If you're not using AI to attack your own systems, your adversaries will
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks.
They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions.
As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse.
They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies.
“There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register.
“As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said.
“One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added.
“AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said.
“We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance.
That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added.
“Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files.
All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives.
It also presents a security use case for defenders: agentic red teaming.
As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.