
Extensive cyber capabilities of new AI models are compelling cybersecurity professionals to reconsider how we can reliably protect critical infrastructure, writes Dr Aybars Tuncdogan, Associate professor in digital innovation and information security at King’s College London
Earlier this year, Claude Mythos uncovered thousands of novel vulnerabilities – many of which were unknown even to the vendors themselves – and suggested that AI is now
a key component of cyber defence not only for organisations but also for states.
More recently, newer models went beyond discovering vulnerabilities; OpenAI’s model autonomously broke out of its sandbox environment and successfully hacked Hugging
Face’s production infrastructure. Similarly, during an experiment by Anthropic, Claude models compromised systems belonging to three external organisations.
Now, OpenAI and Anthropic are beginning to give selected organisations and security professionals access to these AI models. So far, discussion has focused primarily on – what these models are capable of, such as rapidly finding and exploiting vulnerabilities, and who should be given access to them.
However, an angle that has been mostly overlooked is that access to these models will also create certain security risks for the organisations and users themselves.
That said, it is important to note that I am not advising against the use of these cyber AI models – I believe these models will be a key component of an organisation’s cybersecurity posture from now on, and organisations should adopt this technology as fast as they can.
What I am raising here is that while access will decrease certain kinds of risks, it will also introduce new ones, and careful planning will be important to minimise undesirable outcomes.
Access to cyber AI will be a valuable target
The small group of organisations receiving access to cyber AI tools is being given some of the most powerful automated hacking tools we have available. In other words they are given tools that can hack (or make it possible to hack) many external systems.
Worse yet, some of the organisations explicitly eligible for such access are cybersecurity providers, which need to examine their clients’ systems for vulnerabilities. Thus, we cannot sufficiently mitigate this problem by restricting users to testing systems owned by their own organisation.
This also means that hacking these organisations – and thereby stealing their access to frontier models – could allow cybercriminals to find vulnerabilities in and attack other systems, potentially including complex corporate networks and critical infrastructure. The value of this access may make unusually costly methods worthwhile, including zero-day exploits, placing employees inside an organisation or recruiting or coercing existing insiders.
Therefore, organisations receiving this access have to take into account that – while testing their systems with these frontier models can visibly improve their cybersecurity – cybercriminals may also target the organisation or its individual members specifically to steal that access.
The victim’s AI can be used to map the attack path
Cybercriminals can abuse an organisation’s cyber AI access not only against others but also against itself.
In some cases, instead of trying to hack a complicated network, it might be sufficient to just steal the account – or even the browser cookie – of one of the users with access
to the cyber AI model and then use that to find ways to hack into the organisation or execute the hack autonomously. This is particularly powerful, as even guardrails constraining the use of the model to only one organisation would do little to prevent this type of attack.
Beyond this, access to the cyber AI can be particularly valuable for persistence. In other words, once the cybercriminals manage to hack into the network, they may abuse this access to find several other ways in, increasing the likelihood that they can return to the system even if they are ousted.
Organisations need to consider how accounts with access to cyber AI can be protected so that they cannot be easily stolen and perhaps cannot easily be identified or accessed even if cybercriminals gain high-level access to the network.
Insider threats will become more dangerous
Access to cyber AI models can also exacerbate insider threat issues. Insiders – even those without advanced technical skills – can use their positions to hack into the organisation or attack external systems.
This also gives insiders with access to cyber AI – or those who can obtain others’ access – information they can sell. In particular, vulnerabilities and attack paths identified by the system could be sold without the insider having to exploit them personally.
Overall, organisations need to adopt cyber AI models to defend themselves against sophisticated attacks by cybercriminals abusing AI technologies.
However, it is also important for them to remember that while utilising this new technology improves certain aspects of an organisation’s cybersecurity, it also introduces new risks elsewhere. Hence, organisations should plan for these new risks from the outset and treat access to cyber AI as an asset to be protected.
The post Cyber AI will protect critical infrastructure – and cybercriminals will try to steal it appeared first on Planning, Building & Construction Today.