- The Verizon 2026 DBIR found that third-party supply chain breaches surged 60%, with nearly half of all analyzed breaches now traced back to a vendor or partner organization.
- For the first time across the report's 19-year run, the Verizon 2026 DBIR found that exploiting known software vulnerabilities — at 31% of breaches — beat out stolen credentials as the top attacker entry point.
- The National Academies says AI could eventually strengthen defenders' hands, but only if sustained investment and coordination follow — and that favorable shift has not happened yet, the report cautions.
What Folks Are Chattering About
Well, butter my biscuit, there's a whole barnyard of noise right now about whether AI is gonna be the cavalry that saves cybersecurity defenders or the fox that's already halfway through the henhouse. A Kiteworks executive appearing on Manufacturing Business Technology's 'Security Breach' podcast argued — and this is that vendor's own position, not a settled fact — that AI tools could 'even the playing field' for white-hat defenders who are scrambling to keep up with attackers who, the executive claimed, are exploiting new technology faster than anyone on the good-guy side. Manufacturing Business Technology is a trade outlet, and that particular view comes from a vendor-affiliated source without independent corroboration, so take it with a salt lick's worth of skepticism.
What's got more traction than a mud-bogged four-wheel drive is the broader conversation those comments plugged into: a genuinely serious, multi-source debate about whether AI has handed offense such a fat head start that defense may never catch up — or whether the gap can be closed with enough money, coordination, and political will. That question is now drawing responses from the National Academies of Sciences, Engineering, and Medicine, the Center for Strategic and International Studies, and Verizon's annual breach report, which collectively paint a picture that is a good deal more complicated than any single vendor's podcast appearance.
What We Actually Know: The Breach Numbers Are Ugly
Lord have mercy, the Verizon 2026 Data Breach Investigations Report — drawing on roughly 31,000 incidents across 145 countries — is about as close to ground truth as this industry gets, and it does not read like a feel-good story. According to the DBIR, third-party supply chain breaches climbed 60%, with nearly half of every breach analyzed — 48%, to be precise — now involving some kind of outside vendor or partner organization. That's like finding out half your barn fires started in your neighbor's haystack.
Also confirmed by the Verizon 2026 DBIR: for the first time across the report's entire 19-year history, attackers' most common way into a target network is now exploiting known software vulnerabilities, accounting for 31% of breaches and nudging stolen credentials out of the top spot. Separately, the same report found — in partnership with Anthropic — that in a typical scenario, threat actors were leaning on AI assistance to work through 15 distinct attack techniques catalogued in the MITRE ATT&CK framework, and in more extreme cases were querying AI across 40 to 50 such techniques, essentially using the technology as a co-developer across the whole attack chain.
On top of external threats, the Verizon 2026 DBIR flagged that employee use of unapproved AI tools — so-called shadow AI — tripled to 45% of organizations, cranking up the risk of sensitive data leaking from the inside. That's a whole different kind of trouble, like leaving the smokehouse door open while worrying about wolves.
What the Experts Are Cautiously Saying
The National Academies of Sciences, Engineering, and Medicine published a rapid expert consultation in June 2026 concluding that AI is accelerating what both attackers and defenders can do — but that right now, in the near term, the advantage leans toward attackers because AI cuts down the time, skill, and effort needed to mount sophisticated attacks. The report does allow that, with genuine investment and cross-sector coordination, AI could eventually help defenders build a stronger cybersecurity posture. But — and this is the part worth nailing to the shed door — the National Academies stops well short of saying that shift has arrived.
The Center for Strategic and International Studies landed in a similar place, noting in a July 2026 analysis that a June 2026 White House executive order directed the NSA, NIST, and CISA to stand up a classified process for benchmarking the advanced cyber capabilities of frontier AI models. CSIS frames that order as a sign the federal government is waking up to how much AI now shapes the offense-defense balance — though CSIS also notes a policy tension between calls for stronger regulation and the current administration's preference for accelerating AI innovation over new regulatory guardrails.
What Remains Murkier Than a Creek After a Rainstorm
Here's where the wagon gets stuck in the mud: the question of whether AI can actually flip the advantage to defenders over the long haul is, by the honest accounting of the most credible sources, genuinely unresolved. The National Academies and CSIS agree it is possible with the right conditions, but neither outfit is willing to call it a done deal or put a date on it. The International AI Safety Report 2025, for its part, explicitly flags the long-term offense-defense AI balance as currently unclear — which is a polite way of saying nobody really knows.
There's also a disagreement about the role of regulation. Some security practitioners and analysts argue that tighter rules are the single most important lever for changing the balance, while the current administration's cyber strategy and AI action plan lean toward innovation acceleration rather than detailed guardrails, a tension CSIS calls out directly. Meanwhile, vendor-affiliated sources like the Kiteworks executive on the MBT podcast argue defenders can already use AI to equalize the fight — a more optimistic position that flatters their own product line and has not been independently verified, so it deserves a raised eyebrow and a polite 'is that right?'
Our Analysis: A Long Road With No Shortcut in Sight
Analysis, not reporting: the pattern across the credible, independent sources here suggests the cybersecurity community is stuck in a situation that resembles trying to patch a tin roof during a thunderstorm — the rain keeps coming faster than you can cover the holes. Attackers benefit from AI's ability to lower entry barriers, meaning less-skilled actors can now punch above their weight class, and even sophisticated outfits get a productivity boost that compounds over time. The 60% jump in supply chain breaches reported by Verizon is a particularly telling sign that the attack surface is sprawling well beyond what any single organization controls.
The more hopeful reading — and this is analytical inference, not a claim from the sources — is that the same economics that favor attackers today could eventually favor defenders if the defensive side scales investment faster and smarter. That is the conditional bet the National Academies and CSIS are making, and it is a reasonable one. But 'reasonable' and 'inevitable' are two very different critters, and right now the scoreboard doesn't suggest the defenders are pulling ahead. Anyone who tells you otherwise with full confidence is probably selling something — possibly on a podcast.
Who is doing the hollering
These links show where the chatter came from. A link is attribution, not our endorsement or independent confirmation.
- AI Will Elevate Near-Term Cybersecurity Risks but — with Investment and Coordination — Can Strengthen Cybersecurity in the Long RunNational Academies of Sciences, Engineering, and Medicine · primary
- Implications of AI for Cybersecurity: A Rapid Expert Consultation (Interactive)National Academies Press · primary
- 2026 Data Breach Investigations Report (DBIR) — Breach Entry Point FindingsVerizon · primary
- Lessons for organizations from the Verizon 2026 Data Breach Investigations ReportHelp Net Security · top tier
- Top Takeaways from the 2026 Verizon Data Breach Investigations ReportSpyCloud · specialist
- 2026 Verizon Data Breach Investigations Report: What Executive Leaders Need to KnowMintz · specialist
- Making AI Work for Cyber Defenders: A Strategy for Strengthening U.S. CybersecurityCenter for Strategic and International Studies (CSIS) · top tier
- Security Breach: The Bad Guy's Different Set of RulesManufacturing Business Technology · specialist
- Verizon's 2026 Breach Report: Vendors and Shadow AI Are the Weak LinksState of Surveillance · specialist
Last checked Aug 13, 2026, 9:08 AM EDT. Talk Around Town: The long-term offense-defense balance remains genuinely contested: the National Academies report and CSIS analysis agree AI *could* favor defenders with sustained investment, but neither concludes this shift has occurred yet. Quantitative statistics from vendor-sponsored surveys (e.g., analyst workload reduction figures) lack independent replication and should be treated with caution.