Published: October 6, 2026
AI Powered Attacks Demand Application Resilience
What CISOs and AppSec leaders should do as autonomous agents change the economics of exploitation
AI is not creating an entirely new category of application weakness. It is making familiar weaknesses cheaper to find, faster to exploit and easier to attack at scale. The security response must therefore move beyond periodic testing and patching toward continuously verified application resilience.
The number that should concern every CISO
In September 2026, Gambit Security disclosed an active campaign in which a Chinese-speaking operator used three off-the-shelf AI agent frameworks to attack online retailers. In five days, the operator launched 105 attack projects and compromised at least 27 organisations to varying degrees. Gambit attributed more than 600,000 unexpired payment-card records to two victims and confirmed malicious checkout skimmers across multiple websites.
The headline figure is not only the volume of stolen data. It is the cost. The attacker’s own records showed an average model cost of $25.46 across 101 completed scans, with individual targets costing between $3.13 and $79.31. That changes the economics of application attacks. Persistent probing, exploitation and adaptation no longer require a large team or a large budget.
The agents did more than run a fixed vulnerability scanner. They pursued objectives, changed tactics and chained weaknesses together. One documented path moved from SQL injection to multifactor authentication bypass, administrative access, arbitrary file upload, remote code execution, privilege escalation, cloud-secret extraction and payment-database access. Other agents modified legitimate JavaScript, poisoned content served through a CDN and established persistence that restored a malicious skimmer after the clean application was redeployed.
What has actually changed
None of the individual techniques is unprecedented. SQL injection, exposed secrets, excessive permissions, unsafe file uploads and malicious code modification have been part of the defender’s workload for years. What has changed is the operating model of the attacker.
- Speed: Autonomous agents can move from discovery to exploitation within hours, compressing the time available to investigate and remediate.
- Scale: The same operator can direct agents against tens or hundreds of organisations in parallel.
- Persistence: Agents can continue probing for hours, trying alternate approaches that a conventional scanner or opportunistic attacker might abandon.
- Adaptability: Agentic workflows can interpret results, select the next technique and combine weaknesses into an attack path that differs from one target to another.
- Economics: At tens of dollars per target, even organisations that were previously unattractive can be attacked profitably.
Security programmes built around human-paced attacks, periodic assessments and remediation windows measured in weeks are now operating against an adversary that works continuously and at machine speed. Finding and fixing vulnerabilities remains essential, but it cannot be the only line of defence.
The application as a route into high-value systems is not theoretical. ShinyHunters-branded campaigns have used voice phishing to persuade employees to authorise malicious connected applications within enterprise SaaS environments. Once approved, those applications received OAuth permissions that enabled attackers to query and exfiltrate corporate data and, in some cases, gain access to other connected cloud services. An application that may not have appeared business-critical became an authenticated route to sensitive backend data.
The application resilience gap
Together, these campaigns demonstrate that the application attack surface extends beyond individual software vulnerabilities. It includes application code, runtime behaviour, identities, integrations, permissions and trust relationships. As attacks become faster, cheaper and more adaptive, organisations must continuously verify that each of these layers can resist, detect and contain abuse.
The Digital.ai AI Resilience perspective starts from that assumption. The question is no longer only whether an application passed a security test before release. It is whether the application can continue to protect its code, logic, data and critical functions when it is placed in an untrusted environment and subjected to sustained, adaptive analysis.
For mobile applications, OWASP MASVS-RESILIENCE provides a technically credible foundation. It focuses on resistance to tampering, reverse engineering, static analysis and dynamic analysis. AI does not make those objectives obsolete. It raises the standard required to satisfy them. Controls that delayed a human analyst may not withstand an automated system that can generate scripts, vary techniques, interpret failures and continue trying.
What CISOs and AppSec leaders should do now
The response should be practical and staged. The following 30, 60 and 90-day plan is designed to reduce immediate exposure while creating a repeatable resilience programme.
First 30 days establish exposure and validate controls
Identify security-critical applications and attack paths. This must include any application, API, service, integration, administrative tool or third-party component with a direct or indirect path to customer data centres, backend systems, customer data, privileged identities, deployment pipelines or cloud control planes.
Identify priority customer-facing and their attack paths. Start with mobile, web and desktop applications exposed to customers, partners or employees, prioritising those that handle sensitive data or provide a direct or indirect route to backend services, privileged identities or cloud control planes. Trace the APIs, integrations and third-party components along those routes. then trace the paths they provide to sensitive systems. Start with applications that handle customer data or cnnect, directly or indirectly, to backend services, privileged identities, deployment pipelines or cloud control planes. Include the APIs, integrations, administrative tools and third-party components along those path
Do not limit the inventory to applications that directly generate revenue, process sensitive data or are conventionally classified as critical. An apparently low-value application becomes security-critical when its permissions, credentials, connectivity or transitive trust provide a circuitous route to higher-value systems.
Map transitive trust, inherited permissions and potential lateral-movement paths. For each application, establish what an attacker could reach after obtaining remote code execution (RCE) or administrative access. At that point, treat all reachable high-value data as exposed. Assign an accountable owner and confirm that monitoring can reveal unauthorised code, configuration or permission changes.
Within 60 days test at attacker speed and strengthen integrity
Move applications with direct or indirect paths to high-value systems toward continuous security testing. Use scenario-based exercises that chain weaknesses and pursue a business objective. For applications in untrusted environments, validate anti-tampering, platform-integrity, anti-static-analysis and anti-dynamic-analysis controls against current techniques. Measure detection, containment and verified-fix times.
Within 90 days operationalize resilience
Create a repeatable benchmark aligned to relevant OWASP requirements. Track control effectiveness over time, not simply control presence. Integrate protection telemetry with incident response and practise recovery of the minimum viable application and supporting services.
Five questions to take into the next security review
- Which application should we assess and protect first, based on its direct or indirect path to high-value systems and what is our plan to extend that protection across the rest of the application estate?
- How quickly would we know that application code, a runtime control or a delivered asset had been modified?
- Which protections have been tested against current AI-assisted workflows rather than only conventional tools?
- Can an attacker extract a secret, business rule or cryptographic asset from a distributed application and reuse it elsewhere?
- If an AI-assisted attacker chained several weaknesses together, could our application protections prevent, delay or expose tampering, runtime manipulation or asset extraction before the application became a route to higher-value systems?
Measure effectiveness rather than implementation
A checkbox can confirm that a control exists. It cannot confirm how long that control survives, whether it detects manipulation or whether bypassing one mechanism exposes the entire application. An AI resilience assessment should therefore measure observable outcomes: the effort required to understand protected code, alter application behaviour, attach analysis tooling, extract sensitive material and keep the application operating after modification.
This is also why benchmarking matters. Testing a representative set of real applications against a consistent methodology can show where current controls remain effective and where the industry’s baseline has fallen behind the attacker. Repeating that benchmark as models and tools evolve turns resilience from a one-time claim into measurable evidence.
From awareness to action
The lesson from this campaign is not that defenders should chase every new AI tool or rewrite their security programme after every headline. It is that the pace and economics of exploitation have permanently changed. Organisations should expect more attacks, more variation and less time between exposure and exploitation.
CISOs and AppSec leaders now need two capabilities working together: continuous testing that finds weaknesses before attackers do, and application resilience that limits what an attacker can learn, modify or abuse when prevention is not enough. The organisations that lead will be those that can demonstrate both, with evidence that their controls continue to work against the tools attackers are using now.
Sources
You Might Also Like
AI Powered Attacks Demand Application Resilience
What CISOs and AppSec leaders should do as autonomous agents…
ShinyHunters Retrospective: Knowing which apps need resistance to AI-fueled attacks
Somewhere in a Telegram group there may be a key…
AI Is Accelerating Cryptanalysis. Cryptography Must Learn to Adapt
In July 2026, Anthropic reported two cryptanalysis results produced with…