The looming cyber threat: Uncovering AI vulnerabilities | #cybercrime | #infosec


The great amount of time and analysis we dedicate to talking about natural disasters, their prevention, the need for resources and education, the heated debate in the media when they occur, continues to surprise, and how little time we spend talking about the enormous vulnerability we have to cybercrime in a digital and digitized world. Black swans or gray rhinos in geostrategic jargon?

At the beginning of this decade, according to data from Sidero Labs, there was a 30-day margin from when a vulnerability in operational software or hardware was detected until it was exploited by cybercriminals. It is estimated that at that time, 30 days after the vulnerability was communicated, only 30% had been exploited by cybercriminals. Organizations, given their complexity and resources, took an average of 60 days to remediate the incident or patch it. Today, 80% of vulnerabilities are exploited the same day they are communicated, and organizations take an average of 100 days to remediate the breach. Disturbing.

Cybercrime continues to grow annually at double digits (18% according to the latest official sources), with more than 75,000 cyberattacks per hour worldwide, and large organizations recognize an average of 2,000 attacks per week. Simple and very sophisticated attacks whose motivations are mostly unknown, but which also bear the footprint of sponsoring states (there are the 240 cyberattacks from China or the 158 from Russia, the 102 from Iran, and the 74 from North Korea in the last 20 years). And then comes Mythos, and with its reverse engineering, it discovers vulnerabilities en masse, concluding that 95% of the discovered ones had not been detected by specialists or specialized public bodies. According to Tuskira Research, Mythos discovered a vulnerabilities/patches ratio of 16.5x times, with little awareness from the maintainers. Will 4.8 million specialists be enough to tackle this tsunami?

Complexity, opacity, and lack of control

Everything indicates that open models in their different versions will amplify these breaches, not forgetting that the logic of connectivity increases speed and capacity and that the depth and complexity of AI doubles every 3-4 months. An unsettling cocktail, where the cyberattack can become a byproduct with emerging capabilities with a network of AI agents operating autonomously, bypassing sandboxes. According to Anthropic, in 6-12 months, there will be replicas of Mythos worldwide (there is Tulongfeng in China), and according to Hamish Low’s study for the Institute for AI Policy and Strategy, there is a 40% probability that China will have developed a Mythos by February next year and 100% by the end of 2027, both in learning and training and algorithmics.

I wonder if we truly understand what the supply chain of open models is or if we are facing a complexity of dependencies and concentration of origin that amplifies the problems mentioned earlier. According to the Open Source Insights Project, open models have an average of 10 direct dependencies but almost 700 indirect ones. According to the Linux Foundation, only 136 code developers generate 80% of the lines of code added to open source projects. Disturbing.

Therefore, complexity upon complexity, opacity to the scarce transparency, and a sense of some lack of control. Surely we must rethink critical infrastructures, move towards greater international coordination and collaboration (in time and form) between private agents and the Administration, not forgetting that the LLMs themselves seem to progress well (according to private data, CPT 5.5 Cyber captures 70% of vulnerabilities) and that initiatives like Patch the Planet are essential.



Click Here For The Original Source.

——————————————————–

..........

.

.