Frontier AI tipping the scales toward cyber adversaries | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


NEW YORK – The advanced use of AI has created a generational shift in the balance between the ability to protect information and the risk of those systems being compromised, according to researchers at Palo Alto Networks (PAN). 

The cybersecurity firm, which has conducted extensive research on the use of frontier AI, opened a window into those findings in a Wednesday media briefing here. After months of participation in Anthropic’s Project Glasswing and OpenAI’s Daybreak program, PAN security testers were able to discover the volume of security vulnerabilities that would normally take a year to unearth. The danger is that a malicious actor with these same capabilities could weaponize the security flaws at a speed at which most modern security defenses cannot compete. 

A lone threat actor armed with such AI can engage in sophisticated, nation-state-level or criminal capabilities without the need for extensive training or experience, according to Sherrod DeGrippo, VP threat intelligence at Palo Alto Networks’ Unit 42. 

AI-enabled attack window narrows

PAN’s Unit 42 was among the first cybersecurity firms to get a bird’s-eye view of how frontier AI had changed the security landscape. Nation-state and criminal threat groups had already begun to incorporate artificial intelligence into their toolkits in prior years, but these new models raised the stakes to such a new level that only a few organizations were able to see these capabilities under a more controlled environment. 

In May, PAN warned of a three- to five-month window before adversaries would begin to exploit vulnerabilities at speeds that have never been seen before. More than three months later, the researchers now say those expectations are about to be realized, and security leaders need to prepare for this new threat landscape. 

“Here we are, five months, in and we’re starting to see the wave of this coming now,” said Sam Rubin, senior vice president of Unit 42 Consulting and Threat Intelligence at PAN, during the media presentation. 

The researchers currently are investigating an incident where an adversary was able to use AI to exploit 50 different vulnerabilities and attack paths in the space of 10 hours. The hacker gained initial access, moved laterally within the organization, escalated privileges and stole information. 

That level of activity would normally take two weeks for human actors to accomplish, according to Rubin. 

Palo Alto Networks was among a group of 100 security and technology companies to sign a recent open letter calling for immediate action to protect against the threat of weaponized AI. 

——————————————————-


Click Here For The Original Source.