A security team that patches on a weekly rhythm may now be competing with software that reacts in minutes. Palo Alto Networks’ Unit 42 says attackers are using AI to compress parts of the intrusion cycle, and it has launched an AI-driven service meant to continuously find and remediate exposures before those weaknesses are exploited.1, 2, 3

IN BRIEF

Unit 42 says AI-assisted attackers compressed one intrusion from weeks of work to under 10 hours, while its September launch post says automated scanners can weaponize new CVEs within 15 minutes. Its broader 2026 report uses narrower wording: attackers begin scanning within 15 minutes. The evidence supports faster attack cycles, not a universal 15-minute exploit clock.1, 2, 3

What to watch as cyber defense becomes more automated. Whether independent incident data confirms the same compression in attack timelines…: 01. How often automated defensive findings produce safe fixes rather than another queue for…: 02. Which high-risk remediation actions remain gated by human approval.: 03. 3 of 4 entries shown. Selected labels are abbreviated. Full detail appears in the article.
What to watch as cyber defense becomes more automated. 3 of 4 entries shown. Selected labels are abbreviated. Full detail appears in the article.

How the attack window is compressing

  1. Within 15 minutes

    Scanning can begin

    Unit 42’s 2026 incident-response report says attackers start scanning for newly disclosed vulnerabilities within 15 minutes of a CVE announcement.3

  2. Under 10 hours

    One AI-assisted intrusion unfolded

    A Unit 42 investigation says a human-directed attacker used AI agents and more than 50 MITRE ATT&CK techniques to compress work normally taking weeks into less than 10 hours.2

  3. Under 1 hour

    Fast exfiltration is already observed

    Unit 42’s September launch post says time-to-exfiltration has compressed to under an hour in real-world attacks.1

The 15-minute number needs a label. Unit 42’s annual report says attackers begin scanning within 15 minutes. Its September 22 launch post uses the stronger wording that automated adversary scanners are “weaponizing” new CVEs within 15 minutes. Those statements are related but not identical, so the article should not turn them into a universal exploit deadline.1, 3

AI is compressing coordination more than inventing magic exploits

In Unit 42’s detailed intrusion case, the attacker still directed the operation. AI agents handled reconnaissance, mapped internal services, accessed repositories and adapted through the environment. Unit 42 says the operation used more than 50 MITRE ATT&CK techniques in under 10 hours and did not depend on a novel zero-day.2

That distinction matters. The danger is not necessarily that a model discovers a previously impossible attack. It can be enough for AI to make ordinary attack steps faster, more parallel and less dependent on continuous human attention. A workflow that once required several specialists can become a loop that keeps trying while the operator supervises.2

Defense is adopting the same loop

The emerging AI-versus-AI security loop1, 2
StageAttacker advantageDefender response
DiscoverAutomated systems monitor disclosures and scan exposed services quickly.Continuous testing looks for vulnerable paths before a scheduled assessment.
ValidateAgents can test and chain weaknesses with less manual coordination.Defensive agents validate whether a finding is actually exploitable.
ActAttackers can move laterally and adapt through a network at machine-assisted speed.Defenders automate remediation guidance, code-level fixes or virtual patches.
EscalateParallel agents can compress several attack tasks into the same time window.Human security teams focus on authorization, prioritization and high-consequence decisions.

Unit 42’s new service uses multiple frontier and open models to search continuously for exposures, validate attack paths and recommend remediation. The product is commercial, so its claims should be read with that incentive in mind. The interesting structural point is broader: periodic human testing is being challenged by systems that can both attack and test continuously.1

The evidence comes from a vendor with something to sell

Palo Alto Networks is both the source of the attack-speed evidence and the company selling the new defensive service. That does not make the observed cases useless, but it raises the bar for wording. The under-10-hour intrusion is a documented Unit 42 investigation. The 15-minute wording differs between the annual report and the launch post. Neither should be generalized into an industry-wide constant.2, 3, 1

Independent reporting by Reuters confirmed the September 22 service launch and its use of models from Anthropic and OpenAI. The speed claims themselves still trace back to Unit 42 research, so the evidence boundary remains the same.

Human judgment moves up the stack

Automation does not eliminate the need for security people. It changes which tasks cannot wait for them. Machines can scan, test and propose fixes continuously. Humans still decide which systems can be touched, which remediation is safe, when a finding becomes an incident and what business risk justifies disruption.

What to watch as cyber defense becomes more automated

  • Whether independent incident data confirms the same compression in attack timelines across more organizations.
  • How often automated defensive findings produce safe fixes rather than another queue for humans to review.
  • Which high-risk remediation actions remain gated by human approval.
  • Whether faster defense reduces successful intrusions or simply increases the volume of machine-generated findings.

The important shift is not a stopwatch that always reads 15 minutes. It is that both sides can now run more of the security loop continuously. Once attack discovery and defense discovery happen at machine speed, the competitive advantage moves toward whoever can validate and act safely without waiting for the next scheduled review.

Sources and methodology

Sources checked September 23, 2026. Dates and periods for individual figures are stated beside them.

  1. Unit 42: Introducing Continuous Frontier AI DefenseAccessed 2026-09-23
  2. Unit 42: An AI-Assisted Cyber AttackAccessed 2026-09-23
  3. Unit 42: 2026 Global Incident Response ReportAccessed 2026-09-23
Scope and assumptions

The attack-speed evidence comes from Unit 42/Palo Alto Networks, which has a commercial interest in selling the defense service discussed.

The broader 2026 report says attackers begin scanning within 15 minutes, while the September launch post uses stronger 'weaponizing' language; the article keeps those claims separate.

One under-10-hour intrusion does not establish a universal timeline for AI-assisted attacks or prove that every organization needs the same defensive architecture.

Continue reading

Meta’s AI Can Send Emails and Make Purchases. What Should You Let It Touch?

86% Agreement Can Still Miss Half the AI Failures

1 in 3 GitHub Pull Requests Now Involves an Agent