#cybersecurity#ai#threat intelligence#machine learning#enterprise security

AI Cyber Threat Intelligence: What the 2026 IBM and Verizon Data Say to Prioritize

Exploited vulnerabilities are now the top breach entry point. How to use AI for alert triage, KEV and EPSS patch priority, and threat hunting.

📅 January 26, 2026✏️ Updated: September 27, 2026⏱ 7 min read✍ Web3 Listicle Editorial Team

Advanced digital shield protecting global enterprise networks from automated cyber attacks using neural network overlays.

Two annual reports set the baseline for enterprise security planning, and both 2026 editions point in the same direction.

IBM's Cost of a Data Breach Report 2026, published in July and based on 602 breached organizations, put the average global breach at $4.99 million, a record. The US average was about $11.5 million. After five years of improvement, the time to identify and contain a breach rose again to 247 days. One in four malicious breaches involved AI, most often deepfakes and impersonation.

Verizon's 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches, found that exploiting a vulnerability had become the most common way attackers got in, at 31% of breaches, overtaking stolen credentials. Organizations fully fixed only 26% of the vulnerabilities on CISA's Known Exploited Vulnerabilities list during the year, and the median time to fix them grew to 43 days. Third parties were involved in 48% of breaches.

Put those together and the priorities are fairly clear: patch what is actually being exploited, faster; watch third-party access; prepare for impersonation attacks; and use AI where it shortens detection and response. This guide covers each.

Where AI helps defenders

Alert triage and investigation

A security operations center can receive thousands of alerts a day, most of them benign. The most practical AI use today is helping analysts get through that queue: summarizing an alert with its surrounding context, pulling related events from other tools, mapping activity to MITRE ATT&CK techniques, and drafting the investigation notes. Most large security platforms now include an assistant of this kind.

IBM's 2025 edition of the same study found organizations using security AI and automation extensively had breach costs about $1.9 million lower and caught breaches 80 days faster. That is a correlation across companies, not proof that the tool alone caused the difference, but it matches what security teams report: the gain comes from getting through investigations faster.

Behavioral detection

Signature-based tools catch known malware and known bad addresses. Behavioral models catch unusual activity: a user logging in from a new country and downloading far more than usual, a service account suddenly querying the directory, a process spawning PowerShell with encoded commands. These models live in modern endpoint detection (EDR), identity threat detection, and cloud security tools. They need a few weeks of baseline data and tuning before their alerts are trustworthy.

Threat intelligence processing

Threat reports, vulnerability advisories, and vendor bulletins arrive in huge volumes of unstructured text. Language models are good at extracting the indicators, affected products, and ATT&CK techniques from them and turning them into structured formats such as STIX, or into draft detection rules for analysts to review.

Vulnerability prioritization: the highest-return fix

With exploitation now the top entry point, deciding what to patch first matters more than any other single process. CVSS severity scores rank thousands of issues as high or critical, far more than a team can fix quickly. Two free sources give a better signal:

  • CISA's KEV catalog lists vulnerabilities with confirmed exploitation in the wild. US federal agencies must fix them on set deadlines; everyone else should treat the list as a floor.
  • EPSS, maintained by FIRST, estimates the probability that a vulnerability will be exploited in the next 30 days, updated daily.

A worked illustration: a company has 2,000 open vulnerabilities, 600 of them rated high or critical by CVSS. Filtering tells a different story.

Filter Remaining What to do
All open findings 2,000
CVSS high or critical 600 Too many to treat as urgent
On the KEV list 25 Fix first, within days, starting with internet-facing systems
Not on KEV but EPSS above 10% 40 Fix next, within weeks
Remaining high/critical 535 Normal patch cycle, sorted by asset exposure

The numbers are illustrative, but the shape is typical. The urgent list shrinks from hundreds to dozens, and the team can actually finish it. Verizon's data showed edge devices and VPNs as a large share of exploited systems, so internet-facing assets go at the top of each tier.

AI helps here by matching vulnerabilities to your actual asset inventory, reading vendor advisories to see whether a given configuration is affected, and drafting change requests. The ranking logic itself should stay simple enough for people to check.

Security analysts collaborating around dashboards demonstrating real-time threat intelligence and vulnerability analysis.

Defending against AI-assisted attacks

Impersonation and deepfakes. IBM's 2026 data put deepfake and impersonation attacks at 45% of AI-involved malicious breaches. The best-known case is from early 2024, when an employee at engineering firm Arup's Hong Kong office paid out about US$25 million after a video call in which the "CFO" and colleagues were deepfakes. Technical deepfake detection helps, but process controls work better: payment and bank-detail changes verified through a separate, known channel; no exceptions for urgency; and a code word or callback procedure for executives.

Phishing at scale. AI removes the spelling mistakes and awkward phrasing people used to rely on. Phishing-resistant multi-factor authentication (FIDO2 security keys or passkeys) matters more than training people to spot bad grammar.

Faster exploitation. When exploits appear within days of disclosure, patch speed on internet-facing systems becomes the main control. That is why the KEV-first approach above matters.

Risks of AI in the security stack

Prompt injection. An AI assistant that reads phishing emails, log entries, tickets, or web pages is reading text an attacker can control. Instructions hidden in that content can try to make the assistant ignore an alert, mislabel a threat, or run an action. Give AI tools the least access they need, keep them read-only by default, and require human approval for containment actions such as disabling accounts or isolating hosts.

Shadow AI. Verizon's 2026 report found 45% of employees using AI tools regularly, with two-thirds of them doing so through personal accounts, and source code as the data most often pasted in. IBM found that 92% of organizations with an AI-related breach had no access controls on their AI systems. Approved enterprise tools with data protection terms, plus monitoring for uploads to unapproved ones, cut this risk.

Over-automation. Automated containment is fast, and so are its mistakes. Start with automation that gathers evidence and recommends, then allow automatic action only for narrow, well-tested cases like quarantining a known-malicious file.

Governance and disclosure

US public companies must file a Form 8-K under Item 1.05 within four business days of deciding an incident is material, under SEC rules in effect since December 2023. That puts a premium on fast, well-documented investigations, which is another place AI summarization helps, provided a person checks the facts.

Cyber insurers increasingly ask about MFA, EDR coverage, patch timelines, and backup testing when pricing policies. See our cybersecurity insurance guide for what underwriters check.

A practical sequence

  1. Get the logs in one place. Identity, endpoint, email, cloud, and network logs, normalized and retained long enough to investigate.
  2. Set up KEV and EPSS prioritization against a current asset inventory, with deadlines for each tier.
  3. Turn on behavioral detection in the EDR and identity tools you already own, and tune it for a few weeks before relying on it.
  4. Add an AI triage assistant in read-only mode and measure mean time to investigate before and after.
  5. Harden against impersonation with phishing-resistant MFA and out-of-band verification for payments.
  6. Write down what automation may do on its own, and review that list quarterly.

For the architecture that limits how far an intruder can move, see Zero Trust security. For cloud configuration risk, see CSPM. And for the policies that govern AI tools across the business, AI governance frameworks.


This guide is for informational purposes only and is not technical or legal advice. Threats and tools change quickly; work with qualified security professionals on your architecture.

Frequently Asked Questions

IBM's Cost of a Data Breach Report 2026, covering 602 organizations breached between March 2025 and February 2026, put the global average at $4.99 million, a record and 12% higher than the year before. The US average was about $11.5 million. The average time to identify and contain a breach rose to 247 days.
Mostly to do existing attacks faster and at larger scale. IBM found AI involved in one in four malicious breaches in its 2026 study, most often deepfake or impersonation attacks, followed by AI-enabled malware and AI-written phishing. Verizon's 2026 DBIR reached a similar conclusion: AI speeds up known techniques more than it creates new ones.
Start with anything on CISA's Known Exploited Vulnerabilities (KEV) catalog, since those are confirmed to be used in real attacks. Then use FIRST's Exploit Prediction Scoring System (EPSS), which estimates the probability of exploitation in the next 30 days, alongside how exposed and important the affected system is. CVSS severity alone ranks too many issues as critical to be useful.
Yes. An AI assistant that reads emails, tickets, logs, or web pages is reading content an attacker can write. Prompt injection hidden in that content can try to make the assistant hide an alert, mislabel a threat, or take an action. Give AI triage tools read-only access by default and require human approval for containment actions.
US public companies must file a Form 8-K under Item 1.05 within four business days of determining that a cybersecurity incident is material, under SEC rules in effect since December 2023. The clock starts at the materiality determination, which must be made without unreasonable delay after discovery.

Share this article