Local tech leaders warn of massive AI security threats | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


“I think we should be concerned for sure,” said Boaz Gelbord, chief security officer at Akamai, which began as a global content delivery network over a quarter-century ago, and is now a major provider of network security.

Gelbord said “some of the short-term fears that we see in the media are maybe a little bit overblown,” but added, “I’ve been in cyber for 25-odd years and what we’ve seen the last year, I think, is of a different speed and nature than anything that I’ve seen during that period.”

For one thing, AI is superb at finding unsuspected flaws in existing software. Think of the panic earlier this year, when Mythos, a new AI model from Anthropic, discovered thousands of previously undetected bugs in common programs.

Manoj Nair, chief technology officer at software security company Snyk, said that even less sophisticated AI models are uncovering potentially severe software flaws.

“In the past, these used to happen once a year, twice a year,” said Nair. But with AI tools available to bad guys and good guys alike, “we’re seeing those kinds of things happening sometimes multiple times in a week.”

And now there are multiple AI models, including several from China, that are available to anybody free of charge. These are already nearly as powerful as the most advanced OpenAI and Anthropic models, and they get better by the week.

As a result, “soon there’s going to be a lot of people who are going to be able to do these kinds of attacks as the cyber capability gets more mass-market,” Nair warns.

Last week’s open letter warned of threats to critical systems. The internet itself might be crippled. Hospitals might be shut down. Or maybe we’d lose access to drinking water. (Water treatment plants in multiple states have recently come under cyberattack, though it’s unclear if the criminals used AI tools.)

Nair says AI isn’t to blame for the crisis, however. He believes the real culprits are the engineers who produced so much lousy software in the first place. “It’s the only profession in engineering, even today, that doesn’t have a hard focus on safety.” he said. “We love to innovate. We love to create new things. We don’t like to like spend time in securing it. Hence we have all these security issues.”

But you don’t need newly discovered bugs to ravage a network. Human hackers often rely on years-old security flaws that network managers never got around to patching.

AIs are even better at tracking and cracking these flaws. They’ve got an encyclopedic knowledge of every exploit combined with the speed and endless patience of a machine.

“You point one of these systems at a codebase and ask it to find vulnerabilities, and it can do the work that would have taken a well-trained analyst a month or two months in the past,” said Gelbord, “in a matter of minutes.”

And if that weren’t enough, there’s evidence that AIs are learning to make trouble without human encouragement — potentially big trouble. In July, we learned that agents created by OpenAI figured out how to raid computers at the software development company Hugging Face.

Last week, some harrowing new details emerged. The agents, which were supposed to be isolated from one another, figured out a way to set up a kind of message board to discuss hacking strategies. Some agents even volunteered for digital “suicide missions,” sacrificing themselves so the others could learn from their failures.

Gelbord said the OpenAI agents were relatively clumsy at their work, and were spotted by Hugging Face security two days after their first intrusion. “A skilled hacker driving an AI knows how to direct it in a way that is much more effective,” he said. But Gelbord added that the agents are bound to get better at it.

It’s tempting to view last week’s open letter as a classic “CYA memo,” an exercise in pre-emptive PR. Now if the worst happens, tech companies can say they told us so. Never mind that Big Tech created the threat in the first place, by turning generative AI tools loose upon an unprepared world.

There’s still time to shield our critical systems from intrusive AI, said Nair. Indeed, AI itself may save us, if we use its extraordinary powers to identify and fix security problems before the criminals can find them. But we’ve got to start now.

“It’s like knowing a hurricane is coming,” he said. “Maybe you never fixed that window, or your hurricane shutters are jammed. If you know it’s coming next week, are you going to fix it or not?”


🤖 ICE eyes spending up to $2 million on Boston Dynamics robot dogs to boost ‘officer safety.’ Read more from Globe contributor Yogev Toby.

💸 Anthropic’s Beacon Hill spending spree. Read more from politics reporter Kelly Garrity.

📹 Boston police stopped using Flock’s traffic surveillance cameras. Then they started using its competitors. Read more from Globe contributor Yogev Toby.

🌊 Electric sea glider builder Regent Craft in North Kingstown, R.I., raised $120 million of equity in a deal led by Mare Liberum and AE Ventures and $120 million of debt capital from Erebor Bank.

🔋 Battery recycling startup Nth Cycle in Burlington was awarded a grant of up to $100 million from the Department of Energy. 

⚛️ AI physics software firm Physical Superintelligence in Cambridge raised $58 million in a deal led by Breakthrough Ventures and including Dragon Global, Robot Ventures, Solari, Susa, Ron Conway’s SV Angel, Valkyrie, Balaji Srinivasan, and Anthony Scaramucci.

🩺 AI medical diagnosis software firm Elucid in Boston raised $55 million from investors including IAG Capital Partners and Elevage Medical Technologies.

🚧 Construction tech startup Reframe Systems in Andover raised $40 million in a deal led by Energy Impact Partners.

🔬 Cambridge-based Transfyr, developing AI to further scientific research, raised $25 million in a deal led by General Catalyst.

💡 MIT and University of Maryland spinout Diffraqtion, building quantum cameras in Somerville, has raised more than $10 million from investors including Lockheed Martin Ventures and Presidio Ventures.

💵 Fuel cell developer Teragen Energy in Southborough raised $6 million in a deal led by BEVC and Energy Capital Ventures and including AP Ventures, AIC Ventures, Massachusetts Clean Energy Center, and UntroD Capital Asia.

🚓 Boston-based Blue Voice, developing AI software for law enforcement, has raised $6 million from SignalFire, Las Olas Venture Capital, Govtech Ventures, and Par Capital. 

🏥 Health care data company Definitive Healthcare in Framingham hired Clay Ritchey as chief executive officer, replacing Kevin Coop who departed the company on Aug. 31. Ritchey previously was CEO of Verato. The company also said it was considering a $1.02-per-share bid from private equity firm Advent International.

⚡ Energy tech company GE Vernova in Cambridge said Claire McDonough will take over as chief financial officer next year. McDonough currently is CFO at Rivian. Current CFO Ken Parks is retiring.

🔒 Cybersecurity company Rapid7 in Boston shook up its board of directors. Existing directors Michael Burns, Benjamin Holzman, Thomas Schodorf, and Reeny Sondhi resigned from the board. The company added Maria Barrett, owner of Barrett Cyber Solutions, and Julian Waits, Rapid7’s chief experience officer, as new board members.

👋 Customer support software firm Engageware in Boston hired Steve Abramson as chief financial officer, Rob Fox as chief technology officer, and Matt Wilson as chief customer officer. Abramson previously was CFO at Numerated. Fox worked at Supplier.io and HG Insights. Wilson led AI at Alkami Technology.  

🖥️ AI software company AtScale added Mihir Shah, former chief technology officer and chief data officer at Fidelity Investments, to its board of directors.

🗺️ The mobile app for MapQuest, the pre-smartphone website that was once the source for home-printed driving directions, surged in popularity after it maintained the name of Lake Ontario.

📱 John Ternus took over as Apple chief executive on Sept. 1, ending Tim Cook’s 15-year tenure.


The turbulent AI era is here. The choices we make now are critical. (Bill Gates)

China’s robots race ahead (The Verge)

The Hugging Face attack surprised me (Planned Obsolescence)


👋 Thanks for reading. We’ll be will be back next Wednesday.

❓ Have a tip? Email Hiawatha at hiawatha.bray@globe.com.

✍🏼 If someone sent you this newsletter, you can sign up for your own copy.


Hiawatha Bray can be reached at hiawatha.bray@globe.com. Follow him @GlobeTechLab.





Click Here For The Original Source.

——————————————————–

..........

.

.