
The fastest way to get CISSP Certified. Join our bootcamp

September 2025. A Chinese state-sponsored group launched a cyberattack against 30 organizations across technology, finance, chemical manufacturing, and government.
The reconnaissance was automated. The vulnerability discovery was automated. The exploitation, the lateral movement, the data extraction - all automated.
A human operator reviewed outputs and approved decisions at four to six points during the entire campaign. Everything else was handled by AI.
Anthropic, whose tool was used to execute the attack, called it the first reported AI-orchestrated cyber espionage campaign. The group, designated GTG-1002, had jailbroken Claude Code and deployed it as an autonomous operator across a multi-stage intrusion workflow. The AI executed 80-90% of tactical operations independently, at thousands of requests per second - speeds no human operator could match.
Several of the 30 targeted organizations were successfully compromised before the campaign was detected and shut down.
Here's what changed:
Traditional cyberattacks require skilled operators with time to manually probe systems, identify vulnerabilities, and execute intrusions. That constraint limited how many targets an attacker could pursue simultaneously.
GTG-1002 removed that constraint. One threat actor, with minimal human involvement, ran a coordinated espionage campaign against 30 organizations at machine speed. A single operator achieved the reach of a well-funded hacking unit. The number of organizations any threat actor can target simultaneously went up. The time from initial access to data extraction went down.
The security gap this exposes:
Most organizations built their defenses against human attackers. Detection systems tuned to human behavior. Response timelines designed around how fast humans move.
AI-orchestrated attacks don't move at human speed. They don't probe the way humans probe. The indicators of compromise that security teams look for assume a human is making decisions on the other side.
GTG-1002 also demonstrated something equally unsettling: AI tools can be socially engineered. The attackers convinced Claude Code it was an authorized cybersecurity tester. The safety features weren't bypassed through technical exploits. They were bypassed through persuasion.
Your AI tools can be manipulated the same way.
This is what AAISM prepares you for.
Not traditional security threats applied to AI environments. AI-specific threats: how AI tools become attack vectors, how to detect AI-orchestrated intrusion patterns, how to build security programs that account for machine-speed attacks and AI tools that can be socially engineered.
Our next AAISM Bootcamp runs October 5-7. Three days with Joseph Zefrani covering everything ISACA tests. Full year of access to all course materials, plus four implementation tools for real-world AI security work.
Best,
The DestCert Team
P.S. Can't make the bootcamp? Our AAISM MasterClass covers the same material at your own pace.
Free CISM MindMap: Incident Management Training, Testing and Evaluation
We put together a free MindMap video covering the key concepts in Domain 4, a quick, clear way to get the big picture before you dive into studying. Free to watch, no strings attached. Plus you'll get downloadable audio files and printable PDFs.

Something is coming…
Something's been circling in the dark.
The CAT is nearly out of the bag.
Follow so you catch the drop. When it lands, it lands inside the MasterClass and Bootcamp only.

Free AAISM Exam Strategies Guide
Master the mindset and techniques top candidates use to pass the AAISM exam with confidence. Learn how to approach scenario-based questions, avoid common traps, manage your time effectively, and think like an AI security leader.

Destination CCSP just got a major update
We've refreshed the guidebook to match the latest exam outline, with AI/ML security now woven through all six domains. Same clear explanations that have helped thousands pass, updated for what ISC2 tests today.