AI-powered script kiddies, once dismissed as a low-stakes nuisance, are now capable of mounting attacks that rival those of nation-state threat actors, according to Palo Alto Networks’ Unit 42 research team. The warning came during a briefing on early findings from the firm’s Frontier AI Defense service, launched in April 2026.
Sherrod DeGrippo, VP of Threat Intelligence at Unit 42, told the briefing that the traditional categories of cyberattack have shifted. Socially motivated groups are now being ‘enabled with the same tooling and sophistication as a state-sponsored group’ due to artificial intelligence. DeGrippo joined Palo Alto Networks to lead threat intelligence for Unit 42 in July 2026, bringing more than two decades of experience in threat intelligence.
‘This part of the landscape will continue to increase and bring in low-skilled actors that now have exponentially bigger and better capabilities than we’ve seen before,’ DeGrippo said. ‘These are people who know how to use a tool, and we’ve given them incredible tools.’
When AI Breaks the Balance Between Attack and Defence
Sam Rubin, SVP of Consulting and Threat Intelligence at Unit 42, described the situation in stark terms. There has historically been ‘a relative balance between the security and compromise of our information,’ he said, but ‘AI is breaking that balance.’
Unit 42 calls AI a ‘force multiplier’ across the entire attack chain, not just isolated stages. In its own internal tests over three weeks, the team completed the equivalent of one to two years of penetration testing, uncovering dozens of vulnerabilities across customer environments using AI pen-testing models.
Speed is a core part of the shift. Unit 42 found that AI could identify and exploit vulnerabilities, escalate privileges, and steal data all within 10 hours, a task that would normally occupy a penetration testing team for around two weeks.
The broader picture is quantified in Unit 42’s 2026 Global Incident Response Report, published February 17, 2026, based on analysis of more than 750 high-stakes incidents. The report found that AI has accelerated attack speeds by 4x over the past year. Identity-based techniques such as social engineering and credential misuse now drive 65% of initial access events, while vulnerabilities account for 22%. Separately, the report found that 90% of data breaches are linked to misconfigurations or security gaps, and that 48% of attacks involve the browser.
A real incident response case illustrates the ceiling of what AI-directed attackers can now achieve. In one case documented by Unit 42’s investigation team, a human attacker directed AI agents that used more than 50 MITRE ATT&CK techniques during a ransom attack on an enterprise network. The agent left behind an 80-page technical audit detailing dozens of exploited findings on the organisation’s security posture.
AI-Powered Script Kiddies and the Hacktivist Resurgence
The implications extend beyond organised criminal groups. Asked whether old-school hacktivism, similar to what groups like Anonymous practised, could make an AI-fuelled return, DeGrippo said it is ‘absolutely possible,’ as ‘AI is enabling individuals in ways that they have never been enabled before.’
She pointed to a newly accessible class of threat actor: people with personal grievances against former employers or businesses, who now have sufficient tooling to act on those grievances. ‘[AI] is opening up the landscape to the groups that haven’t been that much of a concern,’ DeGrippo said. ‘Individuals who have a vendetta against previous employers, a business they did business with and didn’t get what they were promised, now have the capabilities where they are well-enabled with tooling to carry out malicious activity if they want to. It’s something to watch in the landscape, and it’s probable.’
Attribution, she added, will also become harder. AI and open access to associated tools make identifying who is behind an attack, and where they operated from, increasingly difficult for defenders.
The threat of fully autonomous attacks is already concrete. JadePuffer, first documented by Sysdig’s threat research team on 1 July 2026, is believed to be the first fully agentic ransomware campaign. The operator gained initial access through CVE-2025-3248 in an internet-facing Langflow instance, then ran a destructive database-extortion playbook that autonomously retried failed steps to increase its own success rate. Security firm Expel noted that JadePuffer had significant operational gaps, including no stored decryption keys and no bitcoin address for payment, suggesting the operator was unskilled despite the AI-driven execution, an early illustration of exactly the gap DeGrippo describes.
What Organisations Can Do
Unit 42 has moved to industrialise its own AI-driven defences in response. On 22 September 2026, Palo Alto Networks announced Unit 42 Continuous Frontier AI Defense, an always-on agentic offensive security subscription powered by Anthropic’s Claude Mythos and OpenAI’s GPT-5.6-Cyber models, designed to continuously find, validate, and remediate enterprise exposures. The firm also introduced the Frontier AI Critical Defense Program on 19 August 2026, a coordinated initiative for critical infrastructure across operational technology, healthcare, commercial software, and open-source communities to deploy proactive virtual patches before attackers can exploit vulnerabilities.
DeGrippo is frank about the limits of preparation. ‘None of us are prepared for what is constantly evolving,’ she said. ‘CISOs need to think about what their agentic AI strategy is, top to bottom. They have to develop a strategy and then be willing to adapt. Organisations aren’t ready but are doing what they can to get there.’
Unit 42 recommends zero-trust architecture, stronger employee training beyond annual phishing exercises, governance of unsanctioned ‘shadow AI’ use inside organisations, and partnerships with specialist cybersecurity providers. The immediate test for any security team is whether their defences are calibrated for an attacker who never sleeps, never tires, and autonomously retries every step it fails.
