Security11:20 · 46m ago

AI Enables Scalable Cyberattacks by Repeating Known Exploits Across Multiple Systems

Calcalist
Translated & summarized from Calcalist by baba
The story · English

Recent reports often depict AI-driven cyberattacks as highly sophisticated tools that discover novel vulnerabilities or bypass defenses in ingenious ways. However, the more immediate and silent threat lies in AI's ability to repeatedly apply the same attack method across a wide range of systems. Once attackers understand why a particular technique works, AI systems can autonomously search for similar conditions in other targets, adapt their testing to different environments, and persist even after failures.

A study conducted on Android applications simulated real attacker behavior, initially identifying seven vulnerabilities manually. After defining the common conditions causing these flaws, the AI tool scanned 20 additional apps, uncovering five more related vulnerabilities and a separate critical flaw enabling account takeover. Despite variations in code, interfaces, and permissions across apps, the AI adapted its approach rather than blindly repeating commands.

Unlike fixed-rule scripts, AI systems can modify their testing based on ongoing findings, enabling them to operate across many systems without continuous human oversight. This adaptability allows AI agents to perform complex sequences repeatedly, as demonstrated in another study involving the open-source conference management platform Pretalx, where AI submitted fake talk proposals and awaited predictable organizer responses to exploit vulnerabilities.

Attackers do not need to succeed in most attempts; a single success suffices. As the cost per attempt decreases with automation, AI-driven attacks can target numerous systems without additional manpower or pre-selecting only promising targets. Organizations, meanwhile, must protect numerous applications, APIs, permissions, and evolving business processes. Periodic penetration tests offer only snapshots in time, while attackers continuously probe for new weaknesses as systems change.

The fundamental shift AI brings to cybersecurity is not replacing experts but drastically shortening the time between discovering a vulnerability and exploiting it at scale. An attack method requiring human creativity and effort to develop can be repeatedly tested across many systems at low cost. The threat emerges when a single idea can be amplified beyond the reach of individual attackers or small groups, challenging defenses that update only sporadically.

Ido Gefen, co-founder and CEO of cybersecurity firm Novee Security, emphasizes that AI's power lies in its consistency and scalability rather than brilliance.

Read the original at Calcalist
Full coverage · 1 outlets
First: Calcalist · 46m ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal