In early 2026, an attacker with no prior industrial control systems experience used mainstream AI models to compromise multiple Mexican government organizations, including an attack attempt on a Monterrey water utility, where the AI, without being asked, identified critical infrastructure and recommended a targeted attack against it. The attempt failed, but it exposed something significant: AI has made critical infrastructure visible to attackers who previously lacked the knowledge to find it, and that’s only one thread in a much larger shift. Taken together, researchers believe these developments have opened a narrow window, perhaps six months, before AI capable of finding and exploiting vulnerabilities at scale reaches criminal marketplaces.
Attendees will learn:
• How the Monterrey water utility attack and a separate large-scale, AI-orchestrated cyberattack signal a new class of threat actor capability
• Why the criminal AI marketplace has moved from the dark web to the open web, and what that means for takedown efforts
• How malicious agent skills and shadow AI are turning employee enthusiasm for AI tools into a new insider attack surface
• What AI-powered vulnerability discovery means for the gap between patch release and exploitation, and why that gap is closing fast
• Why researchers believe organizations have roughly six months to prepare, and what “prepared” actually means across patching, monitoring, and shadow AI governance
Guest Speaker, Mark Stockley, Cybersecurity Evangelist, ThreatDown, is a renowned speaker, and host of the award-winning podcast The AI Fix. An expert in modern cyberthreats, ransomware, and AI, Mark is known for making complex topics engaging and easy to understand. With more than two decades of experience, he has worked with leading global cybersecurity brands, investigating emerging threats and helping organizations navigate the rapidly evolving AI and security landscape.
Hosted by Gary Miliefsky, CISSP Publisher, Cyber Defense Magazine
