Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Check Point Research: AI Now Runs Every Stage of Some Cyberattacks

AI is doing more of the hacking, not just helping with it
Cybersecurity firm Check Point released research Monday night showing artificial intelligence is now involved in every stage of some cyberattacks, according to Defense One. That includes identifying targets, testing for vulnerabilities, writing exploit code, and moving through a victim's network after the initial breach.
Two years ago, hackers mostly used generative AI as a research assistant. It translated documents, answered technical questions, helped debug malicious code. The heavy lifting, the actual intrusion, stayed with human operators.
That's changing. Check Point's report describes cases where AI systems generated attack commands and executed thousands of them with less human direction than researchers had seen before.
"We watched criminal groups breach government agencies at scale, using AI as the primary operator rather than a background assistant," the report states, as quoted by Defense One.
Not fully autonomous, but close
A top Check Point executive told Nextgov/FCW the shift doesn't yet amount to fully autonomous hacking. Humans are still in the loop. But AI has moved from an occasional shortcut to something closer to an extra operator working alongside criminal hacking crews.
That's a meaningful distinction. Fully autonomous cyberattacks, where AI selects targets, executes a breach, and exfiltrates data with zero human oversight, would represent a genuine escalation in the threat landscape. What Check Point describes is still short of that. But the gap is closing, and the report notes that in most cases, it wasn't the victim organizations that caught the AI involvement. It was either the attacker's own mistakes or monitoring done by the AI companies themselves.
That detail matters. It means the institutions best positioned to catch this activity right now are private AI companies like OpenAI, Anthropic, and Google, not the government agencies and businesses actually getting hit. That's a real gap in defensive posture regardless of how good any single company's safety team is.
The Gentlemen ransomware group and VoidLink
Check Point's researchers point to a group called the Gentlemen ransomware operation as a concrete example. Members reportedly compared different commercial AI models against each other, largely based on which one imposed the fewest restrictions on malicious requests, according to Defense One. They then used AI to build internal tools, including a management platform that took just three days to develop.
A second example, a remote-access toolkit called VoidLink, initially looked to researchers like it took a team several months to build. Check Point later determined a single developer wrote roughly 88,000 lines of working code in under a week, using a commercial AI coding tool.
That's the practical stakes here. Work that used to require a team and months now takes one person and days.
U.S. models get tried first, then hackers pivot
Check Point's threat intelligence lead, Sergey Shykevich, told Defense One that hackers generally prefer American AI models like ChatGPT or Claude first, because the output quality is considered better. But those models come with stronger guardrails designed to block malicious use.
When U.S. models refuse to cooperate, hackers pivot to Chinese-made AI platforms with weaker restrictions, according to Shykevich. Open-source models and purpose-built malicious AI tools sold on the dark web are also in the mix, but Shykevich said major commercial providers remain the primary choice overall.
Guardrails on U.S. models clearly aren't stopping determined attackers. They're rerouting them to less-restricted alternatives, often built by foreign adversaries. Safety restrictions on American AI companies function more as a speed bump than a wall, and the real fight is against the proliferation of unrestricted foreign models, not just tightening rules on U.S. firms.
At the same time, the fact that stronger guardrails force attackers into a less-effective toolset, lower-quality outputs from other platforms, is itself evidence the restrictions have some deterrent value, even if imperfect.
What's unresolved
Check Point hasn't named which specific government agencies were breached in AI-assisted attacks, and no attribution to a specific nation-state group has been made public in the reporting available. Whether the U.S. government or NIST plans any new guidance for federal agencies in response to this specific research is not yet known. Check Point's report was released Monday night. How U.S. cybersecurity agencies like CISA respond, if at all, is the next thing to watch.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.