Things have changed in the world of cybersecurity, but many companies haven’t noticed. Artificial intelligence (AI) is developing so quickly that typical security measures can’t keep up. We’re now in a time where AI is being used to attack the very systems we use every day.

If you’re in charge of IT, you know that stopping cyber threats is a never-ending battle. But new, powerful AI models have completely changed the game. It’s now cheaper and easier than ever to carry out complex cyberattacks.

Let’s look at the increase in AI-powered attacks, how hackers are using AI to discover software weaknesses, and what your IT security team needs to do to keep up.

How AI is discovering software weaknesses

To understand the scale of the threat, we first need to look at what AI is currently capable of achieving on the defensive side. A recent project offers a serious reality check.

As part of Project Glasswing, Anthropic  and its partners are working to test and improve the security of AI models and tools. The project aims to find and fix critical weaknesses in AI systems.This included uncovering severe bugs that had sat undetected for decades, completely missed by millions of automated security tests. That is not a human security team working overtime. That is AI doing in a few weeks what would normally take multiple lifetimes.

Anthropic’s goal is to make software more secure, but their results show a stark truth: AI has become so good at coding that it can find and use software flaws better than most human experts.

Making cyberattacks easier for everyone

That is the defensive side of the equation. Now consider what that same class of capability means when placed in the wrong hands.

Attackers do not need access to highly restricted models (although Anthropic is currently investigating a claim that an unauthorised party gained access to its unreleased Mythos model and used it to find and sell software vulnerabilities).

Instead, attackers take open-source AI models, strip out the safety guardrails, and fine-tune them on massive amounts of exploit data. They then use these altered models to find security holes and create ways to exploit them.

In the past, creating such complex attacks required nation-state resources and highly specialised knowledge. Now, well-funded criminal groups can do the same thing. They can create harmful code, run automated phishing scams, and find hidden ways into company networks faster and on a larger scale than ever before.

Why it’s getting harder to defend against attacks

The reality of modern cybersecurity is unsettling. Defenders are systematically slowed down by corporate red tape. Companies trying to protect themselves are often slowed down by their own rules and procedures, like getting approvals for changes or buying new software. These things take time.

Hackers don’t have these delays. They can change their tactics in hours.

On the other hand, it can take weeks for most companies to install important security updates, and that’s only if they know about the problem. As we’ve said before, patching vulnerabilities is a race against time. As soon as a software company announces a problem and releases a fix, criminals use AI to figure out the flaw and attack businesses that haven’t updated yet.

Data from the security company CrowdStrike shows that attackers are getting faster. They can now break into a network and start spreading in less than a minute. When hackers move that quickly, waiting weeks to update your systems leaves you wide open to attack.

Your company’s security weak spots are growing

The problem gets bigger when you think about how people work today. With more employees working from different places, company information often ends up on personal devices like phones and laptops that the company doesn’t manage.

As we outline in our guide on BYOD security in the age of AI, the rise of ‘Shadow AI’ creates massive blind spots. Employees might use public AI tools on their personal phones to do things like write down meeting notes or summarise secret company plans.

Hackers using their own AI tools are looking for these weak spots. They know that personal devices are often less secure, making them an easy way to get into your company’s entire network.

Protect the keys to your network

Hackers now use AI to automate their attacks, so they don’t have to force their way through your main security wall (firewall). Instead, they can just log in like a regular user.

They use smart bots to guess passwords, find old and unused login details, and trick tired employees into approving login requests. They often go after special accounts, like those used by IT administrators.

This means that controlling who can access your systems is more important than ever. When it comes to access management, privileged access is the key to stopping cyber threats. Instead, use a ‘just-in-time’ system. This gives people special access only when they need it and for a short time. So, even if a hacker steals a password, it will be useless once the user’s session is over.

It’s also important to have a backup plan. Working with a data protection company like Veeam means that if an AI attack does get through, you’ll have safe, unchangeable copies of your data. This lets you get back to business quickly without having to pay a ransom.

Prepare for what’s next in cybersecurity

We are entering a new and unpredictable phase of digital security, and most companies aren’t ready. It’s no longer a question of if AI will be used against your business, but whether your defences can keep up with these new threats.

Protecting your business requires a major change in strategy. You need smart, automated systems that can match the speed of your opponents.

Leave A Comment

Subscribe to Receive the Latest Updates

Get our latest recommendations, advice and offers direct to your inbox.

We won’t share your details – but you can read more in our Privacy Policy.