- | 2:00 pm
AI is reshaping cybersecurity as attackers become faster, smarter, says Kaspersky
Sergey Lozhkin explores how AI is fueling emerging cyber threats, from AI-generated malware to automated phishing and faster attacks.
The cybersecurity landscape across the MENA region is continuing to evolve with the rapid adoption of technologies such as artificial intelligence. While organizations are increasingly using AI to improve efficiency and strengthen their cyber defenses, threat actors are also leveraging the technology to develop more sophisticated malware, automate phishing campaigns and accelerate cyberattacks.
Speaking at Cyber Security Weekend for the Middle East, Kaspersky’s Global Research & Analysis Team (GReAT) highlighted how AI is reshaping the threat landscape.
“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” said Sergey Lozhkin, Head of Global Research and Analysis Team for the APAC and META regions at Kaspersky.
Kaspersky also unveiled its key cyber threat trends for the first half of 2026, reporting that its systems blocked 75.8 million web-based attacks across the Middle East during the period.
The company identified a growing range of emerging threats, including AI-generated malware, cloud-based data exfiltration, ransomware targeting business operations and the abuse of AI agents, underscoring the need for organizations to strengthen cyber resilience as AI-driven attacks continue to evolve.
AI THREATS
Lozhkin believes one of the most significant shifts in today’s threat landscape is the growing use of AI throughout the cyberattack lifecycle.
“We are seeing threat actors use large language models to generate phishing emails and accelerate the creation of malicious content. AI makes cyberattacks cheaper and faster to put together, allowing adversaries to move faster and scale their operations,” he says.
Beyond AI, he notes that attackers are increasingly using legitimate cloud services to exfiltrate stolen data, ransomware groups are focusing on disrupting business operations rather than simply encrypting files, and AI agents are emerging as a new target for cybercriminals.
Lozhkin explains that the autonomous nature of AI agents introduces entirely new security risks. “Traditional AI tools generate or summarise content, whereas AI agents can plan, call APIs, interact with enterprise systems and execute actions autonomously. Once they gain access to business applications, data, and workflows, they effectively become part of an organization’s attack surface.”
He says this creates a new range of security challenges, as attackers can exploit AI agents through prompt injection, context manipulation, compromised models or plugins, abuse of authorized tools, or vulnerabilities in the agent’s runtime to perform unauthorized actions or exfiltrate sensitive data.
“Modern AI agents also rely heavily on external frameworks, plugins, APIs and cloud services, meaning that they create a new software supply chain that organizations must secure.”
AFFECTED SECTORS
Lozhkin says that critical infrastructure, financial institutions, and government organizations remain among the most attractive targets for both cybercriminals and advanced threat actors, although their motivations differ.
Financial institutions are primarily targeted for financial gain through credential theft, banking malware, and ransomware, while government organizations continue to face espionage campaigns to access sensitive information. Attacks on critical infrastructure pose an even greater risk because they can disrupt essential services and operations that businesses and communities rely on.
“We’re also seeing attackers become more patient and sophisticated, combining social engineering with legitimate administrative tools and carefully planned intrusions that are much harder to detect than traditional malware-based attacks.”
SECURING AI AGENTS
As organizations increasingly deploy AI agents in critical business processes, Lozhkin says they should be treated as privileged enterprise systems rather than conventional software.
“Security should begin with limiting what an agent is allowed to access, ensuring it only has the permissions required for its specific role.”
He adds that organizations also need continuous visibility into AI agent activity by monitoring behavior, validating the integrity of the models, plugins, and external dependencies they rely on, and maintaining strong governance over every action they take. As AI agents become more integrated with third-party tools and cloud services, securing the AI supply chain is becoming as important as securing the models themselves.
“Finally, human oversight remains important, particularly for high-impact business decisions where autonomous actions should be verified before execution.”
THE FUTURE OF CYBERSECURITY
Looking ahead, Lozhkin says emerging AI technologies will have the greatest influence on cybersecurity over the next two years, creating both new opportunities for defenders and new capabilities for attackers.
“New AI developments, particularly as generative AI and agentic AI become more widely adopted, will undoubtedly have the biggest influence,” he says.
He explains that AI enables security teams to process vast amounts of data, detect anomalies more quickly and automate routine tasks, allowing analysts to focus on more complex investigations. At the same time, cybercriminals are using the same technologies to make phishing campaigns more convincing and scalable, while autonomous AI systems could help automate parts of the attack lifecycle.
Looking further ahead, Lozhkin believes the shift from AI assistants to autonomous AI agents integrated across enterprise environments will have the most profound impact on organizations in the META region.
“With organizations integrating these agents into everyday business operations, the enterprise perimeter will continue to expand beyond traditional networks to include cloud services, AI platforms, third-party plugins, APIs and external data exchanges.”
He says attackers will continue using AI to lower the cost and complexity of cybercrime, from scaling phishing campaigns and malware development to automating reconnaissance and social engineering. While these technologies improve efficiency for defenders, they also allow attackers to operate faster and at greater scale.
“Over the next five years, organizations that succeed will be those that recognize AI’s potential as a part of their cybersecurity strategy.”






















