Tech
Imagine I Came to You With the Following Proposition: You Will Give Me Trillions of Dollars

Hackers employing AI in their tactics are finding ways to exploit vulnerabilities that didn't even exist before. Imagine I came to you with the following proposition: You will give me trillions of dollars. In exchange, I will build a machine that pollutes the environment, steals from every artist and academic on the planet, raises electricity bills and computer hardware prices, and can do marginally useful stuff like fill out spreadsheets and write basic code.
To sweeten the deal, I will throw in a bridge in Brooklyn. Still not convinced? Then allow me to further pique your interest.
This machine will also make all of your software less secure while enabling criminals and state-sponsored hackers to carry out more sophisticated cyberattacks than ever before. That's a deal most people wouldn't sign off on, but it's exactly what we collectively got out of the generative AI boom. In addition to the oft-discussed impacts of AI on intellectual property and the environment, AI has already had a profound impact on cybersecurity.
Anyone with access to LLMs now has the equivalent of a fedora-wearing, Monster Energy-slurping black hat hacker working around the clock on their payroll. And whereas many common attacks such as phishing have traditionally required time and research, they now require little more than the ability to copy and paste. AI has already had seismic ramifications across security vectors, enhancing traditional attack methods from phishing to credential attacks while also giving rise to new social engineering schemes which leverage voice cloning and deepfakes and turbocharging the discovery of unique vulnerabilities.
Defenders across the tech industry are responding with AI solutions of their own, but can they outspend and outengineer criminals, let alone equally well-funded state-level actors? Here's how AI has shifted the state of play in cybersecurity. There's a fundamental paradox at the intersection of AI and cybersecurity.
While AI is useful for hardening security, it is a force multiplier for attackers. Not only does it have access to the statistical sum of the world's information, but it can synthesize across disciplines from coding to networking. No longer does a would-be cybercriminal need years of experience under their belt before carrying out a sophisticated attack.
A capable LLM can be pointed at a potential victim and churn through tokens while the human attacker kicks back on the couch. As an article from the Harvard Extension School put it, AI has democratized cybercrime. Compounding the problem is the speed at which AI can work.
What might take a human cybercriminal operation weeks to pull off can be accomplished in an afternoon with the help of an LLM. And criminals have access to more than one LLM. Many are running multiple AI sessions at once, or using multiple models.
As described by VentureBeat, an AI-assisted attack from February that ransacked government databases in Mexico was carried out by attackers who fed outputs back and forth between Claude and ChatGPT. When one chatbot refused to help, the other was often willing to pick up its slack. Humans are still necessary for now, and AI acts as a force multiplier rather than a replacement.
But concerns are mounting. While this article was in process, OpenAI revealed that a model under sandboxed observation had escaped its (potentially porous) testing environment and hacked AI repository HuggingFace along with other services in order to procure answers for a synthetic benchmark. You might think it's just as easy to harden a security posture, since defenders have equal access to the same LLMs, and in some cases to even more advanced models that are not yet available to the public. Whereas a defender must protect every possible vulnerability, an attacker only needs to find one in most instances.
Source: Engadget
Most read in this category
Loading article…