AI agents and systems are increasingly assisting criminals in various stages of cyberattacks, although they cannot yet conduct them fully autonomously, according to the International AI Safety report. The report, authored by over 100 experts, highlights significant improvements in AI's ability to automate and perpetrate cyberattacks over the past year, as reported by The Register.The report notes that AI is particularly useful for identifying software vulnerabilities and generating malicious code. For instance, during DARPA's AI Cyber Challenge, finalist systems autonomously found 77% of synthetic vulnerabilities. Criminals are also leveraging AI tools like HexStrike AI to exploit critical vulnerabilities shortly after they are disclosed. Furthermore, AI systems are improving at malware creation, with weaponized models for ransomware and data-stealing code available for as little as $50 a month. While Chinese cyberspies have been observed using AI to automate many attack elements against high-profile companies and government organizations, fully autonomous end-to-end attacks have not yet been reported.Despite AI's growing role in aiding cybercriminals, fully autonomous, multi-stage attacks remain limited due to AI's current inability to reliably execute complex, long sequences without human intervention. Failures include executing irrelevant commands and an inability to recover from errors. This evolving landscape necessitates continuous vigilance and adaptation in cybersecurity strategies to counter both human-led and AI-assisted threats.Source: The Register
AI/ML
AI enhances cyberattacks, but full autonomy remains elusive
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
