For years, automation has already made cyberattacks faster. Scanners, botnets, and scripts make it possible to scan for vulnerabilities across thousands of systems. However, AI agents introduce a different capability: not just executing a fixed sequence, but adapting steps and decisions to the context.

The Hacker News reported a case where an attacker allegedly used hundreds of AI agents to compromise more than 440 PaperCut instances. Even without turning a single episode into a universal forecast, the signal is significant: cybercrime is experimenting with a form of intelligent parallelization.

The bottleneck was human labor

Many sophisticated attacks require repetitive tasks that cannot be fully automated: interpreting a response, modifying a payload, deciding which technique to try next, checking whether access succeeded.

An AI agent can handle precisely this intermediate layer. It does not necessarily replace the expert, but it enables them to coordinate far more operations simultaneously.

Attacking like scaling cloud infrastructure

In the cloud, when load increases, resources are added. The same logic can be applied to an offensive operation: more agents across more targets, each with a task and operational memory.

This can lower the marginal cost of each new target. If the system can manage hundreds of adaptive attempts in parallel, the distinction between a targeted attack and a mass attack becomes less clear-cut.

Defense must assume the adversary does not sleep

Organizations are still often structured around human cycles: tickets, shifts, escalations, approvals. An automated offensive infrastructure, by contrast, can operate continuously.

The answer cannot simply be “let’s use AI too.” What is needed is reducing the time between detection and remediation, automating patching and isolation where possible, and above all, decreasing the number of unnecessarily exposed systems.

AI makes slowness more costly

A known vulnerability has always been a race against time. With agents capable of searching, testing, and adapting at scale, that window may narrow even further.

The most significant change will not necessarily be an artificial super-hacker. It could be something much more concrete: the ability for a single group to simultaneously do the work that previously required dozens of operators.

If this model spreads, cybersecurity will enter a phase where operational speed matters as much as the technical quality of defenses. And companies that take days to react to a signal will have to confront adversaries that think in minutes.