In hindsight, a cyberattack can look like a straight line of technical brilliance. In practice, it is usually a chain: publicly available information, credible deception, stolen identities, vulnerable software, excessive privileges, limited visibility, and a response that starts too late.
Artificial intelligence can accelerate many links in that chain. It can compress research, personalize messages, analyze code, generate variations, and make large volumes of data useful to attackers and defenders. This does not mean that every vulnerability becomes exploitable, every attack becomes autonomous, or established security work becomes obsolete.
The Last Human Second presents the wider system. It covers social engineering, credential theft, Pass-the-Hash and other Active Directory attacks, exploitation, web and API attacks, cloud misconfiguration, malware, ransomware, data theft, operational technology, and software supply chains. Publicly documented incidents including WannaCry, NotPetya, SolarWinds, Colonial Pipeline, Log4Shell, MOVEit, MGM Resorts, Change Healthcare, 3CX, and XZ Utils show how technical, organizational, and human factors combine.
A dedicated part examines AI on the attacker side: faster reconnaissance, scaled deception, vulnerability research, exploit development, malware variation, deepfakes, and agentic workflows. The book distinguishes observed capability from plausible development and from claims for which public evidence remains limited.
AI is also an attack surface. Prompt injection, poisoned training or retrieval data, insecure model supply chains, overprivileged agents, and confidential-data leakage require controls of their own. Threat modeling and defense in depth must include these systems rather than treating them as isolated tools.
The most important countermeasure begins well before the incident: secure coding, the Security Development Lifecycle, ISO/IEC 27034, threat modeling, strong identity, secure defaults, controlled dependencies, and tested recovery. These foundations are complemented by modern detection, risk-based vulnerability management, incident response, and AI-assisted products for analysis, prioritization, and automation.
Can defenders still succeed without AI? In the author's view, a useful answer is neither an unconditional yes nor an unconditional no. Good architecture and rehearsed processes remain effective. At very large data volumes, with short response windows, and against automated opposition, choosing not to use AI-assisted support may create a measurable disadvantage. Even then, a model does not replace accountability or sound security foundations.
The book is written for security architects, developers, CISOs, risk officers, IT leaders, and everyone who wants to form a reasoned view between headlines, vendor claims, and real incidents.
Oliver Niehus
Oliver Niehus has worked in IT and technology since the early 1990s and has
spent more than twenty years in technical roles at a leading global technology
company.
For more than 15 years, his work has included the Security Development
Lifecycle, threat modeling, operating systems, cloud computing, cybersecurity,
artificial intelligence, and AI development.
The views expressed in his books
are his own.
understanding cyber attacks artificial intelligence cybersecurity secure software development practical threat modeling ransomware incident response Active Directory Cloud security software supply chain security