Urgent.News

What's breaking now, across thousands of outlets.

AI

Anatomy of an AI-powered hack

Palo Alto Networks revealed to Semafor fresh details about an AI-powered hack over the summer that targeted a European IT and software company.

Anatomy of an AI-powered hack

A recent AI-powered hack demonstrated how human hackers are leveraging frontier AI models to expedite their malicious activities. Palo Alto Networks, which assisted in defending a European IT and software company against an extortion attempt, revealed that the hack was completed in under 10 hours, a process that typically takes human hackers around two weeks.

The attack began with the human hacker deploying an AI agent to conduct reconnaissance, essentially launching a massive internet scan to identify potential vulnerabilities. Once the hacker gained access to the company's system, sub-agents were deployed to extract credentials from code repositories, a critical step known as "living off the land." This technique involves using the victim's own software to carry out attacks, making it harder to detect.

The stolen credentials were then used to infiltrate the company's software deployment system, allowing hackers to access their cloud accounts and gain control over the company's AI tools. The attack culminated with a ransom demand, but the team managed to thwart the attack before the hackers could fully succeed. An 80-page technical report detailing the vulnerabilities was left behind, providing valuable insights for the company's security team.

While the prospect of AI enhancing hacking capabilities may raise concerns, Palo Alto Networks' threat researcher, Andy Piazza, emphasized that the attack was a result of a human directing AI agents, rather than an autonomous hack. This situation is similar to how good actors use AI, with humans overseeing the process and making decisions based on the AI's results.

Although AI systems are gaining access to sensitive data, the techniques used in this attack are not novel and can be replicated by human hackers. This situation underscores the importance of robust cybersecurity measures to protect against such threats.

Written by urgent.news from Semafor's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at semafor.com →

More in AI

Build a serverless PII redaction pipeline with Amazon Bedrock Data Automation

Learn how to automate end-to-end PII detection and redaction from scanned documents at scale using Amazon Bedrock Data Automation with a custom blueprint, AWS Step Functions, and AWS Lambda.

  • Amazon Bedrock Data Automation automates PII redaction pipeline on AWS
  • Utilizes generative AI document understanding for holistic interpretation
  • Custom blueprint feature enables precise extraction of structured information

More from Wednesday 16 September →