Security11:20 · 45m ago

AI Enables Scalable Cyberattacks by Repeating Known Exploits Across Systems

Calcalist
Translated & summarized from Calcalist by baba
The story · English

Recent reports on AI-driven cyberattacks often depict highly sophisticated tools that discover hidden vulnerabilities or bypass defenses in novel ways. However, the more immediate threat lies in AI's ability to repeatedly apply the same attack method across many systems, adapting to differences without needing to invent new exploits. Once attackers understand why a particular technique works, AI can identify similar conditions in other targets, tailor its approach, and persist despite failures.

In research conducted on Android applications simulating real attacker behavior, seven vulnerabilities were initially found manually. After identifying common conditions, the AI system scanned 20 apps and uncovered five additional related vulnerabilities plus a separate flaw allowing account takeover. Despite variations in code, interfaces, and permissions, the AI adapted its testing dynamically rather than rerunning fixed commands.

Unlike scripted tools, AI systems can modify their attack strategies based on intermediate findings and context, enabling them to test many systems autonomously without human oversight for each attempt. This capability allows AI agents to perform complex sequences repeatedly and simultaneously across multiple targets, as demonstrated in another study involving the Pretalx conference management platform, where AI submitted fake talk proposals and awaited organizer actions to trigger vulnerabilities.

Attackers do not need to succeed in most attempts; a single success suffices. As the cost per attempt decreases, automated systems can try the same exploit broadly without extra manpower or preselecting promising targets. Meanwhile, organizations must protect numerous applications, APIs, permissions, and evolving business processes. Periodic penetration tests provide only snapshots of security at a moment in time, while attackers continuously probe for new weaknesses introduced by code changes or permission updates.

The fundamental shift AI brings to cybersecurity is not replacing experts but drastically accelerating the scale and frequency of attacks based on a single discovered vulnerability. This expansion challenges traditional defenses that update infrequently. Idan Gefen, co-founder and CEO of Novee Security, emphasizes that the threat begins when one person's idea can be exploited at a scale previously impossible for individuals or small groups.

Read the original at Calcalist
Full coverage · 1 outlets
First: Calcalist · 45m ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal