If you aren’t utilizing AI on your own systems, others certainly will – GadgetLad

AI: A Two-Edged Sword

AI agents are demonstrating their prowess in hacking, as evidenced by recent real-world attacks. They are not only creating an entirely new attack surface but also welcoming a myriad of data-integration channels that can be exploited by troublesome attackers. They bring forth a novel form of non-human identity that’s as challenging to manage as juggling gelatin.

Perils of Agentic AI

“Agentic AI and machine identities are quite a nuisance,” stated Matt Hartman, the former top executive at the US Cybersecurity and Infrastructure Security Agency (CISA), during a conversation with GadgetLad. He believes AI agents are likely to access sensitive systems and data. “Organizations should treat every agent as if they’re royalty,” Hartman mentioned. These threats enriched with AI aren’t solely internal; they are also breaching from external sources.

Attacks Powered by AI

AI-driven mischief-makers are emerging, and Hartman suggests that these AI-enhanced identity and social engineering attacks are increasing. Tailored phishing, effective impersonation, and automated surveillance are rendering trust indicators as valuable as a chocolate kettle.

Red Team Your Own Defense

The Wave of AI Bots

AI attackers are unyielding, seeking out vulnerabilities, mapping networks, and sifting through files like a terrier in pursuit of a squirrel. For the villains, these bots are a dream come true. Rob Joyce from the NSA recommends giving your systems a thorough battering with AI agents before someone else does it for you.

The Expanding Market for Automated Red Team Exercises

You can either invest in a red-team session or receive it at no cost, but the outcome remains uncertain. Hartman indicates that the market is flourishing for ongoing, AI-driven, automated pokes and probes. It’s no longer child’s play; AI identifies vulnerabilities in an instant.

Mandiant’s Powerful AI Assault Swarm

Armadin’s Record-Setting Attack

Kevin Mandia’s latest venture, Armadin, debuted in March with a neat $190 million. They construct attack swarms comprising thousands of AI agents to rigorously test your infrastructure. Prior to Black Hat, Armadin and Tenex.ai executed the largest controlled AI cyberattack to date.

AI Agents and Zero-Day Exploits

Their swarm executed 17 million offensive actions, identified 38 attack pathways, and generated numerous security findings over a three-day period. Armadin’s AI agents are dismantling networks continuously, uncovering top-tier zero-days.

Quarterly Pen-Testing is Outdated

The Demand for Speed and Range

The villains are leveraging AI to rapidly identify potential targets, and traditional penetration testing needs to catch up. Jay Bavisi from EC-Council asserts that conducting pen-testing once a year for compliance is passé. AI is stepping in for automated pen-testing.

The Importance of Human Pen-Testers

However, pen-testers will not be out of work. They are transforming into something more substantial and effective. There’s more to infiltrate now, and humans need to assess the business ramifications and determine solutions. AI systems are essential to organizations, and pen-testers must excel at testing them.

Conclusion: Closing with Impact

So, that’s the situation, everyone. The landscape of pen-testing and AI is evolving quicker than a whippet on energy drinks. Maintain your systems, red-team yourself exhaustively, and don’t let the bots outmaneuver you. And keep in mind, if you’re not challenging your own systems with AI, others will be. Visit gadgetlad.co.uk for further tech insights and antics.