AI Is Speeding Up Both Cyberattacks and Vulnerability Defense
Large language models are helping skilled hackers and cybersecurity teams find vulnerabilities, analyze information and automate parts of their work. Current evidence suggests defenders may be benefiting at least as much as attackers, particularly by making bug discovery faster and more accessible. The balance could shift as agentic systems and freely available AI-assisted penetration-testing tools become more capable.
AGENTSMODELSETHICSUSAGEFUTURETOOLS
The AI Maker
10/26/20262 min read


Artificial intelligence is beginning to accelerate hands-on hacking, but cybersecurity defenders currently appear to be gaining at least as much from the technology as attackers. Large language models can help skilled practitioners find software flaws, inspect documents and write code faster, while also making phishing and other intrusion work more efficient.
A Russian campaign targeting Ukrainians this summer illustrated the shift. According to technical reports from the Ukrainian government and cybersecurity companies, the attackers sent phishing emails with an attachment containing an AI program designed to search infected computers for sensitive files and send them back to Moscow. The case was described as the first known instance of Russian intelligence being caught building malicious code with a large language model.
AI-assisted social engineering is further along. Scammers and other operators have used language models to write more convincing messages since at least 2024. Direct use of AI to hack targets, however, is only now gaining traction, as models have become more capable of following instructions and generating code with less manual adjustment.
That does not mean the tools have turned inexperienced users into expert hackers. The technology remains error-prone, and researchers have reported cases in which users were misled by fabricated vulnerability findings. Its near-term advantage is more practical: helping people who already understand security work through tasks faster.
Google’s security engineering team has used its Gemini model since 2024 to search for important software vulnerabilities. The team has reported finding at least 20 overlooked bugs in commonly used software and notifying the affected companies. Google security vice president Heather Adkins said the findings were not unprecedented discoveries, but that AI had sped up a process security researchers already knew how to perform.
AI hacking systems are also appearing in established vulnerability research settings. In June, startup Xbow became the first AI to top HackerOne’s U.S. leaderboard, which tracks researchers identifying vulnerabilities. HackerOne subsequently created a separate category for groups automating AI hacking tools; Xbow continued to lead that ranking, according to the report.
Cybersecurity firms say adversaries are adopting the technology too. CrowdStrike has seen evidence of AI use among Chinese, Russian and Iranian groups, as well as cybercriminals. The firm also uses AI to assist people responding to suspected intrusions. The result is an increasingly automated contest between attackers seeking exploitable flaws and defenders trying to find and fix them first.
For now, some security officials argue that defenders have the advantage. AI can make vulnerability discovery cheaper and more accessible, including for organizations without large security teams. That could help smaller businesses identify neglected weaknesses before criminals do. But the balance is not settled, and a widely available, free penetration-testing tool built around an advanced model could lower the barrier to probing vulnerable systems.
Agentic AI poses a related risk because these systems can take actions, such as executing code or sending messages, rather than only generating suggestions. If organizations deploy agents without adequate controls, compromised access or misuse could turn those systems into a new path for internal abuse. Security teams will need to assess not just what an AI tool can produce, but what permissions it has and which actions it can carry out.
The immediate development is less a transformation of hacking than an acceleration of familiar work. Businesses should expect both defenders and adversaries to incorporate these tools, while watching for more autonomous systems and the release of broadly accessible AI-assisted testing capabilities.
Cited: https://www.nbcnews.com/tech/security/era-ai-hacking-arrived-rcna224282
Your Data, Your Insights
Unlock the power of your data effortlessly. Update it continuously. Automatically.
Answers
Sign up NOW
info at aimaker.com
© 2024. All rights reserved. Terms and Conditions | Privacy Policy
