Agentic AI is undermining passive detect and response, and companies underinvest in active controls that limit how much damage agentic attackers can do.
For decades, the dominant cybersecurity model has been detect and respond: deploy enough sensors and response tooling to identify attacks and breaches and react accordingly. As a result, passive capabilities like monitoring, detection, logging, incident response, patching, and forensic readiness are common in many security functions.
AI agents shift the paradigm
Agentic AI is changing the threat landscape and risk calculus by accelerating attacker tempo and efficacy. AI attackers work at machine speed, continuously operate, and can target company brands, finances, and infrastructure simultaneously.
Consider that threat actors are beginning to use capable AI agents to:
- Sustain parallel operations across dozens of targets, as opposed to targeting one system at a time
- Perform vulnerability discovery at scale and rapidly chain numerous low-severity vulnerabilities into working exploits, instead of targeting a single high-severity vulnerability
- Escalate from initial access to data exfiltration in minutes, rather than days
- Evade serial defenses that rely on historical patterns of escalation (such as those documented by MITRE ATT&CK) by jumping across phases, instead of following a predictable sequence
- Confuse forensic investigators attempting to reconstruct an incident, preventing long-term security improvements
The net effect is that attackers don’t need to be nearly as patient, skilled, or well-resourced to successfully breach and compromise systems. This new reality invalidates a core assumption of a passive security posture: that there’s a sufficient window of time between detection and damage to react and prevent escalation. Machine-speed attacks collapse that time window, and a posture primarily built to react will always lag.
Recent threat data shows that defenders are already falling behind. According to data from the 2026 Verizon DBIR, AI is lowering the barrier to entry while increasing tempo for attackers. The report found that threat actors are using AI across the full attack chain and, notably, that exploiting unpatched vulnerabilities has become the single most common way into a breach, while the median time to remediate a known exploited vulnerability rose to 43 days.
Passive approaches fall short
Faced with faster and more frequent attacks, many security teams double down on two passive approaches: patching faster and identifying the root causes of successful attacks. Both are important functions, but both are retrospective. Patching closes a door after it’s been found open and given how quickly AI-enabled vulnerability exploitation happens, patch cycles likely can’t keep up. Root-cause analysis and remediation explain an incident after the fact and help improve long-term posture, but don’t limit what the attacker already accomplished.
Fundamentally, a security program built primarily around reactive functions is prepared to manage the aftermath of an attack, not mitigate what the attackers are able to achieve before detection and response is activated. Reacting faster or understanding the cause of an incident doesn’t change the fact that gaps in the company’s security posture enabled an attack to escalate into a breach or compromise.
Active defenses are essential, but rarely prioritized
Active defenses are essential to combat agentic AI-powered attacks. They are not a replacement for passive defenses that detect and respond, but rather a layer that sits in front of them to limit how much damage is possible.
Many organizations have taken initial active steps by investing in awareness training, incident response scenario planning, resilience auditing, and assurance. These measures have gained traction largely because they mirror proven best practices businesses already use to defend their market positions, brands, and operations.
However, many active defenses are inherently hard to visualize and justify. Success is defined by incidents that don’t occur and damage that isn’t achieved. As a result, the default security posture still favors detect and respond over predict and prevent, and very few companies implement critical active measures such as:
- Anticipating attacker behavior from world and market events through counterintelligence
- Building interdiction capabilities that defeat reconnaissance probes and social coercion tactics before they mature into intrusions
- Designing adaptive defenses that assume attack in depth from the outset
- Deploying measures like digital twins and deception environments that deny the attacker a stable target
Impact: Companies with insufficient active defenses face a greater risk of data theft, operational disruption, and financial loss.
Documented agentic attacks show the threat isn’t theoretical. Recent incidents demonstrate why organizations need to restructure their security posture to limit potential damage.
Agentic AI-Enabled Attacks (2025-2026)
In September 2025, Anthropic identified and disrupted GTG-1002, the first documented large-scale cyberattack executed predominantly by AI. A Chinese state-sponsored group weaponized Anthropic’s Claude Code tool to target approximately 30 organizations including major technology firms, financial institutions, chemical manufacturers, and government agencies. Claude Code independently handled an estimated 80 to 90 percent of tactical operations including reconnaissance, vulnerability identification, exploitation, lateral movement, credential harvesting, and data extraction, with limited human review at final exfiltration and approval. The attack ran continuously, was handed off between operators without loss of context, and resumed after interruptions without re-briefing. In a report on the incident, Anthropic noted that the operational tempo was evidence of an autonomous AI-enabled attack, with peak activity reaching “thousands of requests, representing sustained request rates of multiple operations per second.”
Starting in late December 2025, an unrelated attack campaign used Claude Code to successfully compromise ten Mexican government agencies. The attackers used Claude Code to create exploits, generate tools, and automate exfiltration, and used ChatGPT-4.1 to analyze data and accelerate the attack. The campaign ultimately exfiltrated more than 150GB of data from the agencies, exposing around 195 million records including government employee credentials, taxpayer records, and civil registry files.
These incidents demonstrate the lower barrier to entry, speed, and scale enabled by agentic AI-driven attacks, and the significant damage they can do if organizations aren’t prepared.
Claude Mythos and Project Glasswing (2026)
In April 2026, Anthropic announced Project Glasswing, a closed consortium of large enterprises and security vendors testing Mythos Preview, a new Claude model which demonstrated significant improvements in finding and exploiting vulnerabilities. Mythos Preview was reportedly able to autonomously identify thousands of zero-day vulnerabilities across every major operating system and browser, including flaws that had survived decades of human audits.
Cloudflare, one of the Project Glasswing participants, directed the model at its own repositories and observed the model chain low-severity bugs into severe exploits with working proofs of concept. Cloudflare concluded that faster defense and patching weren’t sufficient, and that security teams should instead focus on making exploitation and escalation harder in the first place to make patching gaps matter less.
The results from Project Glasswing show that agentic attacks can collapse the window of time between vulnerability discovery and weaponization. They also point to the importance of developing a more active posture that limits the impact and escalation of agentic attacks.
Action: Create zones of active defense that complement passive capabilities with a predict-and-prevent posture.
To combat AI-enabled attacks, deploy active defenses that make the terrain- company systems, identities, and assets- continuously hostile to an AI attacker. This ensures that passive defenses manage a contained event.
1) Active Identity Defense: Enforce Zero Trust and Conditional Access
Agentic AI attacks degrade the variable of time from a defensive perspective: they occur faster and more frequently than manual attacks. This undermines static perimeter identity defenses that assume a trusted interior.
Companies should implement Zero Trust and require continuous policy verification for every access request, in addition to enforcing conditional access to impose a cost per action rather than a cost per time period. Together, these controls force agentic attackers to continuously re-satisfy policy requirements, raising attack costs and diminishing throughput.
1Kosmos unifies identity proofing and passwordless authentication in a single platform, binding every access request to a verified human identity rather than a reusable credential to prevent AI-powered impersonation, deepfakes, and social engineering attacks.
“In a world with novel identity attacks enabled by AI-generated documents, deepfakes, and biometric spoofing, we have to rethink how identity works. Every access request or action, whether human or machine, needs to be tied to a verified individual.”
Hemen R. Vimadalal CEO and Co-founder, 1Kosmos
2) Active Terrain Defense: Destabilize Targets
Agentic attacks overwhelm static systems because they exhaustively enumerate infrastructure at machine speed. Security teams should design their defenses around this reality.
Continuously rotating IP addresses, ports, credentials, and process names forces agentic attackers to re-enumerate constantly, burning attack budget on every cycle. In addition, coordinated decoys, honeypots, and canaries can be particularly effective countermeasures against agentic attacks. Canary tripwires should utilize dynamic discretionary rules and create an adaptive response- not a static blocklist- that fingerprints the agent’s behavior, creates sinkholes, and progressively degrades access by slowing responses and narrowing reachability.
Huntress helps companies protect endpoints with 24/7 managed EDR, including by deploying lightweight ransomware canaries that trigger an adaptive SOC-verified investigation and response.
3) Active Network Defense: Segmentation and Blast Radius Mitigation
Cybercriminals increasingly rely on behavioral evasion, Living off the Land, and lateral movement to persist in networks, steal data, and deploy ransomware. Agentic attackers add another layer of complexity by utilizing less predictable attack sequences. Defenders need to actively limit the potential blast radius from an attack.
Segmentation is a key structural control that limits how far autonomous lateral movement can propagate before hitting a policy boundary. It creates an architectural constraint on the damage any single agentic foothold can achieve. When combined with identity-based access controls, microsegmentation can transform a network into a collection of isolated micro-perimeters, each requiring fresh authentication and authorization- ultimately limiting movement and damage.
Lumu’s Continuous Compromise Assessment® capabilities monitor network activity across endpoint, cloud, identity, and OT assets to identify compromises in real time, in addition to automating containment and host isolation to prevent lateral movement.
“Building higher walls and stronger perimeters doesn’t work when attackers are already blending into your network traffic. Start with the assumption that the adversary is already inside and create a dynamic security posture anchored in continuous attack visibility.”
Ricardo Villadiego CEO and Founder, Lumu
4) Active SOC: Leverage AI for Investigations, Response, and Posture Improvements
AI can accelerate both passive and active defense in the SOC. On the reactive front, autonomous AI can improve detection, investigation, and response. On the active side, AI tools can identify threats and attacker patterns from investigations, generating insights to strengthen security posture.
Qevlar AI deploys autonomous AI agents that investigate and respond to every SOC alert, while learning from emerging threats, TTPs, and active vulnerability exploitation to improve security posture.
“SOCs shouldn’t measure success by how many alerts they resolve and how quickly they do it. The goal of the SOC is to develop a defensive posture that gets harder to breach over time. AI has the potential to make SOCs both faster and stronger to effectively combat agentic attacks.”
Ahmed Achchak Co-founder and CEO, Qevlar AI