Key Takeaways
- AI is reshaping both defensive and offensive cyber operations across the MENA region, accelerating attack workflows and lowering the cost of cybercrime.
- In the first half of 2026, Kaspersky blocked 75.8 million web‑based attacks in the Middle East, highlighting the scale of the threat landscape.
- Emerging threats include AI‑generated malware, cloud‑based data exfiltration, ransomware focused on operational disruption, and the abuse of autonomous AI agents.
- AI agents introduce new attack surfaces because they can plan, call APIs, and interact with enterprise systems autonomously, making them ripe for prompt injection, context manipulation, and supply‑chain compromises.
- Critical infrastructure, financial institutions, and government bodies remain prime targets, though motivations differ—financial gain, espionage, and service disruption, respectively.
- Securing AI agents requires treating them as privileged enterprise systems: enforce least‑privilege access, continuous behavior monitoring, model and plugin integrity checks, strong governance, and human oversight for high‑impact actions.
- Looking ahead, generative and agentic AI will dominate cybersecurity developments over the next two years, offering defenders faster data analysis and automation while empowering attackers with scalable phishing, malware creation, and autonomous reconnaissance.
- Organizations that integrate AI responsibly into their security strategy—balancing automation with rigorous oversight—will be best positioned to thrive in the evolving threat environment through 2026 and beyond.
AI’s Dual Role in the Evolving Threat Landscape
The adoption of artificial intelligence is rapidly transforming the cybersecurity environment across the Middle East and North Africa (MENA). While enterprises harness AI to boost efficiency and fortify defenses, threat actors are simultaneously weaponizing the same technology to craft more sophisticated malware, automate phishing campaigns, and speed up the overall attack lifecycle. Sergey Lozhkin, Head of Kaspersky’s Global Research & Analysis Team for APAC and META, warned that AI will remain a pivotal factor shaping threats through 2026, as it already accelerates adversary workflows and expands their operational scale.
Scale of Attacks Blocked in H1 2026
Kaspersky’s telemetry revealed the magnitude of the challenge: its systems thwarted 75.8 million web‑based attacks across the Middle East during the first half of 2026. This figure underscores the relentless volume of malicious activity confronting organizations in the region and serves as a baseline for understanding how emerging AI‑driven tactics are amplifying traditional threat vectors.
Emerging AI‑Powered Threats
Beyond sheer volume, the nature of threats is shifting. Kaspersky identified several emerging trends, including AI‑generated malware that can adapt on the fly, cloud‑based data exfiltration leveraging legitimate infrastructure, ransomware variants that prioritize disrupting business operations over simple file encryption, and the growing abuse of AI agents. Each of these developments signals a need for organizations to reassess their defenses and invest in AI‑aware resilience measures.
How Attackers Weaponize AI Across the Attack Lifecycle
Lozhkin highlighted that threat actors now embed large language models (LLMs) into every stage of an attack. LLMs facilitate the rapid creation of convincing phishing emails, the generation of malicious code, and the automation of reconnaissance, making attacks cheaper, faster, and easier to scale. This integration reduces the technical barrier for cybercriminals, allowing even less‑skilled actors to launch sophisticated campaigns that previously required specialized expertise.
The New Attack Surface: Autonomous AI Agents
A particularly concerning development is the rise of autonomous AI agents—systems that can plan, invoke APIs, interact with enterprise applications, and execute actions without constant human supervision. Unlike traditional AI tools that merely generate or summarize content, agents become active participants in an organization’s workflow, thereby expanding the attack surface. Attackers can exploit these agents through prompt injection, context manipulation, compromised models or plugins, abuse of authorized tools, or runtime vulnerabilities to perform unauthorized actions or exfiltrate sensitive data. Moreover, agents rely heavily on external frameworks, plugins, APIs, and cloud services, creating a novel software supply chain that must be secured alongside the models themselves.
Sector‑Specific Risks and Motivations
Critical infrastructure, financial institutions, and government organizations continue to attract the most attention from cybercriminals and advanced threat actors, albeit for different reasons. Financial firms are primarily targeted for monetary gain via credential theft, banking malware, and ransomware. Government bodies face persistent espionage campaigns aimed at harvesting classified or sensitive information. Attacks on critical infrastructure carry the greatest societal impact, as they can disrupt essential services such as power, water, and transportation, thereby affecting businesses and communities at large. Lozhkin also noted that adversaries are growing more patient, blending social engineering with legitimate administrative tools to craft stealthy, hard‑to‑detect intrusions that surpass traditional malware‑based attacks in sophistication.
Best Practices for Securing AI Agents
Given the privileged nature of AI agents, Lozhkin advises treating them as core enterprise systems rather than ordinary software. Security should begin with the principle of least privilege—granting each agent only the permissions essential for its designated function. Continuous visibility is crucial: organizations must monitor agent behavior, validate the integrity of underlying models, plugins, and external dependencies, and enforce rigorous governance over every action the agent takes. Because agents frequently interact with third‑party tools and cloud services, securing the AI supply chain becomes as vital as protecting the models themselves. Finally, maintaining human oversight for high‑impact decisions ensures that autonomous actions can be reviewed and vetoed when necessary, reducing the risk of unintended or malicious behavior.
Future Outlook: Generative and Agentic AI as Catalysts
Looking ahead, Lozhkin predicts that emerging AI technologies—especially generative AI and agentic AI—will exert the greatest influence on cybersecurity over the next two years. For defenders, these tools enable rapid processing of massive data sets, quicker anomaly detection, and automation of routine tasks, freeing analysts to focus on complex investigations. Conversely, cybercriminals will exploit the same capabilities to produce more convincing, scalable phishing campaigns, accelerate malware development, and automate reconnaissance and social engineering. The shift from AI assistants to fully autonomous AI agents embedded throughout enterprise environments will further blur the traditional network perimeter, extending it to encompass cloud services, AI platforms, third‑party plugins, APIs, and external data exchanges.
Strategic Imperatives for Organizations
Over the next five years, the organizations that succeed will be those that recognize AI not merely as a threat vector but as an integral component of their cybersecurity strategy. This means investing in AI‑driven defenses while simultaneously hardening the AI lifecycle—from model development and deployment to ongoing monitoring and supply‑chain security. By coupling advanced AI capabilities with robust governance, continuous monitoring, and human oversight, enterprises in the META region can harness the benefits of automation and intelligence without exposing themselves to the heightened risks posed by adversarial AI. In doing so, they will position themselves to resist the evolving tide of AI‑powered cyber threats and maintain resilient operations well into 2026 and beyond.

