Seemant Sehgal is Founder & CEO of BreachLock Inc., a leader in Continuous Attack Surface Discovery & Penetration Testing as a Service.
I’ve spent more than two decades on the offensive side of security, first as part of the CISO’s office at one of Europe’s largest banks and, for the past eight years, building offensive security products. In that time, I’ve watched the skill required to run a meaningful attack campaign drop steadily with each new wave of tooling—from exploit kits to phishing-as-a-service platforms to ransomware affiliate programs that turned cybercrime into a franchise model. But what’s happening right now feels qualitatively different from anything that came before.
In August 2025, Anthropic documented a cybercriminal who used an AI coding agent to breach at least 17 organizations, with the model handling everything from reconnaissance to setting ransom prices based on the stolen financial data. Around the same time, a group called FulcrumSec was using AI not to break into systems but to analyze what they’d stolen so they could negotiate from a position of knowledge.
The industry has collectively started referring to this as “vibe hacking,” and the cases have been multiplying. Complex attacks that formerly required years of specialized experience and carefully honed skills, like chaining vulnerabilities into an exploit leading to lateral movement, exfiltration and extortion, are now being executed by operators whose only real capability is knowing what to ask for.
The complexity of the attacks has stayed relatively stable, but the expertise required to launch one has dwindled.
What Makes Vibe Hacking Different From Previous Waves Of Automation
Security has absorbed automation before, but previous generations of attack tooling were essentially static templates that still required a high level of skill and working knowledge to use effectively. What sets vibe hacking apart is adaptability.
An AI model is capable of rewriting a phishing lure when the first attempt gets flagged, adjusting an extortion negotiation based on how the victim responds and generating enough payload variation that blocklists and signature matching, tools the industry has relied on for years, struggle to keep pace.
The silver lining in this is that vibe hacking hasn’t introduced a new category of vulnerability. The bad news is that it’s handed attackers your organization’s existing gaps at much greater speed. The controls that would have stopped these campaigns a year ago are most likely still doing their job, but the speed at which an attacker can find the one gap nobody closed and exploit it has gone from days to minutes.
What This Means For CISOs Building A Defense Plan
That shift in speed has practical implications for how security programs need to operate, and most of them come down to one thing: The cadence at which you test, validate and respond was designed to stay ahead of a slower, less equipped adversary.
Continuously prove what’s exploitable and how.
If an AI-assisted attacker can probe an environment and chain together an attack path faster than your team can complete an annual pentest, that pentest no longer offers the control and visibility it used to. Most enterprise security programs already have more findings than they can remediate, and the bottleneck was never discovery. What matters now, arguably more than ever, is understanding which of those findings an attacker could exploit and what the attack path would look like, then validating that continuously rather than once or twice a year.
Rethink awareness training for AI-quality social engineering.
AI-generated phishing lures that were once much more easily detectable to the average human are now grammatically clean, contextually relevant and convincingly personalized enough to pass casual inspection. Training employees to spot poorly worded emails is no longer enough. The focus needs to shift toward verification habits like out-of-band confirmation for sensitive requests and developing healthy skepticism toward urgency regardless of how polished the message looks or a vishing call sounds.
Treat your own AI deployments as part of your attack surface.
As organizations roll out AI agents and assistants internally, they’re creating a new layer of attack surface that most security programs haven’t fully accounted for. Vibe hacking not only enables attackers to use AI against you, but it also increasingly involves manipulating the AI tools you’ve deployed through prompt injection, tool misuse or simply talking an agent into performing an action that sounds routine.
For reference, 100% of the AI applications that were tested in the “Penetration Testing Intelligence Report 2026“ “contained OWASP LLM Top 10 vulnerabilities, led by prompt injection.” Any AI system with access to internal resources requires the same or stricter level of governance and least-privilege discipline you’d apply to a human employee with equivalent access.
Rebuild incident response for concurrent pressure.
More threat actors having access to AI-assisted tooling means that facing multiple simultaneous intrusions from different threat actors in the same week isn’t so far-fetched, especially for large enterprises with high-value data. Most incident response plans are still written around the assumption of a single, contained incident, and that assumption is worth revisiting.
Reframing The Risks Associated With Vibe Hacking To The Board
When presenting this to the board, the framing that tends to resonate is practical, not alarmist.
Most programs already have scanners identifying more findings than they can act on, and adding to that list doesn’t make anyone more secure. What makes the most impactful difference in this environment, especially in the wake of vibe hacking, is proving which of those findings are actually exploitable; mapping the attack paths that connect them to real outcomes like lateral movement, privilege escalation and data exfiltration; and focusing remediation in the most critical areas first.
Doing this continuously, whether it’s done manually with your internal red team or automated with an autonomous penetration testing tool, is one of the most practical ways to cut through noise and make measurable progress against the gaps that matter, even as the speed and volume of attacks increase.
That’s a practical, fundable commitment any board can get behind.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

