Urgent.News

What's breaking now, across thousands of outlets.

Tech

The ascent of autonomous attacks and the race to contain them

Autonomous AI attacks are accelerating, forcing businesses to rethink cyber defense, identity and resilience.

The ascent of autonomous attacks and the race to contain them

Cybersecurity risks have become a crucial concern for boardrooms, as demonstrated by the 2025 Jaguar Land Rover attack, which resulted in a £485 million loss after the company's profit from the previous year had been wiped out. This incident highlighted how swiftly a cyber intrusion can disrupt operations, impede production lines, and impact the entire supply chain.

With the advent of AI, attackers now possess the ability to automate various stages of their operations, such as target research, initial access, and malware development. Consequently, businesses are wrestling with a novel form of threat: autonomous attacks fueled by AI.

As AI-driven automated technologies become more prevalent, cybercriminals benefit from a significant advantage, as they no longer need to dedicate time and resources to researching their targets. The emergence of "attack-as-a-service" tools further exacerbates the situation, enabling perpetrators to swiftly and accurately breach organizations.

While regulatory bodies are attempting to curb AI misuse through measures like guardrails on established generative AI tools (e.g., ChatGPT and Claude), hackers are finding workarounds. Instead of utilizing widely available large language models (LLMs), they develop their own small language models (SLMs) and execute attacks from devices like Raspberry Pi computers, thereby concealing their activities from detection.

The threat of AI-enabled attacks poses a risk to businesses of all sizes. Traditionally, smaller firms were less likely to be targeted, as attackers relied on their knowledge of the target's existence. However, AI can now efficiently scan and assess thousands of organizations, potentially exposing even less secure smaller businesses. Moreover, the fragmented and disorganized defenses commonly found in smaller enterprises are even more vulnerable to AI-driven attacks.

Autonomous attacks also exacerbate third-party and supply chain risks. By automating reconnaissance and scaling attacks across numerous organizations, attackers gain an edge in compromising weaker suppliers, which can serve as an entry point into larger businesses. Supply chain security management has traditionally relied on annual questionnaires, point-in-time assessments, and contractual assurances; however, these methods are no longer sufficient to counter AI-driven threats.

Companies must now adopt continuous, automated monitoring of their suppliers' security posture, in line with regulations such as NIS2 and the expectations of regulatory bodies like the ICO and FCA.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Monday 24 August →