
Microsoft Threat Intelligence Podcast Fact vs Hype: How Threat Actors Are Really Using AI Right Now
Jan 28, 2026
Chloe Mesdaghi, AI governance and cybersecurity risk lead focused on oversight and resilience. Crane Hassold, security researcher tracking how adversaries adopt tech. They cut through hype to show where AI actually helps: detection, triage, automated recon, and workflows. They flag real risks like prompt injection, agent manipulation, and AI systems becoming targets. Practical, practitioner-focused conversation.
AI Snips
Chapters
Transcript
Episode notes
Content Quality ≠ Proof Of AI Use
- AI improves content quality but doesn't prove attribution of malicious emails.
- Well-written phishing existed before LLMs, so detection must use other signals.
Accelerate Detection Engineering
- Use AI to accelerate detection engineering tasks like writing and refining regular expressions.
- Treat AI as a force-multiplier to make defenders more effective, not a replacement.
Attackers Follow ROI, Not Tech Hype
- AI adoption follows attacker psychology: they'll use what yields sufficient ROI.
- Most actors prefer existing profitable tactics over pushing AI to extremes.
