"Keep going, bro. You've got this!" A data-driven look at how adversaries are weaponizing AI
Cisco Talos Blog ● Covered by 39 sources
Cisco Talos analyzed artifacts from cloud-based AI models and found threat actors using them for three main purposes: writing malicious code, scaling criminal operations, and accelerating vulnerability research. Key findings show guardrails provide minimal protection, with most actors bypassing them through simple claims of ownership or false bug-bounty framing rather than sophisticated techniques. Threat actors now have AI-augmented capabilities for faster exploitation and larger-scale attacks, requiring defenders to deploy AI agents in security operations to handle the increased volume of vulnerabilities and incidents.
Why it matters
Adversaries are increasingly using AI for their malicious activities, using it for software development, scaling operations, and vulnerability research. The effectiveness of AI in these scenarios heavily depends on the user's expertise, with novice actors creating basic malicious tools while advanced users produce sophisticated outputs and automate complex processes.