Shared scroll

View this post on Scrolls

Amerigo Magazine
Amerigo Magazine
@amerigomagazine
AI Is Changing Hacking — and the Next Cyberattack May Move at Machine Speed

Article

AI Is Changing Hacking — and the Next Cyberattack May Move at Machine Speed

Artificial intelligence is rapidly reshaping cybersecurity, giving defenders powerful new tools while raising fears that hackers could automate parts of attacks that once required significant time and expertise. Artificial intelligence has spent the past several years learning how people write, code, search and communicate. Now cybersecurity experts are confronting another consequence of that progress: AI can potentially help criminals do many of those things, too. The emerging threat is not necessarily an autonomous machine independently deciding to hack a company. More immediately, security researchers are concerned about criminals using AI as an accelerator — helping them research potential targets, write convincing phishing messages, analyze stolen information and modify malicious code more quickly. That could change the economics of cybercrime. Traditional hacking campaigns often require considerable human labor. Attackers have to identify targets, study their systems, craft messages and sift through whatever information they manage to obtain. AI systems could reduce the amount of time required for some of those tasks, potentially allowing a relatively small criminal operation to pursue far more targets. Phishing illustrates the problem. For years, fraudulent emails were frequently recognizable because of awkward grammar, strange wording or generic messages. Generative AI can produce polished emails in seconds and tailor them to particular professions, companies or situations. Voice and image-generation technology can make impersonation attempts even more convincing. The same technology can also help analyze software. Modern AI coding systems are capable of reading large amounts of source code and explaining how programs operate. Those abilities can be enormously useful to legitimate developers and security researchers looking for vulnerabilities. In the wrong hands, however, similar capabilities could help attackers investigate weaknesses faster. Cybersecurity has consequently entered something resembling an arms race. Companies are deploying AI to examine enormous streams of network activity, identify unusual behavior and prioritize security alerts. Automated systems can sometimes detect suspicious activity faster than a human analyst working through thousands of notifications. That creates an unusual dynamic: AI systems may increasingly be used to identify attacks that were themselves partially created or accelerated using AI. Humans nevertheless remain central to the equation. Many successful cyberattacks still begin with familiar weaknesses — reused passwords, deceptive emails, unpatched software or employees accidentally granting access to someone they believe is legitimate. AI does not eliminate those methods. It can make some of them easier to scale. The larger concern is what happens as increasingly capable AI systems become able to perform longer sequences of digital tasks with less human supervision. A future attacker might not need to manually perform every stage of an intrusion. A person could potentially direct software agents to gather information, examine potential vulnerabilities and continuously adapt their approach, while intervening only at critical moments. Defenders are pursuing the same automation. An AI security system could potentially identify suspicious activity, isolate an affected computer and help engineers understand what happened before an attacker has time to move deeper into a network. The result may be a cybersecurity environment operating at speeds increasingly difficult for humans alone to match. For governments, technology companies and businesses, the challenge is therefore larger than stopping a new generation of computer viruses. They must determine how to secure a world in which both sides of a digital confrontation can increasingly delegate work to machines. The age of AI hacking does not mean computers have suddenly become independent cybercriminals. It means the people behind cyberattacks may soon be able to move much faster. And on the internet, speed can be the difference between discovering an intrusion and discovering the damage.

More
Log in to interact

Scrolls

Join the conversation on Scrolls

Open in the app to comment, rescroll, and follow the creator.