Skip to main content

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Written by
Headshot of Snyk Team

Snyk Team

feature insights context

October 7, 2026

0 mins read

Last week, Snyk CTO Manoj Nair sat down with Alon Krifcher, Head of Applied AI from Anthropic, for a live discussion on the coming wave of autonomous attacks. Manoj kept landing on one thing: the AI Hurricane has already arrived, and what's left is deciding whether your defense runs at the same speed as the threat.

Attacks have gone agentic, and so has the code writing them. Across thousands of real enterprise environments, Snyk is seeing new security issues introduced grow more than 2X quarter over quarter, and for every six new issues, teams are closing one. CrowdStrike's most recent threat report clocked the fastest recorded breakout time at 27 seconds. The average is now measured in minutes, not months. Zero days used to take a long time to develop and longer to exploit, giving defenders time. Time is exactly what autonomous attackers have taken away.

However, Manoj doesn't think the sky is falling. He thinks the response is simpler than people expect, and it's already working in the largest enterprises he talks to. If autonomous attacks demand machine-speed defense, he argues, you need four things running in parallel, not in sequence: Discover → Remediate → Validate → Prevent. You can start anywhere in that loop. Most companies start with the backlog they already have, because everyone has one.

That's where the risk math changes. The old model: likelihood times impact. Impact hasn't moved much, but likelihood has. An attacker can now cheaply and agentically chain three vulnerabilities, each classified as low or medium, into something that isn't low or medium at all. Retriaging everything isn't the answer, Manoj explains. Starting with your highest-impact applications and testing them the way an autonomous attacker actually would — that's the answer, and it's why Snyk built Evo Continuous Offensive Security. One early customer ran it against an app that had come back clean from a pen test that same week. Snyk found everything the pen tester found, plus two or three things they had to fix that day. It's not a concept, Manoj says. It's live.

On the backlog itself, some of Snyk's customers, including Labelbox and Relay Networks, have talked publicly about getting to backlog zero using a combination of Skills and remediation agents built on Claude. Another Fortune 10 customer said the same thing. If that's true at that scale, he says, "we'll deal with the backlog eventually," stopped being a credible plan.

Prevention is the piece Manoj is most proud of, because it's where Snyk started. The company was built on the idea that you fix security at the point of creation, instead of after the fact. The point of creation moved. For most companies he talks to now, it's an agent. So Snyk built Snyk Studio to give that agent the same security context a good developer would have, at the exact moment it's writing code, fast enough that the agent doesn't just route around it. Almost 1,500 customers are running this in production today. Manoj demoed it recently by asking an agent to build a QR code scanner. Told the truth about two candidate packages: one abandoned for a decade, one current and clean. It picked the right one without a human having to catch it.

None of this works, Manoj argues, if it's treated as Snyk's job alone, and he wants to be direct about where the line sits with a partner like Anthropic. They're doing the hard work of keeping their models from being weaponized at the intelligence layer. That work has a boundary, and the boundary is the surface area their guardrails don't reach: exposed credentials, misconfigured components, an agent, a team built without knowing what packages, or Skills it pulled in along the way. Snyk is seeing roughly a three-to-one ratio of models to agentic components across the nearly 3,000 customers using its AI bill of materials today. Every one of those components is a place where risk can hide if nobody's watching it. Snyk used this same approach to help secure one of the largest cloud code deployments in the world this summer: 50,000 developers, rolled out with continuous Skill scanning built in from day one.

If you take one thing from all of this, Manoj says, measure one number: new findings versus findings closed, for your top applications. Everything else on a security dashboard, like tickets opened, scans run, headcount added, moves because you did something. That ratio only moves when the program itself actually changes. If you're sitting at six to one and it's getting worse, you're building inventory, not security. Track a second number if you can: what proportion of proposed fixes merge without a human rewriting them? That's the real throughput constraint, and it tells you how agentic your remediation actually is versus how agentic you'd like it to be.

The market moves in weeks, Manoj says. The playbook above is a starting point, not a finish line, and he expects it to evolve the same way this whole space has evolved in the year since Snyk shipped Studio. What hasn't changed, and won't, is the conviction Manoj and Alon share: attackers only have to win once, and the only real defense is layered enough that there's no daylight left for them to find.

Want to hear the full conversation? Watch the on-demand session with Manoj Nair and Alon Krifcher.

On-Demand Webinar

Snyk & Anthropic: Preparing for the Coming Wave of Autonomous Attacks

The Register’s James Hayes is joined by Manoj Nair, Chief Innovation Officer at Snyk, and Alon Krifcher, Head of Applied AI at Anthropic, for a direct look at what is actually changing and what a credible response looks like in operation.