Every vendor pitch deck in 2026 leads with AI. AI-powered detection. AI-driven response. AI-augmented SOC. But on the other side of the wire, attackers are running the same playbook — and they don't need board approval to deploy.
Von Neil Beulecke, Geschäftsführer — Layer7 Networking
What's Actually Changed
Drei Veränderungen in der Bedrohungslandschaft sind tatsächlich auf KI zurückzuführen, und Sicherheitsteams müssen sie klar verstehen.
Phishing at scale with personalisation. Large language models have eliminated the grammar-check heuristic that caught 80% of phishing emails for two decades. Attackers now generate context-aware, grammatically perfect lures in any language, customised per target using scraped LinkedIn data. We're seeing campaigns where every recipient gets a unique email — no two payloads share the same hash, no two subject lines match. Traditional signature-based email gateways miss these entirely.
Deepfake social engineering. Voice cloning requires roughly three seconds of sample audio. In Q1 2026, a Johannesburg-based financial services firm lost R4.2 million after an attacker cloned the CFO's voice and authorised a wire transfer via Teams call. This isn't theoretical — it's happening to South African organisations right now. The countermeasure isn't better voice analysis; it's out-of-band verification procedures that assume any single channel can be compromised.
Polymorphic malware and evasion. AI-assisted code mutation generates functionally identical malware variants faster than sandboxes can analyse them. The concept isn't new — polymorphic engines have existed since the 1990s — but the speed and sophistication have increased by an order of magnitude. Static analysis alone is no longer sufficient.
What Hasn't Changed
Here's the uncomfortable truth that doesn't make it into the keynote presentations: the majority of successful breaches in 2025 and early 2026 still exploited the same attack vectors we've been talking about for a decade.
- Ungepatchte Schwachstellen — Fortinet, Ivanti und Palo Alto hatten alle kritische CVEs, die innerhalb von Tagen nach der Offenlegung in freier Wildbahn ausgenutzt wurden. Patch-Management bleibt die einzelne Sicherheitsmaßnahme mit dem höchsten ROI.
- Stolen credentials — Infostealer malware harvesting session tokens and passwords from endpoints continues to be the primary initial access vector. MFA helps, but only if it's phishing-resistant MFA (FIDO2/WebAuthn), not SMS or TOTP.
- Fehlkonfigurierte Cloud-Dienste — S3-Buckets, zu freizügige IAM-Rollen, exponierte Management-Schnittstellen. Das Cloud-Shared-Responsibility-Modell wird von den meisten Organisationen immer noch schlecht verstanden.
- Lack of network segmentation — Once inside, attackers move laterally with minimal resistance because internal networks remain flat. This hasn't changed in twenty years.
Das wahre Risiko: AI Washing
Die gefährlichste KI-bezogene Bedrohung im Jahr 2026 ist kein KI-gestützter Angriff — es ist AI Washing. Organisationen werden „KI-gestützte" Sicherheitsprodukte verkauft, die umbenannte Machine-Learning-Modelle von 2019 sind, während grundlegende Kontrollen vernachlässigt werden. Wenn Ihre Firewall-Regeln seit 18 Monaten nicht überprüft wurden, Sie aber gerade eine KI-Bedrohungserkennungsplattform gekauft haben, haben Sie Ihre Prioritäten verkehrt.
Praktische Empfehlungen
Für CISOs und Sicherheitsmanager im Jahr 2026:
- Get the basics right first. Patch within 72 hours for critical CVEs. Deploy phishing-resistant MFA. Review firewall rules quarterly. These aren't exciting, but they prevent 80% of breaches.
- Update your phishing simulations. Your training programme needs to account for AI-generated lures. If your test emails still contain obvious grammar mistakes, you're training your staff for threats that no longer exist.
- Implementieren Sie Out-of-Band-Verifizierung für jede Finanztransaktion oder privilegierte Aktion. Gehen Sie davon aus, dass jeder einzelne Kommunikationskanal — E-Mail, Telefon, Teams — gefälscht werden kann.
- Fordern Sie Belege von Anbietern. Wenn ein Anbieter „KI-gestützt" behauptet, fragen Sie: Welches Modell? Welche Trainingsdaten? Wie hoch ist die Falsch-Positiv-Rate? Wie hoch ist die Erkennungsrate bei neuartigen Bedrohungen im Vergleich zu bekannten Signaturen? Wenn sie nicht antworten können, ist es Marketing.
- Investieren Sie in Detection Engineering, nicht nur in Prävention. Gehen Sie von einem Breach aus. Bauen Sie Erkennung für laterale Bewegung, Credential-Missbrauch und Datenexfiltration auf. Der Angreifer wird eindringen — Ihre Aufgabe ist es, ihn zu erwischen, bevor er die Kronjuwelen erreicht.
The AI threat landscape in 2026 is real, but it's not the paradigm shift that vendors are selling. It's an acceleration of existing trends layered on top of the same fundamental weaknesses we've always had. Organisations that master the basics and layer AI-aware defences on top will be well-positioned. Those chasing the latest AI security product while ignoring patch management will learn expensive lessons.
Layer7 Networking schützt südafrikanische Organisationen seit über 21 Jahren. Wir konzentrieren uns auf das, was funktioniert: Konfigurationsgovernance, Zero-Trust-Architektur und Managed Security Services, die messbare Risikoreduktion liefern.