Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left

AI is changing cybersecurity in quick and terrifying ways

Imagine I came to you with the following proposition: You will give me trillions of dollars. In exchange, I will build a machine that pollutes the environment, steals from every artist and academic oโ€ฆ

AI is changing cybersecurity in quick and terrifying ways
Engadget โ€” 7 August 2026
Text:
18 0 0

Imagine I came to you with the following proposition: You will give me trillions of dollars. In exchange, I will build a machine that pollutes the environment, steals from every artist and academic on the planet, raises electricity bills and computer hardware prices, and can do marginally useful stuff like fill out spreadsheets and write basic code. To sweeten the deal, I will throw in a bridge in Brooklyn. Still not convinced? Then allow me to further pique your interest. This machine will also make all of your software less secure while enabling criminals and state-sponsored hackers to carry out more sophisticated cyberattacks than ever before.

That's a deal most people wouldn't sign off on, but it's exactly what we collectively got out of the generative AI boom. In addition to the oft-discussed impacts of AI on intellectual property and the environment, AI has already had a profound impact on cybersecurity. Anyone with access to LLMs now has the equivalent of a fedora-wearing, Monster Energy-slurping black hat hacker working around the clock on their payroll. And whereas many common attacks such as phishing have traditionally required time and research, they now require little more than the ability to copy and paste.

AI has already had seismic ramifications across security vectors, enhancing traditional attack methods from phishing to credential attacks while also giving rise to new social engineering schemes which leverage voice cloning and deepfakes and turbocharging the discovery of unique vulnerabilities. Defenders across the tech industry are responding with AI solutions of their own, but can they outspend and outengineer criminals, let alone equally well-funded state-level actors? Here's how AI has shifted the state of play in cybersecurity.

There's a fundamental paradox at the intersection of AI and cybersecurity. While AI is useful for hardening security, it is a force multiplier for attackers. Not only does it have access to the statistical sum of the world's information, but it can synthesize across disciplines from coding to networking. No longer does a would-be cybercriminal need years of experience under their belt before carrying out a sophisticated attack. A capable LLM can be pointed at a potential victim and churn through tokens while the human attacker kicks back on the couch.ย As an article from the Harvard Extension School put it, "AI has democratized cybercrime."

Compounding the problem is the speed at which AI can work. What might take a human cybercriminal operation weeks to pull off can be accomplished in an afternoon with the help of an LLM. And criminals have access to more than one LLM. Many are running multiple AI sessions at once, or using multiple models. As described by VentureBeat , an AI-assisted attack from February that ransacked government databases in Mexico was carried out by attackers who fed outputs back and forth between Claude and ChatGPT. When one chatbot refused to help, the other was often willing to pick up its slack.

Humans are still necessary for now, and AI acts as a force multiplier rather than a replacement. But concerns are mounting. While this article was in process, OpenAI revealed that a model under sandboxed observation had escaped its (potentially porous) testing environment and hacked AI repository HuggingFace along with other services in order to procure answers for a synthetic benchmark.

You might think it's just as easy to harden a security posture, since defenders have equal access to the same LLMs, and in some cases to even more advanced models that are not yet available to the public. But cybersecurity is asymmetrical. Whereas a defender must protect every possible vulnerability, an attacker only needs to find one in most instances. This dynamic has created a proliferation of zero-day vulnerabilities โ€” security flaws that shipped with a piece of software and were secretly discovered by hackers. Flaws that AI models have proven adept at uncovering.

It's tempting to think of a hacker as someone who wears long black trench coats and types code at a million words per second, but more often it's someone sending out millions of scam emails until someone proves gullible enough to fork over credit card information. End users are almost always the weakest vulnerability to target.

Read Full Story at Engadget โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Hanwha Group and LG CNS tokenize trade receivables to enhanโ€ฆ
๐Ÿ’ป Technology
Hanwha Group and LG CNS tokenize trade receivables to enhance supply chain finance
CoinDesk ยท 14 days ago
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to โ€ฆ
๐Ÿ’ป Technology
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired ยท 9 days ago
Altra Running Promo Codes: 10% Off July 2026
๐Ÿ’ป Technology
Altra Running Promo Codes: 10% Off July 2026
Wired ยท 13 days ago
Hereโ€™s the biggest news you missed this weekend
๐ŸŒ World News
Hereโ€™s the biggest news you missed this weekend
NBC News ยท 14 days ago
Iran war live: Trilateral Mecca defence pact signed, as Horโ€ฆ
๐ŸŒ World News
Iran war live: Trilateral Mecca defence pact signed, as Hormuz deal looms
Al Jazeera ยท 2 days ago
Ghana's community service bill: A fix for the prison crisis?
๐ŸŒ World News
Ghana's community service bill: A fix for the prison crisis?
DW World ยท 14 days ago
Full view