Artificial Intelligence & Machine Learning for Security: From Threat to Cyber Defense

Published: August 21, 2026

How to block sites at DNS level, ones that are dangerous or damaging in many ways

Cloud, Companies, ISP & WISPs, MSP, OEM & Manufacturers, Retailers, Understanding Internet Security

person typing on the keyboard of a laptop and graphics rapresenting a brain

Artificial intelligence and cybersecurity are becoming increasingly intertwined. Yet when the two are discussed together, the conversation tends to focus primarily on one side of the relationship: how AI can make cyberattacks faster, more automated, and more scalable.

AI-generated phishing, vulnerability discovery, social engineering, malware, campaign automation, and, more recently, AI agents capable of carrying out offensive activities autonomously: the attention these risks receive is justified. But they represent only part of the transformation underway.

If Artificial Intelligence can enhance attackers’ speed and capabilities, why shouldn’t it do the same for those responsible for protecting networks, users, and data?

This is the other side of Artificial Intelligence & Machine Learning for Security. AI and Machine Learning are also becoming increasingly important tools for cyber defense, enabling organizations to analyze vast amounts of information, detect anomalies, classify potential threats, and accelerate detection and response.

In the sections that follow, we will explore why AI is reshaping today’s cyber threat landscape—but, more importantly, we will shift the perspective. We will examine how Artificial Intelligence and Machine Learning can be used in cybersecurity, their main applications in threat detection, and why these technologies play a particularly valuable role in DNS Security and the classification of potentially dangerous domains.

Because AI is not only changing how attacks are carried out. It is also changing how we defend against them.

AI and Cybersecurity: Why the Conversation Focuses Mainly on Risk

Artificial Intelligence is lowering some of the barriers that have traditionally limited the speed and scale of cyber operations.

Attackers can use AI-powered systems to support reconnaissance, analyze vulnerabilities, generate content for phishing and social engineering campaigns, or automate parts of an attack chain.

With the evolution of agentic AI, the implications become even more significant: rather than simply producing an output, a system can plan and execute sequences of actions to achieve a specific objective.

A recent incident clearly illustrates this evolution.

In July 2026, Hugging Face disclosed a particularly significant intrusion: its systems were breached not directly by a human operator, but by an autonomous AI agent based on OpenAI models.

OpenAI had been using the agent in an internal test designed to assess its cybersecurity capabilities, with the aim of finding and exploiting software vulnerabilities. While running the benchmark, however, the system managed to break out of the sandbox in which it was supposed to remain contained, exploiting a zero-day vulnerability to reach the Internet. From there, it compromised another external environment and used it as a launch point to penetrate Hugging Face’s infrastructure.

According to Hugging Face’s technical reconstruction, the agent then continued the attack autonomously, identifying vulnerabilities, executing code, collecting credentials, and moving through the infrastructure. In total, investigators reconstructed approximately 17,600 actions performed at machine speed.

On the one hand, the incident reveals a new risk scenario in which an AI agent independently escaped its test environment and breached real external systems. On the other, it highlights one of the factors set to have the greatest impact on the evolution of cyber risk: machine speed.

Many of the techniques used by attackers are not necessarily new. What is changing is the ability to execute, repeat, and adapt specific activities at a speed and scale that would be difficult to achieve through human effort alone.

The Center for Strategic and International Studies (CSIS) also notes that frontier AI models are rapidly improving their cyber capabilities, including their ability to identify vulnerabilities and conduct cyber operations at greater speed and scale.

The risk, therefore, is real.

But looking at AI’s impact on cybersecurity solely from the attacker’s perspective means ignoring half of the transformation underway.

Artificial Intelligence & Machine Learning for Security: The Other Side of AI

The same ability to analyze large volumes of data quickly can be applied in the opposite direction: to detect and counter threats.

Artificial Intelligence and Machine Learning are not synonymous.

Artificial Intelligence encompasses a broad set of technologies designed to perform tasks that require capabilities such as analysis, interpretation, decision-making, or information generation.

Machine Learning, by contrast, is a field within AI in which algorithms and models identify patterns in data and use what they have learned to classify or make predictions about new inputs.

This approach becomes particularly valuable when applied to cybersecurity.

A digital infrastructure continuously generates DNS queries, network events, security logs, access requests, and other forms of telemetry. Analyzing these volumes of information manually is simply not sustainable.

AI and Machine Learning can help security systems:

  1. recognize patterns associated with potential threats;
  2. detect anomalies in relation to expected behavior;
  3. correlate signals across large volumes of security data;
  4. automatically classify potentially suspicious elements;
  5. accelerate detection, investigation, and response.

The point, then, is not to determine whether AI is inherently a threat or a solution. The real question is who can use it better, and faster.

Next-generation DNS protection, fully cloud & AI-based and easy to activate

Why Machine Learning Is Becoming Increasingly Important in Cyber Defense

Modern cybersecurity faces a structural challenge: scale.

Every day, enormous volumes of events, requests, new domains, URLs, files, and communications are generated. At the same time, malicious infrastructure can change rapidly, while attackers modify techniques and indicators to evade security controls.

Can a security system based exclusively on static rules respond as quickly as an increasingly automated threat?

Increasingly, the answer is no.

Blocklists and predefined rules continue to play a role in cybersecurity, but they mainly rely on knowledge that has already been acquired: a given element must first have been identified, analyzed, and classified.

Machine Learning adds another layer of capability.

By analyzing recurring patterns and characteristics, models can help identify suspicious elements and support their classification. This allows cyber defense systems to operate across volumes of data that would be extremely difficult to manage through manual processes alone.

This does not mean eliminating the role of the cybersecurity expert.

It means enhancing their operational capacity.

The goal is to combine human expertise, threat intelligence, automation, and computing power to reduce the time between the emergence of a potential threat and its identification.

And as attacks increasingly operate at machine speed, detection time becomes a security factor in its own right.

5 Applications of AI and Machine Learning in Cybersecurity

Artificial Intelligence & Machine Learning for Security now spans multiple layers of cyber defense. Here are five particularly relevant applications.

1. Threat Detection

Machine Learning-based systems can analyze large volumes of data to identify patterns associated with potentially malicious behavior.

Their main advantage lies in the ability to process and correlate more information than could be handled manually, helping security teams identify the signals that matter most.

2. Anomaly Detection

Not every threat immediately presents a known indicator.

Anomaly detection makes it possible to identify events or behaviors that deviate from an expected baseline. An anomaly does not automatically indicate an attack, but it may be a signal that should be analyzed and correlated with other indicators.

The goal is to reduce noise and improve the ability to identify what truly deserves attention.

3. Phishing and Malicious Content Detection

Machine Learning and AI can help analyze emails, URLs, domains, content, and other indicators used in phishing campaigns.

This capability is particularly important at a time when Generative AI enables attackers to produce more convincing and personalized communications.

In other words, AI can make social engineering more effective. At the same time, however, it can improve security systems’ ability to identify its warning signs.

4. Threat Intelligence and Classification

One of the challenges of Threat Intelligence is not merely collecting information, but turning vast amounts of data into actionable intelligence.

AI and Machine Learning can support signal correlation and classification, helping accelerate both the identification of potential threats and the updating of protection systems.

5. DNS Security and Domain Classification

DNS occupies a particularly strategic position in cyber defense.

Before connecting to an Internet resource through its domain name, a device will typically make a DNS query to determine the associated IP address.

This creates an opportunity: to assess the requested destination before a connection to a potentially dangerous resource is established.

This is precisely where AI and Machine Learning can make a significant contribution.

Next-generation DNS protection, fully cloud & AI-based and easy to activate

AI, Machine Learning, and DNS Security: Blocking Threats Before Connection

A DNS Content Filter applies security policies directly during the DNS resolution process.

When a user or device attempts to reach a domain, the system can inspect the request and determine whether to allow or block access based on the available information and configured policies.

This model is particularly effective against a broad range of web threats because it enables action before a connection is made to a destination classified as dangerous.

But there is a challenge: the Internet is constantly changing.

New domains and resources are created every day. Some serve legitimate purposes; others may be used for phishing, malware, Command and Control, or other malicious activities.

A traditional blocklist can effectively block a domain already known to be dangerous.

But what happens when that domain is new and has not yet been added to the databases used by the security system?

This is where continuous analysis and classification become valuable.

Machine Learning, classification algorithms, and Threat Intelligence can help analyze new domains and identify those with suspicious characteristics more quickly.

It is not simply a matter of knowing about past threats.

The challenge is to reduce the time required to recognize the threats emerging right now.

How FlashStart Uses AI and Machine Learning in DNS Security

The use of Artificial Intelligence in cyber defense is not merely a future prospect. It is already part of the technologies used to protect web access.

The FlashStart engine makes extensive use of AI and Machine Learning to detect and classify suspicious domains, integrating these capabilities into its DNS Content Filtering system.

The scale of its operations helps explain why automation is so important.

FlashStart checks more than 200,000 new websites every day, while its infrastructure handles billions of DNS queries, combining filtering with an Anycast network designed to maintain high service performance. The independent DNSPerf benchmark has also ranked FlashStart as the world’s fastest DNS resolver.

In this environment, Machine Learning and automated classification support a fundamental objective: rapidly identifying potentially malicious destinations and preventing users and devices from reaching them.

Security, however, cannot come at the expense of network performance.

Every control introduced into web access can potentially affect latency. A DNS Security platform must therefore combine protection capabilities, speed, and infrastructure reliability.

The value of AI in DNS Security should therefore be understood as part of a broader system: Threat Intelligence, Machine Learning, DNS filtering, and infrastructure must work together, because effective protection must recognize threats without becoming a constraint on business productivity or performance.

Next-generation DNS protection, fully cloud & AI-based and easy to activate

The Hugging Face Incident Also Reveals the Other Side of AI

Let us return briefly to the incident with which we began.

The story of the attack on Hugging Face includes one particularly interesting detail.

AI was not only used in the attack. It was also used in the defense.

Hugging Face stated that the intrusion was initially identified through an AI-assisted detection system: an anomaly detection pipeline used LLM-based triage on security telemetry to separate meaningful signals from everyday noise.

Once the incident had been detected, the company also used AI models to analyze more than 17,000 logged events, reconstruct the attack timeline, identify Indicators of Compromise, and determine which credentials had been involved. According to Hugging Face, tasks that would normally have taken days were completed in hours.

It is perhaps one of the clearest illustrations of the transformation ahead. On one side: AI-enabled attackers. On the other: AI-enabled cyber defense.

As attack speed increases, detection speed must increase as well.

AI vs. AI? The Future of Cybersecurity Will Be Increasingly Automated

The future of cybersecurity will not be a simple contest between humans and Artificial Intelligence.

It will be an ecosystem in which people, automated systems, and AI models operate simultaneously on both the offensive and defensive sides.

Attackers will continue to use AI and automation to increase the scale, speed, and capabilities of their operations. Defenders will need to do the same.

This does not mean handing cybersecurity over entirely to algorithms. Governance, human expertise, policies, risk analysis, and decision-making capabilities will remain essential.

It does, however, mean recognizing an important shift: when threats can operate at machine speed, cyber defense must also develop analysis and response capabilities that can match that speed.

The CSIS reaches a similar conclusion: as the cyber capabilities of AI models increase, investment in AI capabilities for defenders must increase as well.

The competition, therefore, will not simply be human versus machine. Increasingly, it will be AI-enabled attackers vs. AI-enabled defenders.

Artificial Intelligence & Machine Learning for Security: From Fear to Protection

Artificial Intelligence introduces new cybersecurity risks. Ignoring them would be a mistake. But it would be equally limiting to portray AI solely as a tool in the hands of cybercriminals.

Artificial Intelligence and Machine Learning are also becoming core cyber defense technologies, capable of supporting threat detection, anomaly detection, classification, Threat Intelligence, and incident response.

In DNS Security, this evolution has a tangible impact: analyzing vast volumes of requests, continuously classifying new domains, and blocking access to potentially malicious destinations before a connection is established.

This is the principle behind FlashStart’s integration of AI and Machine Learning into its DNS filtering technology: turning analysis and classification capabilities into proactive protection for web access, while maintaining performance and reliability.

When attacks can evolve at machine speed, defenses must be able to respond just as quickly. The timely identification and classification of a threat therefore become decisive factors in delivering effective protection.

Daniele Balducci

Marketing Executive

Daniele Balducci is a Marketing Executive at FlashStart, where he contributes to the development of content, campaigns, and communication strategies focused on cybersecurity and Internet protection.