ai-cybersecuritytrade-pressNewsThe Broadside2 min read

FBI tells defenders AI hasn't changed the kill chain

The same controls that stopped yesterday's intrusions will stop tomorrow's, but only if patching shifts from quarterly to continuous.


TL;DR

FBI deputy assistant director Jason Bilnoski said Tuesday that AI is accelerating attacker speed and capability but isn't altering the fundamental nature of intrusions. "What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday," he told CyberScoop and the Billington CyberSecurity Summit, pointing to the Bureau's 10-item cyber-hygiene basics list. Colleen Ferranti, assistant section chief for cyber engagement, added that quarterly patching is no longer viable given AI's vulnerability-discovery pace, pushing organizations toward continuous, risk-based patching. The remarks came ahead of an FBI cyber strategy release Wednesday.

The FBI's message this week is an uncomfortable one for an industry that sells AI-powered threat detection: the attackers are using AI, but the fix hasn't changed.

Jason Bilnoski, deputy assistant director of the FBI's cyber division, laid out the paradox plainly. AI is "taking actors to the next level," he said, producing "an exponential increase in the use of AI, whether it's nation-state or criminal." The Bureau is adding a new section to its annual digital-crimes report to quantify the impact. And yet: "The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following."

Bilnoski pointed to the FBI's 10-item fundamentals list, multifactor authentication chief among them. "If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment." The FBI sees this pattern in its own investigations, including cases with an AI element. The post-mortems don't find a novel AI-enabled kill chain. They find missing MFA and unpatched edge devices.

That's the defensive posture. The operational tempo is where AI does force a change.

"The speed at which AI models are uncovering vulnerabilities means organizations need to rethink their approach to patching," said Colleen Ferranti, assistant section chief of the FBI's cyber engagement and intelligence section. "We no longer can essentially do the quarterly patching." Her prescription: continuous, risk-based patching, "patch-all-of-the-time."

This aligns with the framework CISA published in BOD 26-04 on June 10, 2026, which prioritizes vulnerabilities by four criteria: public exposure, fully automatable exploitation, whether exploitation grants system control, and evidence of real-world exploitation. Vulnerabilities hitting all four get a three-day remediation deadline. The logic is the same: AI compresses the window from discovery to weaponization, so the patching cadence has to compress with it.

The new FBI cyber strategy, released Wednesday, commits the Bureau to deploying AI for its own operations, triaging large datasets, accelerating malware analysis, mapping adversary infrastructure. It also commits to expanding the Computer Network Operations program for court-authorized remote collection and disruption. The public-facing value, though, is in the alignment between the FBI's operational message and CISA's risk-based patching framework. Two agencies telling defenders the same thing (basics still matter, but speed matters more) is worth noting.


Published ·Deep Fathom