There is a lot of talk right now about AI becoming the better hacker. What often gets overlooked: that is only the first phase. A proverbial cybercrime Zeitenwende begins after it.
The End of the Classic Playing Field
Over the past decades, cyberattacks were relatively clearly structured: find a vulnerability, develop an exploit, gain access, and so on — the sequence usually described as the “Cyber Kill Chain”.
The bottleneck in that chain was always the technical gap. Vulnerabilities, let alone 0-days, were rare, expensive and highly profitable. With AI, exactly that is changing. Systems like the models demonstrated by Anthropic are already able to find vulnerabilities faster and analyze them more systematically — and, looking ahead, to validate and patch them automatically. The half-life of a 0-day drops drastically, because from now on it gets discovered and closed quickly.
When Exploits Lose Their Value
This leads to an economic shift that is hardly being discussed. Attackers do not optimize for elegance — they optimize for return. And this is exactly where the system tips over.
A vulnerability nobody else knew about stayed usable for a long time.
Their half-life drops drastically, because they get found and closed quickly.
Breaking in through the technology paid off reliably.
The same effort buys less access — so the ROI goes down.
Manual work, and easy to recognize when it was done badly.
Thanks to AI — which is precisely what makes it worth the capital.
Capital and energy will migrate to wherever attacks are still worthwhile — that is the logical consequence.
The Human as the Last Truly Profitable Point of Attack
And here comes the uncomfortable truth: when systems get harder, only one real vulnerability remains — the human. That is not a new insight. What is new is the dynamic we can expect. The data already shows a clear trend today:
- The majority of all attacks begin with social engineering.
- AI-generated phishing campaigns scale massively.
- Attacks are becoming personalized, multi-stage and cross-channel.
This means the human attack surface stays wide open, while technical security will increase considerably.
The New Quality of Attacks
What is changing in parallel is the nature of the attacks themselves. We are moving away from the simple phishing email towards something with a different craft behind it:
The crucial point here is that these attacks are no longer manual. They are automated and therefore scalable, they are data-driven, and they are continuously optimized by the criminals. In short: AI industrialises social engineering.
The Quiet Shift Inside Companies
While the attackers' vectors are changing, internally the opposite often happens on our side. The focus stays on technology — infrastructure, compliance, tools. The report mentioned above shows it clearly: security budgets keep rising, but the investments flow primarily into technical measures. At the same time, the human stays under-addressed. That is a structural problem, and one we know all too well.
The Zeitenwende of Attack Vectors
The real Zeitenwende, therefore, is not technological, it is strategic. Cybersecurity has long been a question of: “How do we protect our systems?” It is increasingly becoming a different one: “How do we change human behavior under attack?”
The reality is that systems are getting more robust, attacks are getting more intelligent, and humans remain consistently manipulable. The playing field is starting to shift — permanently. We are moving towards a new reality in which 0-days become rarer and shorter-lived, technical attacks lose their appeal, and social engineering becomes the dominant attack vector. Not because it is new, but because it is almost the only thing cybercriminals have left.
The biggest challenge of the next decade is not a system — it is human behavior. And that is exactly where cybersecurity will be decided going forward: in strengthening behavioral defenses. Others improve their employees' knowledge; Cyberdise changes their behavior.

