Hackers Without Skills Now Exploit Flaws in Minutes. The Asymmetry Is the Story.
New Scientist reports that AI-wielding attackers with zero technical skill are now finding and exploiting software vulnerabilities at unprecedented speed. Nordvedt, a cybersecurity expert cited in the piece, notes that the gap between a vulnerability appearing in the public CVE database and its exploitation by hackers has collapsed from weeks or months to as little as 24 hours. Now it can be minutes. Sometimes the hack precedes the CVE listing entirely.
The principle here is capability democratization in the adversarial direction. When the cost of launching a sophisticated attack drops to near zero because the AI handles the technical reasoning, the volume of attacks scales while the skill floor vanishes. The mental model is asymmetry of defense versus offense. A defender must patch every vulnerability. An attacker using AI need only find one. Organizations without large cybersecurity budgets are now exposed to the same attack patterns previously reserved for well-funded adversaries. The lesson for everyone: your personal accounts face the same dynamic in miniature.
Nordvedt and Hillel-Tuch, both cited in the New Scientist report, are tracking this collapse in the exploitation timeline. Nordvedt attributes the acceleration directly to malicious AI use by actors who lack conventional hacking skills. Hillel-Tuch notes that AI models are becoming more capable, which compounds the problem.
- Go to haveibeenpwned.com and enter your primary email address. This will show you which data breaches have already exposed your credentials.
- For each breached account, change the password to a unique randomly generated string using your browser's built-in password manager or a free tool like Bitwarden.
- Enable two-factor authentication on every account that offers it. These three steps close the most common vulnerabilities that AI-assisted attackers exploit when they reuse leaked credentials at scale.