Security1 publisher2 min readPublished
Talos argues defenders are already behind the models they have
Cisco Talos's weekly newsletter says the newest models add only incremental cybersecurity capability, and that defensive use has not kept up with the ones already shipped.
The Watch · Security desk

What happened
- Cisco Talos's Threat Source newsletter argues that an AI slowdown, if one happened, would not have much impact on cybersecurity.
- Talos says models have improved so fast that defenders' ability to use them effectively for defensive tasks has not kept up.
- The strategy Talos proposes is improving agentic harnesses and frameworks to get more capability out of the models organisations already have.
- In the same newsletter, Talos reports ransomware incidents in Japan rose nearly 5 percent in the first half of 2026.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision If Talos is right, the security AI budget line that returns something is integration labour: engineers building harnesses around licensed models.
- exposure Qilin's script generation already runs on public models, so a frontier slowdown leaves Japanese small and medium enterprises where they are.
- constraint Weak asset inventories, loose identity management and flat networks cap what any model returns, so the fundamentals work gates the AI work.
A harness is the agent framework, tool access and permissions that let a model an organisation already licences do defensive work. Talos's suggestion is to improve that layer instead of waiting on the next release [5]. The same newsletter says recent releases bring only incremental improvement in cybersecurity capability [2].
The offensive side of the newsletter is where the concrete case sits. Talos names two actors behind the Japanese increase: "The Gentlemen," a rapidly expanding ransomware-as-a-service operation, and Qilin, both hitting small and medium enterprises with double extortion [9]. Qilin uses large language models to generate destructive scripts, which Talos says accelerates attack speed and lowers the barrier to entry [10]. The Gentlemen uses AdaptixC2, a legitimate red-teaming framework, to blend in, and Talos says that makes lateral movement difficult to detect [11]. Both techniques run on models that already exist [15].
The second argument is about the environment the model sits in. "But no matter how great your AI is, if it's sitting on the typical two-and-a-half-legged stool that is most IT environments, you're still going to have compromises and breaches no matter how much AI you throw at it," the newsletter said [6]. The items Talos names as more impactful are asset and role inventories, identity management, least privilege and segmented networks [7]. It also draws the line at exclusion: "just don't look only to AI" [14].
The defensive lag is stated as judgement, and Talos published no measurement of how far defensive use trails model capability [16]. The offensive half is easier to check against what responders already see: Talos says practically every recent model can mine decades of tech debt for vulnerabilities [4]. The remediation list attached to the Japan research predates the AI question entirely, starting with auditing VPNs, disabling unused features, enforcing MFA on administrative and third-party accounts, watching endpoints for suspicious remote access or attempts to disable backups, and deploying the Snort rules in the full report [12].
Talos is explicit that it does not know whether a slowdown will happen or whether it should [13]. The claim being made is narrower than the debate it responds to: the models on the market are already ahead of the defensive workflows built around them [3].
What to watch
- Whether Talos publishes second-half Japan data showing if Qilin's LLM use changes victim counts or dwell time.
- Whether AdaptixC2 intrusions attributed to The Gentlemen turn up in telemetry outside Japan.
- Whether any vendor ships a defensive agent harness a security team can operate off the shelf.