SyncAI.news, a Varaisys broadcasting
Sound The Alarm And Rally The Troops: The Risk Of AI Hacking Your Company Is Real
SS

Srinivas Shekar, Forbes Councils Member

· 1 min read

World NewsForbes: Innovation

Sound The Alarm And Rally The Troops: The Risk Of AI Hacking Your Company Is Real

Srinivas Shekar, Founder and CEO, Pantherun Technologies.

​If you knew that your critical operations and data security methods were infested with vulnerabilities that hackers could exploit in as little as one day, you would sound the alarm and rally all hands on deck to do something about it, wouldn’t you?

Well, I’m afraid that’s exactly what’s being faced. Not “maybe, someday,” but “very likely soon.”

While the problem is probably more severe and urgent than you think, there are steps you can take to mitigate your exposure.

Welcome to the bugmageddon.

We all remember when Anthropic previewed its Mythos model to a select group of large enterprises, cybersecurity organizations and government departments. Right out of the gate, the AI model discovered some 23,000 cybersecurity vulnerabilities across 1,000 open source projects, with over 6,000 of the bugs considered severe. Many of these bugs sat undetected for years or even decades.

Given how widely open-source components are used in commercial codebases, few organizations can assume they are insulated from this risk.​ And according to Sergej Epp of security platform Sysdig, the average time between a bug’s public disclosure and an attack today is just 24 hours.

The implications of this are so severe that the Wall Street Journal dubbed the discovery “bugmageddon.” And while some aspects of Mythos were put on ice to let companies beef up their defensive posture, AI is not going to stop advancing, nor is the problem of malicious bug discovery going to go away.

Of key concern here is that AI increasingly has the capability to analyze how combinations of individually discovered vulnerabilities may be used together as “building blocks” to form a complete attack path. “Bug 1” could be used to gain initial access, for example. “Bug 2” could be used to steal credentials. “Bug 3” could be used to escalate privileges, and so on, until the AI hacker’s objectives are met.

Now, it would appear that the bugmaggedon is in full swing.

Original source

This story was published by Forbes: Innovation and written by Srinivas Shekar, Forbes Councils Member. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on forbes.com

Similar News