Generative AI is erasing the technical skill gap that once separated experienced cybercriminals from inexperienced attackers, according to a new report published by BreachLock, a global offensive security firm. The analysis warns that the next wave of threat actors won't need years of exploit development or reverse engineering experience — they'll simply use AI to bridge knowledge gaps by speeding up research, generating code, troubleshooting errors, and adapting known techniques to new targets. The shift is collapsing the traditional hierarchy that once ranked attackers by technical sophistication, with nation-state operators at the top and so-called "script kiddies" at the bottom.
The economics of cyberattacks are shifting in ways that mirror earlier technology revolutions, the report explains. Cloud computing slashed the expense of building infrastructure, while open-source software cut the cost of developing applications. Now, large language models are reducing the cost of offensive security knowledge. An attacker who previously required weeks to grasp a newly disclosed vulnerability can now leverage AI to summarize technical documentation, explain exploit mechanics, identify affected technologies, and generate prototype code in minutes. The result is a larger population of more capable attackers who can become operational far more quickly than before.
The report introduces the concept of "vibe hacking" — the ability to translate intent into effective offensive activity through natural-language interaction with AI — as a parallel to what developers now call "vibe coding," where natural language replaces most of the manual effort behind working software. According to the analysis, today's emerging attacker often collaborates with an AI assistant, asking iterative questions, refining payloads, debugging code, and adapting techniques to a specific environment. The report argues that the term "script kiddie" no longer captures this dynamic, because expertise is becoming accessible on demand. Complex intrusions still demand expert judgment, creativity, and persistence, the authors note, but what's changed is how much expertise it takes to get operational.
The broader implication is that defenders can no longer rely on attacker scarcity as an implicit layer of protection, the report warns. Many organizations built their security programs around an assumption that highly capable attackers were relatively rare. As AI compresses the time between vulnerability disclosure and exploitation, periodic penetration testing and vulnerability scanning stop being sufficient on their own. The report advocates for Continuous Threat Exposure Management — a cycle of discovery, prioritization, validation, and mobilization conducted on an ongoing basis rather than as a point-in-time snapshot. Adversarial Exposure Validation and Penetration Testing as a Service are how the validation stage actually gets executed, testing the same paths an AI-assisted attacker would try, on the same timeline they'd try them.
Organizations need continuous evidence that critical attack paths stay closed, that compensating controls keep functioning, and that security spending is reducing exploitable risk rather than just generating more findings, the report concludes. Technical complexity alone no longer discourages adversaries. Resilience now depends on continuously validating security controls, understanding real attack paths, and prioritizing exploitable risk over theoretical exposure. The age of AI-assisted attackers has already started, and it's time to build security programs that can outpace what today's adversaries are now capable of. Defensive strategies anchored to yesterday's threat landscape may discover they're racing against an opponent whose learning curve has steepened far faster than anticipated.

