In 2023, artificial intelligence (AI) demonstrated its double-edged-sword effect on cybersecurity, as organizations were able to use the technology to bolster their cyber defenses, while threat actors increasingly explored ways to use generative AI (genAI) and large language models (LLMs) to refine and escalate their campaigns.
“During 2023 we saw tremendous advancement in generative AI, a technology that has the power to reshape the security industry,” Vasu Jakkal, CVP of Microsoft security, told SDxCentral in an email.
The year 2024 is expected to be another pivotal year for the use of AI in cybersecurity. Google Cloud CISO Phil Venables expects AI’s benefits and capabilities to surge in 2024 as cyber defenders own the technology and thus direct its development with specific use cases in mind.
“On the other hand, while our frontline investigators saw very limited use of attackers using AI in 2023, in 2024 we expect attackers to use generative AI and LLMs to personalize and slowly scale their campaigns,” he noted.
As a result, this new year in cybersecurity will be characterized by a race between defenders and attackers in the realm of AI. Here are some predictions sent to SDxCentral by security vendors.
How adversaries might use AIWendi Whitmore, SVP and head of Unit 42 at Palo Alto Networks: The rise of AI-enabled social engineering will destabilize politics and disrupt business. We will see attackers leverage AI tools with greater sophistication and scale to create social engineering content that will target global elections, especially with the presidential election in the U.S. on the horizon, and cause political friction on a global scale. We also expect to see this within organizations as AI-enabled social engineering tactics become harder to detect, therefore increasing our reliance on advanced detection capabilities to bridge the gap.
Chris Scott, managing partner of Unit 42 at Palo Alto Networks: Adversaries will seed disinformation by manipulating LLMs. The tools of the AI revolution are fueled by the power of LLMs. Adversaries will look for opportunities to seed disinformation and distrust by manipulating the data that underpins them.
Elia Zaitsev, CTO at CrowdStrike: AI blind spots open the door to new corporate risks. In 2024, CrowdStrike expects that threat actors will shift their attention to AI systems as the newest threat vector to target organizations, through vulnerabilities in sanctioned AI deployments and blind spots from employees’ unsanctioned use of AI tools.
After a year of explosive growth in AI use cases and adoption, security teams are still in the early stages of understanding the threat models around their AI deployments and tracking unsanctioned AI tools that have been introduced to their environments by employees. These blind spots and new technologies open the door to threat actors eager to infiltrate corporate networks or access sensitive data.
Ian Pratt, global head of security for personal systems at HP: Beyond phishing, the rise of LLMs will make the endpoint a prime target for cybercriminals in 2024. One of the big trends we expect to see in 2024 is a surge in use of generative AI to make phishing lures much harder to detect, leading to more endpoint compromise.
Beyond this, we will see a rise in “AI PCs,” which will revolutionize how people interact with their endpoint devices. With advanced compute power, AI PCs will enable the use of “local LLMs” – smaller LLMs running on-device, enabling users to leverage AI capabilities independently from the internet. These local LLMs are designed to better understand the individual user’s world, acting as personalized assistants. But as devices gather vast amounts of sensitive user data, endpoints will be a higher risk target for threat actors.
As many organizations rush to use LLMs for their chatbots to boost convenience, they open themselves up to users abusing chatbots to access data they previously wouldn’t have been able to. Threat actors will be able to socially engineer corporate LLMs with targeted prompts to trick them into overriding their controls and giving up sensitive information – leading to data breaches.
Bar Kaduri, research team leader at Orca Security: Attacks on cloud-based AI platforms. Cloud-based AI platforms such as Amazon SageMaker, Google Cloud Vertex AI and Azure OpenAI Service have become indispensable tools for organizations aiming to leverage the power of artificial intelligence technology. Like any cloud-based asset, there are potential security risks. Some of these risks are brand new, such as model data poisoning, in which a malicious actor intentionally feeds wrong or inappropriate data to the model to tamper with its training process and cause it to provide falsified information.
However, other risks are derived from the fact that an AI model is a service running code and interacting with consumers and developers. Considering this fact, AI platform users can expect security risks coming from theft of sensitive data, unauthorized access to code, denial of service attacks and output abuse.
Steve Grobman, CTO at McAfee: Move over memes — AI scams will be the new, sneaky stars of social media. Heading into 2024, AI will help cybercriminals manipulate social media and shape public opinion like never before. Powerful, AI-powered tools will help these bad actors fabricate photos, videos, and audio – and unfortunately, these well-crafted fakes are social media goldmines. People should brace for celebrity and influencer names and images being used by cybercrooks to endorse scams, and local online marketplaces that could become hotspots for AI-driven trickery.
Max Heinemeyer, chief product officer at Darktrace: AI will be further adopted by cyberattackers and we might see the first AI worm. 2023 has been the year where attackers test things like WormGPT and FraudGPT and adopt AI in their attack methodologies. 2024 will show how more advanced actors like APTs [advanced persistent threats], nation-state attackers and advanced ransomware gangs have started to adopt AI. The effect will be even faster, more scalable, more personalized and contextualized attacks with a reduced dwell time.
It could also be the year of attackers combining traditional worming ransomware — like WannaCry or notPetya — with more advanced, AI-driven automation to create an aggressive autonomous agent that has sophisticated, context-based decision-making capabilities.
AI’s impacts on the defender sideSam Curry, VP and CISO at Zscaler: Businesses will need to learn to hide their attack surface at a data level. The influx of generative AI tools such as ChatGPT has forced businesses to realize that if their data is available in the cloud/internet, then it can be used by generative AI and therefore competitors. If organizations want to avoid their [intellectual property] from getting utilized by gen AI tools then they will need to ensure their attack surface is now hidden on a data level rather than just at an application level.
Based on the rapid adoption of genAI tools, we predict businesses will accelerate their efforts to classify all their data into risk categories and implement proper security measures to prevent leakage of [intellectual property].
Steve Winterfeld, advisory CISO at Akamai: Machine learning (ML) and generative AI/LLM will not solve the talent crisis. While there will be some relief with the utilization of ML and generative AI, AI will not solve our talent crisis. In 2024, it will continue to be extremely difficult to find and retain the talent needed and identify workers with needed skills in new areas like securing data science. This will likely lead to partnerships with vendors for on-demand staffing or managed services for non-essential functions.
Robert (Bobby) Blumofe, CTO at Akamai: 2024 will be the year of AI security snake oil. The answer to generative AI-enhanced cyberattacks isn’t necessarily generative AI-enhanced security. That fact won’t stop startups from claiming that they have used genAI to create a security silver bullet. Organizations will be better served by avoiding the AI panic and ensuring security solutions help them optimize the security basics – identity, visibility, zero-trust access and microsegmentation.
Sridhar Muppidi, CTO at IBM security: Companies will restrict ChatGPT third-party AI tools due to security concerns. Generative AI and ChatGPT have risen to incredible levels of popularity, as 57% of American workers have tried ChatGPT. However, employees often share confidential information with these platforms, including sensitive details of projects, risking information they do not want public. With cyber incidents and vulnerabilities impacting ChatGPT, companies may be inadvertently putting information at risk, and so in 2024, companies will apply more policies that restrict the use of third-party AI tools.
Chris Holt, bug bounty program manager at Intel: AI will drive new legislation and government mandates for hackers to test new tech products. In July, the White House began eliciting agreements from major tech companies to facilitate third-party discovery and reporting of vulnerabilities in their AI systems.
Consider that just last year, the U.S. Department of Justice said it would no longer prosecute ethical hackers under the Computer Fraud and Abuse Act (CFAA). The calls for Safe Harbor clauses in our bounty program policies to protect ethical hackers from legal repercussions if they met set criteria began as far back as 2018. The industry went from “you should have a bug bounty program” to “you should collaborate with ethical hackers, without a looming threat of litigation” to “you should ask ethical hackers to review AI technology” in just a few years. Legislation around AI will continue transforming how companies work with security researchers and ethical hackers.
Brian Spanswick, CISO and CIO at Cohesity: As more companies implement generative AI, they will face a challenge similar to shadow IT, except shadow AI puts proprietary data in the public domain — representing a much greater risk. The challenge is not knowing what algorithms are being used, the data fueling them, and who is using those algorithms. CISOs and organizations will need to ensure transparency and control around the growing use of genAI.
Paul Martini, iboss CEO: The debate about whether AI will help or hinder security will play out live. Companies are leveraging AI to build more secure products and will begin using the technology to automate repeatable tasks, such as fixing SQL parameterization issues. At the same time, threat actors will also turn to AI, including through deepfake voice and video for social engineering, mass-produced phishing emails and writing malicious code.
Comments