Does AI assist cybercriminals? Of course it does, from writing malware code to creating sophisticated and highly believable social engineering scenarios. But that, dear reader, is only part of the cybersecurity AI story, as the newly published “Inside the Mind of a Hacker” report from bug bounty platform Bugcrowd has confirmed with some gusto.
As OxMoose, a Bugcrowd hacker, said: โSecurity is a race where the finish line keeps moving forward, and the only way to stay ahead is to run faster than everyone else. By utilising AI, the pack not only gets โsmarterโ but also quicker, running on a relentless 24/7 schedule.โ
The report, based on research that took insights from 2,000 hackers worldwide, revealed that these essential security researchers, uncovering and disclosing vulnerabilities before cybercriminals get a chance to exploit them, have not only embraced AI, but are doing so in droves.
It confirmed what I have suspected for ages, nay, what I knew: the vast majority of hackers are now using AI in their workflows. This is hardly surprising as AI tools themselves continue to mature. Perhaps the only surprise is that one in five are still relying upon purely human skillsets. The Bugcrowd research found that the percentage of AI users has increased from 64% as reported in its 2023 report to 82% today.
โWhile the industry often frames the AI conversation as a choice between humans andย machines, weย have reached a point where those forces are converging,โ said Bugcrowdโs CEO, Dave Gerry.
Gerry called this a โnew era of human-augmented intelligence,โ which might be a little over the top, but not much.
Reaction to the Bugcrowd hacker report
This evolution does, of course, spread out of the bug bounty hacking bubble and into the enterprise.
โWeโre seeing AI rapidly evolve from simple automation to deeply personalised, context-aware assistance,โ Randolph Barr, Chief Information Security Officer at Cequence Security, told me, โand itโs heading toward an agentic AI future where tasks are orchestrated across domains with minimal human input.โ
As Ram Varadarajan, CEO at Acalvio, said: โIn 2026, security teams can no longer rely on humans doing everything by hand.ย The model has to change to allow humans to direct AI-driven workflows, just as hackers do.ย It’s fated to be a bot-on-bot duel forevermore.โ
While thereโs an argument to suggest that this is a race to the bottom, pitting AI against AI and may the best prompt take the glory, I prefer the OxMoose version. This is a race to the finish. By choosing the right hybrid workflows, with AI providing the scale and speed while humans add hard-earned judgement and oversight, itโs a race that cybersecurity can, and must, win.
Related articles