ENISA

3 items · Policy 2 · Defense 1 · all entities

ENISA's annual threat report says AI is augmenting existing attacker skills rather than producing new capability — for now

The EU cybersecurity agency's Threat Landscape 2026, drawn from 8,257 incidents collected between 1 January and 31 December 2025, finds that “threat groups are primarily leveraging closed AI models to augment existing skills rather than achieve novel breakthrough capabilities,” mainly through consumer-grade tools for phishing, fraud and malware development. Looking ahead, ENISA assesses that “artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations,” and expects 2026 to bring “an increased number of the kill chain's phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts.”

On the recordENISA ↗ ·

An AI patching vendor says it code-reviewed the EU's new vulnerability-reporting platform before it went live

AISLE, which sells what it calls “AI-native vulnerability lifecycle management” — a platform that finds flaws and generates ready-to-merge patches — announced that it performed AI-based secure code review of ENISA's Cyber Resilience Act Single Reporting Platform, and that the arrangement includes continuing coverage. ENISA launched that platform on September 11, the day the CRA's reporting obligations became enforceable for manufacturers, who must file an early warning on an actively exploited vulnerability within 24 hours and a fuller notification within 72. The release names ENISA's Chief Cybersecurity and Operations Officer, Hans de Vries; it states no figure for vulnerabilities found or fixed, and ENISA's own launch announcement does not mention AI, code review or AISLE.

Self-reported, untestedAISLE (via GlobeNewswire) ↗ ·

ENISA publishes its view on cybersecurity in the frontier AI era, aimed at operational capability against machine-speed threats

Published the same day as the European Commission's EU Action Plan on Cybersecurity and Artificial Intelligence, ENISA's report sets out recommendations for national competent authorities, EU policymakers, defenders and service providers on building operational capability against what it calls machine-speed threats. ENISA frames it as an initial framework to be refined with Member States and aligned to the Commission's Action Plan.

On the recordENISA ↗ ·