AI and Cybersecurity Set New Records

You may be feeling AI news fatigue lately with all the reports this month of one AI engine autonomously attacking another. That’s a big deal, but the last 45 days brought two other important news stories that also deserve big headlines, and you need to understand how they weave together.

First, at the end of June, the Five Eyes (FVEY) intelligence-sharing alliance, consisting of the United States, the United Kingdom, Canada, Australia, and New Zealand, warned that we are “months away” from AI causing catastrophic damage to systems running old and unsupported software.

Then, the month of July broke the all-time record for the number of security patches released by Microsoft. This is the second month this year to break the record. Over 570 security holes were addressed this month.

The reason for all this excitement is that AI is now finding vulnerabilities in software, hardware systems, and cloud services at a record pace. People are using AI to inventory and exploit these vulnerabilities just as quickly. There are two key take-aways:

  • Aggressive Patching is Mandatory: When a patch is released, it needs to be installed as soon as possible—for real. If you’re running old software or hardware that isn’t patched or can no longer be patched, you’ve always been vulnerable, but now you’re vulnerable to more people, more of their AI systems, and in more ways than ever previously possible—nearly in real-time. It’s not an exaggeration to say that AI now requires us all to take a much more aggressive approach to patching modern software and retiring unsupported systems.

  • Attacks Move at Machine-Speed: AI can now run reconnaissance, plot vulnerabilities, steal credentials, and launch attacks continuously. The window of time between initial compromise and payload delivery used to be measured in months or days, but more and more successful attacks are now being measured in minutes. Services like Pegasus Technologies AI Automation relied on human defenders in our Security Operations Center (SOC) to notice these unusual patterns and stop them before they had time to deploy their payload. Over the past year we’ve been making more and more use of automation and AI to meet attackers at machine-speed. AI certainly doesn’t replace the humans in our SOC, but what was once a tool for efficiency is now a required tool so AI can fight AI. It may sound futuristic, but this is our reality as we proactively work to keep our clients safe.

The cybersecurity battlefield continues to advance at a record pace. We’re here if you have any questions or concerns, but know we are doing our best to stay informed and bring you the latest cybersecurity defenses available.