AI, Bots, and Automated Attacks: New Challenges for Website Security

In short:

The Internet has always been vulnerable to attacks. What is new, however, is the speed and degree of automation with which vulnerabilities can be found and exploited. Today, artificial intelligence helps developers and security experts analyze large amounts of program code, detect errors, and identify potential security issues. However, these same capabilities can also be

silhouette photograph of a man

The Internet has always been vulnerable to attacks. What is new, however, is the speed and degree of automation with which vulnerabilities can be found and exploited. Today, artificial intelligence helps developers and security experts analyze large amounts of program code, detect errors, and identify potential security issues. However, these same capabilities can also be misused. AI bots are already automatically scanning the internet for known vulnerabilities. With AI and increasingly autonomous AI agents, this automation can reach a new level: systems can be analyzed, attack vectors assessed, and parts of an attack carried out automatically. For companies, this means one thing above all else: the time between the discovery of a security vulnerability and the first attacks is becoming increasingly critical.

Just how real this trend is became evident in mid-July 2026 with WordPress, the globally used content management system. On July 17, security updates were released for two vulnerabilities that could be exploited in combination. Particularly problematic: In affected WordPress versions, this combination could, under certain conditions, enable so-called remote code execution—that is, the execution of code on the server without prior authentication. The WordPress core itself was affected, not just some additionally installed plugin. Shortly thereafter, publicly available proof-of-concepts were already circulating, and security firms observed actual attacks on systems that had not yet been updated. On July 20, TechCrunch reported estimates suggesting that, at that time, tens of millions of WordPress websites may still have been vulnerable. What’s key for our article, however, is not so much WordPress itself. The incident serves as a prime example of just how narrow the window of opportunity has become for operators of modern websites. In the past, one might have been able to rely on installing an update “when the time was right.” Today, a publicly known vulnerability can be automatically detected and exploited on the internet very quickly. WordPress therefore not only released updates but, according to reports, in some cases even enabled mandatory automatic security updates.

The entire online world is affected

WordPress is a good example because of its widespread use, but the underlying problem affects virtually any publicly accessible software: websites, online stores, customer portals, booking systems, club platforms, members-only areas, newsletter systems, web applications, APIs, or custom-developed online solutions. Software runs everywhere. And software can contain errors. Added to this are dependencies on third-party components: libraries, extensions, interfaces, payment providers, JavaScript components, server software, and external services.

These days, a modern website is not a finished product that can be created once and then operated unchanged for ten years. It is an IT system that is continuously maintained. To me, that would be one of the key messages of the article.

Why Swiss SMEs and nonprofit organizations, in particular, need to change their mindset

Understandably, many Swiss SMEs, associations, and smaller organizations still view their websites primarily as a means of communication. The site may have been created five years ago, continues to function, and is updated occasionally. As long as it’s accessible and looks good, everything seems fine.

Awareness is often slightly higher among small online stores. However, it tends to be lower for club websites, local businesses, doctors’ offices, accounting firms, architecture firms, or small company websites. Yet for an automated attack, the size of the organization hardly matters. A bot doesn’t distinguish between an international corporation and a sports club in the Emmental. It finds vulnerable software—and tries to exploit it. This insight, in particular, is likely to be important for your target audience.

“There’s nothing to be gained here, after all.”

Many smaller companies think:

We don’t store credit card information. Why would anyone hack our website? Because a compromised website has value in and of itself. For example, an attacker could:

  • Placing malicious code or phishing sites on the domain
  • Redirecting visitors to fraudulent websites
  • Sending spam or fraudulent emails through the server
  • Accessing login credentials or customer data
  • Manipulating Forms
  • Share bank or payment information
  • Create new administrators or hidden accounts
  • use the website for further attacks
  • Delivering Malware to Visitors
  • Edit or Delete Content
  • Generate SEO spam and thousands of unwanted pages
  • damage the domain’s reputation
  • fully encrypt the website or render it inoperable

With an online store, the challenges become even more critical.

For example, it is conceivable that payment information could be tampered with, orders or customer data could be stolen, or visitors could be redirected to a fake payment page without realizing it.

And even if no sensitive data is stolen, a compromised company website alone can cause significant damage.

The real damage often doesn’t begin until later

I think this is particularly important for small and medium-sized businesses. The damage isn’t limited to the fact that “the website was hacked.” This may be followed by: cleaning up the website, forensic analysis, restoring backups, changing passwords, checking other systems, communicating with the hosting provider and customers, addressing data protection issues, restoring the company’s reputation on Google, removing phishing warnings, reactivating email services, or verifying whether data has been compromised.

A security issue—which might have been prevented by a timely update—can suddenly result in days of work and significant follow-up costs. For an online store, this is compounded by an immediate loss of revenue.

AI is changing both sides in this process

AI also significantly improves security. Developers can review code more quickly. Security researchers can better identify vulnerabilities. Log files can be analyzed automatically, and unusual activity can be detected more quickly. At the same time, however, the technical barrier to entry for attackers is also lowering.

An interesting idea for the article would be:

AI doesn’t reinvent cyberattacks—but it can make existing methods faster, more scalable, and more automated.

Research is now even moving toward autonomous agents that can independently examine web applications and identify potential attack vectors. For example, a research project published in July 2026 demonstrated an autonomous agent for web security testing on controlled test systems. The authors deliberately withheld operational details and exploit code, precisely because of the dual-use risk.

This illustrates very well where things might be headed, without turning it into a scare story.

The Implication for Smaller Businesses: Professionalization

At this point, I’d start to make the connection to your service—but without saying “Buy a maintenance contract now.”

The days when a company website could simply be set up somewhere and then left to fend for itself for years are coming to an end.

Even smaller companies are increasingly in need of basic professional structures:

Regular security updates, backups, monitoring, secure user accounts, two-factor authentication, properly configured access rights, server and hosting security, protection mechanisms against automated attacks, and someone who can assess security alerts and respond to critical incidents.

An SME does not need to set up its own IT security department.

But there should be clear guidelines on who is responsible.

“Who actually looks at our website?”

That could be another strong subheading. Many companies probably wouldn’t be able to answer this simple question.

  • Who checks to see if updates are available?
  • Who determines whether an update is security-critical?
  • Who notices unusual access attempts?
  • Who monitors the backups?
  • Who knows what to do if a critical security vulnerability is disclosed tomorrow?
  • After an attack, who verifies that all backdoors have actually been removed?

If the answer to all these questions is “no one,” that is precisely where the real risk lies.

Professional care is evolving from a convenience to a safety issue

For a long time, professional website management was primarily a matter of convenience. Updates were handled, backups were checked, and technical issues were resolved. With the increasing automation of cyberattacks, this role is changing.

Ongoing support is increasingly becoming an integral part of a company’s security strategy. A professionally managed website should therefore involve more than just updates. The key lies in the interplay of software, hosting, configuration, access rights, monitoring, backups, responsiveness, and expert assessment.

A Look Ahead

Twenty years ago, a company website was often little more than a digital business card. Today, it encompasses forms, customer data, email communication, online stores, interfaces, member areas, and, in some cases, entire business processes.

Accordingly, our understanding of their safety must also change.

These days, a professional website needs not only someone to build it—but also someone to ensure that it can continue to operate securely in the future.

In my opinion, that would also be the ideal way to subtly mention your maintenance and security services right at the very end.

Wenn auch Sie mit einer Herausforderung konfrontiert sind und Unterstützung oder Beratung benötigen, dann kontaktieren Sie uns gerne.

Für allgemeine Anfragen / Offertanfragen / Projektfragen:

E-Mail: solutions@rettenmund.com

Zur Blog-Übersicht

More interesting new articles

WE WORK FOR, AMONG OTHERS ...

Stiftung für Konsumentenschutz

swiss alpine herbs - SWISSALPINEHERBS

Schweizerische Eidgenossenschaft

BETAX Genossenschaft BERN

männer.ch - Dachverband Schweizer Männer- & Väterorganisationen

UBS Bank - Y

medbase Gruppe

REKA Genossenschaft

Kyburz Saphire, Safnern - Optische Komponenten Saphir, Keramik

Edition Königstuhl

Gemeinde Urtenen-Schönbühl

LKBV - Luzerner Kantonal-Blasmusikverband

stadtwerke kongress aarau

Casafair - Eigentum mit Verantwortung

Green Golfreisen

Swisspower AG

Gemeinde Moosseedorf

Einwohnergemeinde Lengnau

reCIRCLE AG - Die Mehrwegsystem-Lösung

HESAV - Haute Ecole de Santé Vaud