Lead Machine Pink 160x1200

Lead Machine Pink 160x1200

iTWire TV 705x108notfunny

Tuesday, 31 October 2023 14:38

Generative AI: a disruptive force at the hands of cyber attackers

By Uri Dorot, Senior Security Solutions Lead, Radware
Uri Dorot, Senior Security Solutions Lead at Radware Uri Dorot, Senior Security Solutions Lead at Radware

COMPANY NEWS:  The introduction of publicly available Generative AI tools at the end of 2022 launched us into one of the biggest technological revolutions in human history.

Some claim that it is just as big or even bigger than the introduction of the internet, cellphones, smart phones and social media. The adoption and development rate of these new Generative AI technologies is like nothing we have seen before.

While there are many implications to this AI revolution, let’s focus on the cyber security world.

picture

*This image was generated using the AI text-to-image tool Mage

 Generative AI tools are designed to be masterful co-pilots. When it comes to ethical hackers or white hats, many already admit to relying on AI to automate tasks, analyse data, identify vulnerabilities, and more.

We can assume that black hats are using AI, too. Even though we can’t really survey black hats, there is evidence they are using AI to find vulnerabilities in applications and platforms, quickly run reconnaissance operations to find zero-day vulnerabilities, and analyze their data.

As generative AI chatbots digest every piece of data, their database grows exponentially and becomes more accurate. With that, they can be manipulated to expose vulnerabilities of applications, platforms, software, and security tools and mechanisms. They can even write code to bypass applications security layers.

When Generative AI finds its way into the wrong hands, it can be used for a variety of malicious purposes. These are just a few of ways bad actors can enlist AI as a co-pilot:

Phishing attacks: AI’s powerful editing capabilities make it a perfect co-pilot for generating phishing campaigns. AI can be used to generate well written, authentic looking emails, landing pages, URLs and text messages.

As a result, it opens the door for more non-English speaking malicious actors to get into the game. With the help of AI, for instance, it’s now much easier for them to generate more convincing, higher quality phishing attacks on a global scale.

Before AI, we could often spot a malicious landing page, email, or text message because of incorrect grammar or unusual wording. Now, it is much harder to tell the difference between legit and AI-generated fake content. With that in mind, we can expect to see not only more phishing campaigns in the future, but more successful ones.

Distribution of malicious code libraries: Generative AI can also be used as a co-pilot to speed up code development. However, my advice is to proceed with caution if you use AI Chat tools to download code libraries when building applications.

Bad actors are flooding AI databases with libraries of nefarious codes, spreading them across development environments. That’s why it’s especially important to carefully vet libraries by checking the creation date and download count before you use them.

Keep in mind that even libraries with a history of many downloads can be malicious. My strong recommendation is to avoid using AI tools altogether to download code libraries and packages. It simply is not worth the risk.

Smarter bots . . . many more: With the help of their AI co-pilots, ill-intended actors can now manipulate AI chats to easily build new advanced bot scripts,otherwise known as zero-day bots.

As if that is not enough, new AI chat tools have been designed specifically for nefarious purposes and made available on the dark web. The tools help hackers and fraudsters to generate new automated scripts for their malicious cyber purposes.

With the emergence of AI, we can expect that this bad bot situation is going to get worse. Today, 30% of internet traffic is driven by bad bots,a number that is certain to rise in the future.

The consequences? Standard bot protection tools will not be able to defend against the growing number and variety of these new AI-generated bot scripts. CAPTCHA might also see its demise as more sophisticated AI-generated bots circumvent traditional CAPTCHA challenges.

To protect organisations adequately, a new form of detection is needed, whether it be unique custom challenges, blockchain-based crypto challenges, new attestation and identity-based user validation services, or even AI-generated challenges for bot mitigation.

Generative AI tools in the wrong hands are a serious threat, which is why their use must be regulated properly. With an AI co-pilot, hackers become ten-fold smarter and faster. They can cut the time it takes to discover a vulnerability by 90% and come up with a new one any time an older one is patched.

Unfortunately, regulation lags behind technology. To fill this gap, security teams must deploy advanced application protection solutions that use behavioural algorithms to automatically detect and block zero-day attacks in real time before they materialise.

Read 1463 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




EXL AI IN ACTION VIRTUAL EVENT 20 MARCH 2025

Industry leaders are looking to transform their businesses and achieve measurable outcomes with AI.

As organisations across APAC navigate the complexities of AI adoption, this must-attend event brings together industry leaders, real-world demonstrations, and visionary panel discussions to bridge the gap between proof-of-concepts and enterprise-wide AI implementation.

Learn how to overcome common challenges in deploying AI at scale.​

Unlock cost savings, efficiency, and better customer experiences with AI.

Discover how industry expertise and data intelligence enable practical AI deployment.

Register for the event now!

REGISTER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown: img0

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments