Cybersecurity Awareness Month spotlights AI risks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


CYBERSECURITY Awareness Month this October is prompting security experts to broaden traditional advice on passwords, phishing and access as artificial intelligence creates new risks involving digital identities, privileged access and synthetic media.

Three cybersecurity leaders from Keeper Security — CEO and Co-founder Darren Guccione, Senior Vice President of Strategy for Identity Security Michael Marino, and cybersecurity expert Anne Cutler — highlighted evolving threats and the need to adapt cybersecurity practices.

Guccione said organizations deploying AI agents must treat them as digital identities subject to the same security controls applied to human users.

“AI agents can now authenticate into systems, retrieve sensitive information, interact with applications, execute workflows and make critical decisions – all at machine speed,” Guccione said.

“If an agent has credentials and permissions, it represents an identity, and every identity creates risk when its access is excessive, persistent or poorly monitored,” he said.

Get the latest news


delivered to your inbox

Sign up for The Manila Times newsletters

By signing up with an email address, I acknowledge that I have read and agree to the Terms of Service and Privacy Policy.

He said organizations should apply zero-trust principles to AI agents, including least-privilege access, continuous monitoring and protection and rotation of credentials and secrets.

“The next frontier of cybersecurity awareness is recognizing that AI agents are users too,” Guccione said.

Marino said the expansion of cloud, hybrid and remote environments has also changed the role of privileged access management, or PAM.

“Modern PAM, therefore, has to be about much more than protecting passwords,” Marino said. “It must control when privileged access is granted, what someone or something can access and what happens during that session.”

He said principles such as least privilege, just-in-time access and zero standing privilege can replace persistent administrative rights with access that is temporary and auditable.

Cutler, meanwhile, pointed to the growing use of AI-generated deepfakes in social engineering attacks.

“Deepfakes are increasingly relevant to personal cybersecurity because the same technology used for entertainment can be weaponized by cybercriminals to impersonate other people, manipulate trust and steal sensitive information,” Cutler said.

She urged users to verify unusual or urgent requests through another trusted channel, particularly when the request involves money, passwords or multifactor authentication codes.

“A familiar face or voice should no longer be treated as proof of identity,” Cutler said.

The three perspectives underscore the need for Cybersecurity Awareness Month to evolve alongside emerging technologies, with attention extending from human users and credentials to AI agents, privileged access and synthetic media.

——————————————————-


Click Here For The Original Source.