Site navigation

Is AI’s Threat to Cyber Overblown?

Elizabeth Greenberg

,

ai cyber
While cyber criminal interest in AI is on the rise, this seems to be inline with the increased interest across wider society, a new cybersecurity threat report claims. 

AI’s potential threat to humanity often makes top headlines, but is it’s threat to cyber being overblown by sensationalist reports?

SecureWork‘s 2023 State of the Threat report revealed some interesting trends concerning the pernicious nature of cybercriminals and new avenues of exploitation, as well as vulnerability mitigation.

While the news has often focused on the use of AI and its potential to improve the scope, scale, and effectiveness of threat actors, SecureWork’s analysis found that most uses of AI in the cyber threat landscape appear to be rather elementary.

So is the AI-hype something cybersecurity experts really need to be concerned about?

Afterall, Gartner did place generative AI at the apex of its “peak of inflated expectations” hype cycle, staring down the sharp descent to the “trough of disillusion.”

According to SecureWork’s report, the most common use of ChatGPT, the most prolific publicly available AI chatbot, has been as lures in phishing emails or malicious sites.

These sites typically used typos to impersonate ChatGPT and trick users into following malicious links.

SecureWorks also found that while threat actors are leveraging ChatGPT to create malware to evade defences and generate malicious code, they company says that these are not quite as threatening as they sound.

These models are based on user inputs on statistical analysis of existing texts, and “do not currently demonstrate the creativity and ingenuity of human coders when finding novel ways to circumvent security controls and discover new vulnerabilities,” the report said.

Threat actors are also selling access to Telegram bots that are based on AI models, which can allow users to request malicious scripts or phishing emails, and even find illegal goods on the dark web.

These bots may expand the amount of threat actors who can bypass ChatGPT’s ethical guardrails, despite a minimal skill set.

WormGPT is an alarming advent of AI, essentially offering the same service at ChatGPT but without legal or ethical restructures. Threat actors with low skillsets can use this service to draft malicious code or access dark web materials.

While SecureWorks says this has yet to make a significant impact in the cybersphere, the rate of AI’s development could change things.


Recommended reading


Sub-forums focusing on AI and machine learning (ML) on popular hacking and threat actor forums have begun to arise, meaning new developments could be well on their way.

By mid-2023, however, the main uses of AI in terms of cyber were still on phishing and Telegram bots, according to SecureWork’s report.

But perhaps the main concern with the rise of AI is how it makes malicious methods more accessible to less highly skilled threat actors.

Further, AI is beginning to outsmart humans and AI, with recent studies showing that AI bots are unable to identify AI-generated phishing emails as malicious.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data