Artificial intelligence is changing cybersecurity on both sides of the equation. Attackers can use AI to analyze exposed software and accelerate their search for weaknesses—but defenders can use the same speed to identify and correct vulnerabilities before they become incidents.
That is the encouraging message behind new research from Mandiant, part of Google Cloud. Its security specialists have developed an AI-assisted vulnerability-discovery system that combines automated analysis with structured workflows and expert human validation. The result is not security without people. It is experienced professionals working faster, covering more ground and focusing their attention where it matters most.
A significant shift in cyber defence
Traditional vulnerability testing can require specialists to examine large applications, trace how data moves and determine whether suspicious behaviour is truly exploitable. Modern business systems may contain millions of lines of code, many dependencies and numerous connections to cloud services, databases and external users.
Mandiant’s approach uses specialized AI agents to map an application, identify entry points, analyze access controls and follow potentially dangerous data flows. Separate validation stages then challenge the initial findings before a human expert performs final verification.
According to Mandiant, this system found more than 100 true-positive critical vulnerabilities in two days during an incident involving stolen corporate source-code repositories. The organization also reported that the work contributed to 12 assigned Common Vulnerabilities and Exposures (CVEs). These results show how carefully governed AI can give defenders valuable time when attackers are moving quickly.
AI does not replace cybersecurity expertise
The most important part of this development is the combination of automation and professional judgment. AI can generate false positives, misunderstand business logic or miss controls that exist elsewhere in an environment. An automated finding should never be treated as confirmed simply because a model produced it.
Effective AI-assisted security therefore needs a defined threat model, accurate information about the organization’s assets and architecture, multiple validation stages, risk prioritization and hands-on expert review. Mandiant’s researchers specifically recommend manually validating findings.
This human-in-the-loop model is good news for organizations. It means AI can handle repetitive analysis at scale while experienced security professionals concentrate on complex attack paths, operational impact and practical remediation.
What this means for Toronto businesses
A company does not need to develop its own advanced AI security platform to benefit from this shift. The immediate lesson is that vulnerability management should become more continuous, structured and proactive.
- Maintain an accurate asset inventory. You cannot protect systems, cloud services, websites or applications that nobody knows are active.
- Prioritize internet-facing systems. Remote-access services, firewalls, websites, VPNs and cloud applications deserve frequent review because attackers can reach them directly.
- Patch with business context. A long list of findings is less useful than a prioritized plan based on exposure, exploitability and operational importance.
- Test access controls. Authentication and authorization weaknesses can expose sensitive functions even when the underlying software is fully updated.
- Combine assessment with monitoring. A penetration test provides a valuable point-in-time view, while continuous monitoring helps detect new risks and suspicious activity between assessments.
- Keep expert validation in the process. Automated scanners and AI tools should support—not replace—qualified analysis and controlled testing.
Turning AI into a defensive advantage
The cybersecurity conversation often focuses on how criminals can misuse artificial intelligence. That risk is real, but it is only half of the story. Defenders now have an opportunity to use AI to examine larger environments, detect subtle weaknesses and shorten the time between discovery and remediation.
The strongest results will come from combining modern tools with fundamentals that remain essential: secure network design, least-privilege access, timely patching, tested backups, proactive monitoring and regular security assessments.
For growing organizations, the goal is not to adopt every new security product. It is to understand the systems that matter most, identify realistic attack paths and invest in controls that meaningfully reduce business risk.
How Mehravin can help
Mehravin helps Toronto and GTA organizations assess infrastructure, identify security gaps and build practical improvement plans. Our services include network security review, penetration testing, cloud and infrastructure consulting, and proactive monitoring.
Would you like a clearer view of your organization’s technology risks? Book a complimentary consultation to discuss the most valuable next step.
Source: This article was inspired by Mandiant’s August 18, 2026 research, “Staying Ahead of Adversarial AI Through Agentic Source Code Review.”

