What happens when a potential attacker can bring an AI assistant to the attack?

Cybersecurity is no longer only a concern for large enterprises. Any organization operating on the public internet is exposed to a steady stream of scanning, probing, crawling and exploitation attempts.

At CreationUnited, we operate production infrastructure across multiple locations around the world, along with additional environments for testing and development. Over the past few years, we have seen the volume and variety of malicious activity around our infrastructure change significantly.

What stands out today is not one particular type of attack. It is the persistence of the activity, the range of techniques being used, and the growing level of automation behind it.

AI is becoming part of that picture. It is giving attackers another tool to research, automate, generate code and move faster. It is also making some capabilities more accessible to people who previously would not have had the knowledge or time to attempt them.

That is changing the security environment for everyone.


What we're seeing on our servers

Our internet-facing infrastructure is constantly exposed to activity from across the internet. A large part of it never reaches the systems behind our network edge, while additional layers continue to detect and block malicious behavior.

We use a combination of open-source security tooling, crowdsourced threat intelligence, commercial security services and internally tuned rules and controls to protect our infrastructure.

That layered approach gives us visibility at different points in the traffic path and helps us respond to different types of activity.

The volume alone gives a sense of how active the environment has become.

For the week of August 31 to September 7, 2026, our security systems recorded 65.4k attacks prevented.

The most common attack behaviors during that period were:

Attack behavior Events
HTTP Scan 13.6k
HTTP Exploit 12.6k
HTTP Crawl 9.31k
Weekly malicious activity detected and prevented across monitored production infrastructure.

This activity is not limited to large or highly targeted attacks. A significant amount of it consists of automated scanning, crawling and attempts to find common weaknesses.

That is important because even low-level activity creates pressure. Every request needs to be filtered, analyzed or rejected, and large volumes of unwanted traffic add to the operational work involved in keeping systems secure and available.


What the network edge sees

There is another view of the same environment at the network edge.

Across one of our primary domains, Cloudflare handled approximately 674.08k requests over the previous 30 days.

During that period:

  • 8.36k requests were cached
  • 665.72k were uncached
  • 11,471 malicious requests were blocked or challenged

That means thousands of malicious requests were stopped before they could reach the application.

Cloudflare request activity for one of our primary domains over the previous 30 days.

These numbers are a snapshot of a much larger environment, but they show something that is easy to overlook. Security work is happening continuously in the background while legitimate traffic continues to flow.

For users, the result is often simple: the service keeps working.


The attack landscape is getting busier

Looking back at older aggregated data, we have seen periods where current activity was up to roughly 40% higher per week than the historical levels available to us.

The exact pattern varies from week to week. What has remained consistent is that malicious activity has become part of the normal operating environment rather than something that appears only during a major incident.

We are seeing scans, crawls, exploit attempts and other automated activity as an ongoing part of running public-facing infrastructure.

The challenge is not just stopping a single attack. It is dealing with the volume of activity around it.


AI is changing the equation

AI did not create cyberattacks. Attackers have been using automation, scripts, botnets and publicly available security research for years.

What AI changes is how quickly some of this can be done and who can do it.

A skilled attacker can use AI to speed up research, generate or adapt scripts, analyze results and automate repetitive work.

Someone with much less experience can use the same tools to understand technical concepts, troubleshoot code, modify requests or build simple attack workflows.

That does not make every novice a sophisticated attacker. It does make experimentation easier.

Recent industry research points in the same direction.

Microsoft's Digital Defense Report 2025 highlighted the increasing use of AI to improve phishing operations and showed how automation can dramatically increase the scale and effectiveness of campaigns.

Google Threat Intelligence has reported a shift toward more operational use of generative AI by threat actors, including activity around vulnerability research, exploit generation and initial access.

IBM's 2026 X-Force Threat Intelligence Index reported a 44% year-over-year increase in attacks beginning through exploitation of public-facing applications, with AI-enabled vulnerability discovery identified as part of the acceleration.

CrowdStrike has also reported attackers using generative AI to scale operations and speed up attacks.

Taken together, the trend is clear: AI is becoming another capability in the attacker's toolkit.


When attacks come from ordinary-looking infrastructure

One observation that has stood out to us is the presence of malicious activity from residential or household IP addresses.

A residential IP does not automatically indicate malicious activity. But seeing this type of infrastructure involved in hostile traffic is a useful reminder that attack infrastructure does not always look like a traditional server or obvious botnet.

The barrier to running basic reconnaissance and attack automation continues to fall.

Someone sitting at home with a normal internet connection can access the same broad ecosystem of scanners, scripts, open-source tools and AI assistance that is available to more experienced operators.

Many of the attempts we see are still targeting relatively low-level weaknesses.

But low-level attacks at high volume still create work for defenders.

This is one of the less visible effects of the changing threat landscape. A large number of small attempts can add up to a meaningful operational burden even when none of them becomes a major incident.


AI is also becoming a defensive tool

The other side of this is equally important.

Defenders are using AI and automation too. Security teams can use these systems to process large amounts of telemetry, identify unusual activity, correlate information and speed up incident response.

The result is an ongoing race.

Attackers are getting better at automation. Defenders are doing the same.

For organizations, the practical goal is not to eliminate every hostile request. It is to reduce exposure, detect problems quickly, prevent attacks from becoming incidents and recover when something does get through.


This affects everyone

This is not just a story about CreationUnited.

Websites, APIs, SaaS platforms, e-commerce systems, remote access services and development environments all operate in the same broader environment.

Most organizations will never experience the kind of headline-making attack that makes the news. They will, however, experience the background pressure of automated scanning, credential attacks, exploitation attempts and malicious traffic.

That is why security is increasingly tied to availability and reliability.

A secure service should continue operating under pressure. It should be monitored. It should have layers of defense. And there should be a clear process for responding when something goes wrong.


Security is a continuous job

There is no point at which an internet-facing system is simply "secure" and the work is finished.

Threats change. Software changes. New vulnerabilities appear. Attackers change their methods.

Our approach at CreationUnited is built around continuous protection rather than a one-time security step.

We combine different sources of threat intelligence and multiple defensive controls, tune them to the environments we operate, and keep adjusting them as the threat landscape changes.

The objective is straightforward: protect the systems, reduce unnecessary exposure, detect suspicious activity and keep services running.

That work continues whether customers see it or not.


Security also means knowing what's happening

Keeping systems available is only part of resilience. Customers also need visibility when something changes.

That is why we maintain a public service status page at status.creationunited.co.

It gives customers a central place to check service health and see operational updates when there is an issue.

For us, transparency is part of the service itself. When something does happen, clear communication matters just as much as the technical work happening behind the scenes.


The threat landscape will keep changing

The internet has always been a hostile environment.

What is changing is the speed and accessibility of the tools available to people operating within it.

AI is adding another layer to that environment. It is helping experienced attackers move faster, and it is making some technical workflows more accessible to people with less experience.

At the same time, defenders are improving their own use of automation and intelligence.

For companies operating online, the answer is not to assume attacks can be eliminated.

It is to build systems that are harder to compromise, easier to monitor, faster to respond to and resilient when something gets through.

That is the approach we take at CreationUnited.

A lot of the security work happens quietly in the background. Users may never see the request that was blocked, the scan that was rejected or the suspicious behavior that was stopped.

They simply see the service working.

And that is exactly what good security should make possible.


Sources and further reading

Microsoft — Digital Defense Report 2025
https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025

Google Threat Intelligence — AI and vulnerability exploitation
https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/

IBM — 2026 X-Force Threat Intelligence Index
https://www.ibm.com/think/x-force/threat-intelligence-index-2026-securing-identities-ai-detection-risk-management

CrowdStrike — 2025 Threat Hunting Report
https://www.crowdstrike.com/en-us/blog/crowdstrike-2025-threat-hunting-report-ai-weapon-target/

ENISA — Threat Landscape 2025
https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025