Gartner has named four security threats where attackers already hold the advantage—and most organizations aren’t catching up fast enough.

The four threats are:

  • AI application compromises
  • Identity impersonation using deepfakes
  • Software supply chain threats
  • Prompt injections

At its Security & Risk Management Summit in National Harbor, Maryland, Gartner VP Analyst John Watts explained these critical threats in significant detail and how to counter them. Here are some key takeaways:

AI Application Compromises

As AI applications grow in popularity, attackers are targeting both publicly used and internal enterprise AI tools. Watts noted 2,130 AI-related CVEs disclosed in 2025, a nearly 35% year-over-year increase.

Gartner recommends, among other things, that CISOs apply secure development life cycle and threat modeling best practices to AI applications.

Identity Impersonation Using Deepfakes

Six in 10 organizations have been struck by a deepfake attack involving social engineering or bypassing facial or voice recognition systems, according to Gartner.

“Attacker use of deepfakes continues to advance and is now commonplace to make fraud and phishing scams difficult to detect,” Watts said. “There is no one cybersecurity control that will protect you. Instead, organizations should use a combination of strengthening business processes, improving awareness, and deploying available deepfake detection technologies where possible.”

Software Supply Chain Threats

Attackers will continue to use AI software to uncover vulnerabilities in open source software. Claude Mythos Preview, for instance, recently found thousands of zero-day vulnerabilities, many of which are critical, in every major operating system and every major web browser, according to Project Glasswing.

To secure their applications, cybersecurity teams build comprehensive inventories of software assets and integrate strong controls at every stage of application development, Gartner recommends.

Prompt Injections

Prompt injections target AI systems, especially large language models (LLMs), and aim to overwhelm them, forcing them to cough up sensitive information or perform unauthorized actions. Data from Google shows a 32% increase in indirect prompt-injection attacks from November 2025 to February 2026, Watts noted.

Gartner’s recommendation: Cybersecurity teams should proactively identify vulnerabilities in LLMs and other AI systems, establish strong system prompts to guide AI behavior, and deploy AI runtime guardrails that monitor for and block suspicious activity.

Time to Act

What could a security incident stemming from one of the four critical threats cost? Globally, a single data breach costs USD $4.4 million. In the U.S., however, the cost of a data breach has “surged past USD $10 million, driven by steeper regulatory penalties and rising detection costs,” according to IBM’s “The Cost of a Data Breach Report 2025.”

Taking these threats seriously—and acting immediately—could save your organization significant money and hardship.

Share Button