待翻譯:How AI-armed script kiddies will soon wield the power of state-sponsored threat actors
AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:Low-skill hacktivists are now 'enabled with the same tooling and sophistication as a state-sponsored group,' according to cybersecurity consultant Unit 42.
AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。
Follow ZDNET: Add us as a preferred source on Google.ZDNET's key takeawaysAI has created a permanent "generational shift" in cybersecurity. This shift includes how we classify threats, with hacktivism predicted to take center stage. Low-threat script kiddies may be a thing of the past, as AI changes the conversation.Can you imagine a future when script kiddies -- low- or no-skill wannabe hackers who use prewritten scripts or tools to cause havoc -- can shake the foundations of cyberdefense?According to Palo Alto Networks' Unit 42 research team, that's a "probable" scenario.In a briefing on Wednesday, Unit 42 discussed early findings from its new service, Frontier AI Defense. Launched in April, Unit 42's service combines threat intelligence, threat telemetry, and frontier AI models to help enterprise clients address security issues that have become urgent due to AI.Also: A low-tech solution from the past may be your best defense against AI deepfakesThe team says that in three weeks of internal tests, Unit 42 completed the equivalent of about one or two years of penetration testing, uncovering dozens of vulnerabilities across customer environments using AI pen-testing models.If we consider this result and how the speed of AI-based vulnerability discovery and testing can be applied, we can also understand just how much impact AI models could have for cybercriminals using the same tools for their own malicious ends. We're not just talking about skilled, well-funded cybercriminals, either.Script kiddies go nation-stateWhen we consider cyberattacks today, we tend to organize them into two main categories: cyberattacks driven by financial goals, or attacks carried out by state-sponsored threat actors, who may seek information, disrupt or destroy, or conduct surveillance.There are smaller categories, too, such as hacktivists and those who commit malicious actions for social or political reasons. According to Unit 42, it's the sudden AI-enabled power boost for these individuals that we need to watch. In the briefing, Sherrod DeGrippo, VP Threat Intelligence at Unit 42, said that the traditional categories of cyberattacks have shifted, and that socially motivated groups are being "enabled with the same tooling and sophistication as a state-sponsored group" due to artificial intelligence.Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expected"This part of the landscape will continue to increase and bring in low-skilled actors that now have exponentially bigger and better capabilities than we've seen before," DeGrippo commented. "These are people who know how to use a tool -- and we've given them incredible tools."In the past, most script kiddies and hacktivists -- lacking an adequate understanding of the underlying technology or programming languages to modify digital weapons for their specific goals -- have relied on others' tools, scripts, and programs. Now, with the backing of AI to run analyses, reverse-engineer, or even develop tools for them (if the right guardrails aren't in place), these lower-skilled groups have far more at their disposal without the need to upskill. How is AI making such an impact?Unit 42 calls AI a "force multiplier" that is changing how cybersecurity operates. While we've seen threat actors experimenting with AI and large language models (LLMs) piece by piece in the attack chain -- such as improving phishing campaigns, translating language, or assisting with ransomware negotiations -- AI is now being used across the entire process. An example is JadePuffer, which is believed to be a fully agentic ransomware attack, with every stage handled by AI from beginning to end. Also: The best and worst AI for your privacy, ranked - and how each handles your dataAccording to Sam Rubin, SVP of Consulting and Threat Intelligence at Unit 42, there has been a "relative balance between the security and compromise of our information," but now, "AI is breaking that balance."The elements of a cyberattack, from discovering vulnerabilities to developing malware or conducting social engineering, used to require manual execution. But now, AI can take over many of these tasks -- which gives cybercriminals "the time and energy back to be more effective," according to Rubin.There's also the matter of speed. During the cybersecurity firm's work on its new service, the team found that AI could be used to identify and exploit vulnerabilities, escalate privileges, and steal data all within 10 hours in an operation that would normally take a penetration testing team around two weeks. Anonymous hacktivism 2.0We asked DeGrippo if she could see a future in which old-school hacktivism, like Anonymous, makes a resurgence powered by AI -- and whether this is something defenders and organizations should be concerned about.According to the executive, "it's absolutely possible" as "AI is enabling individuals in ways that they have never been enabled before."Also: Why enterprise AI agents could become the ultimate insider threatThere's also the prospect that attribution will become far more difficult in the future, as AI and open access to associated tools will make identifying who is responsible for attacks and their origins even more challenging for defenders. "[AI] is opening up the landscape to the groups that haven't been that much of a concern," DeGrippo says. "Individuals who have a vendetta against previous employers, a business they did business with and didn't get what they were promised -- now have the capabilities where they are well-enabled with tooling to carry out malicious activity if they want to. It's something to watch in the landscape, and it's probable." Are organizations prepared?There's only so much that can be prepared for, DeGrippo noted, as the impact of AI on cybersecurity threats and defense is constantly changing, and this "transformative period" is one we simply have to get through. Also: 5 security tactics your business can't get wrong in the age of AI - and why they're criticalAI threats have now become a board-level conversation, which is certainly a start. Best practices that organizations should consider adopting include:Implement a zero-trust architecture: Adopting a zero-trust model for access and identification, with a "need to access" mentality for user accounts across the entire network, can help reduce the risk of cybercriminals moving laterally or easily reaching sensitive corporate resources in the case of compromise. Educate and train employees: AI-driven cyber threats are constantly evolving, and we need to do more than an annual exercise in spotting phishing and scams. Invest in improving employee awareness, as the human factor in defense is often the weakest one. Monitor and regulate employee AI use: AI can be an entry point to your network and a means for sensitive information to be shared without permission. So-called shadow AI, when AI use is unsanctioned, can lead to security and compliance issues. Collaborate with AI and cybersecurity experts: Few of us can keep up with the risks AI poses to organizations, and existing cybersecurity solutions may not protect against what is coming. Now might be the time to consider investing in specialized platforms or partnering with experienced professionals in the space to improve your organization's security posture. "None of us are prepared for what is constantly evolving," DeGrippo added. "CISOs need to think about what their agentic AI strategy is, top to bottom. They have to develop a strategy and then be willing to adapt. Organizations aren't ready but are doing what they can to get there."