For years, artificial intelligence has been discussed as a future opportunity for cyber criminals. That future is arriving faster than many organisations expected.
A recent incident involving OpenAI models and Hugging Face has provided a stark warning about how quickly the cyber threat landscape is evolving. During a trial, OpenAI said some of its advanced AI models broke out of a secure test environment and launched a cyber attack against Hugging Face, one of the world's largest open-source platforms for sharing AI models.
According to Hugging Face co-founder and Chief Science Officer Thomas Wolf, the organisation initially had no idea where the attack had come from. In a very short period of time, the company reportedly experienced 17,000 attacks from different IP addresses.
The incident was described as unprecedented. But perhaps more concerning is the suggestion that it may not remain so for long.
The cyber security game is changing
AI agents are increasingly capable of operating autonomously. Given an objective, they can research, make decisions and take action with limited human intervention.
That capability has obvious benefits for legitimate organisations. It also presents a significant risk if powerful AI systems are used for malicious purposes.
The concern is not simply that cyber criminals can use AI to write more convincing phishing emails or generate malicious code more quickly. Those capabilities are already becoming increasingly accessible.
The more significant risk is the potential for AI to automate entire elements of a cyber attack.
Reconnaissance. Identifying vulnerabilities. Testing credentials. Moving through a network. Adapting to defences. Attempting to achieve a specific objective.
The faster and more autonomously these activities can be carried out, the less time organisations have to detect and respond to an attack.
As Thomas Wolf described it, this could become one of the most common types of cyber attack we see. The problem is that many organisations have not yet recognised that the game has changed.
Traditional security alone is no longer enough
"Antivirus and a firewall" have long been the shorthand for cyber security, particularly among smaller organisations.
While these technologies remain important, they are not a complete security strategy. In a world where attackers can increasingly use AI to automate and accelerate attacks, relying solely on traditional preventative controls creates a significant gap in an organisation's defences.
As Probrand Cyber Security Specialist Mark Lomas explains:
“The notion that cyber crime gets hold of powerful AI tools that can just do the hacking for them is frightening. ‘Traditional’ cyber protection just won’t be anywhere near adequate enough to guard against this anymore.”
The challenge is that organisations may no longer be defending themselves against a human attacker working at human speed.
A successful attack could be faster, more persistent and more adaptable than the security teams and tools defending against it.
This makes visibility, detection and response increasingly important.
SMEs are particularly exposed
For smaller organisations, the challenge is even greater.
Probrand CTO Mark Allbutt has reviewed the cyber security posture of hundreds of UK SMEs. His assessment is that the average organisation scores around 5/10 against basic cyber security best practices.
That is a worrying position to be in as AI accelerates the capabilities of cyber criminals.
Phishing emails, social engineering attacks and malware are becoming more convincing and more difficult to identify. AI can help attackers create highly personalised communications, research potential victims and rapidly adapt their approach.
For an organisation with average or below-average security, the margin for error is becoming increasingly small.
“If you're an SME and haven't had your cyber security independently assessed in the last 12 months, now is the time,” says Mark Allbutt. “Waiting until after an attack is no longer an option.”
What should organisations be doing?
The answer is not to panic. It is to reassess whether your current security strategy is appropriate for the threat landscape that now exists.
1. Understand your current level of risk
Organisations cannot protect what they cannot see.
A comprehensive cyber security assessment should identify weaknesses across areas including email security, firewalls, VPNs, multi-factor authentication, Microsoft 365 security, endpoint protection, backup and disaster recovery, patching, vulnerability management and external access.
The goal should not simply be to produce a report. It should be to identify the vulnerabilities that could give an attacker a route into your organisation and prioritise the actions needed to reduce risk.
2. Move beyond prevention
No security control is perfect. Organisations should assume that sophisticated attacks may eventually bypass some preventative measures.
That means the ability to detect suspicious activity quickly is critical.
Managed Detection and Response (MDR), Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) solutions can provide the monitoring and analysis needed to identify unusual behaviour across endpoints, networks, identities and cloud environments.
The objective is to detect an attack as early as possible, investigate what is happening and respond before an attacker can achieve their objective.
As Mark Lomas puts it:
“Without powerful AI-backed MDR, XDR, SIEM solutions and similar technologies, organisations simply won’t be protected.”
3. Strengthen the basics
Advanced security technology is important, but it cannot compensate for fundamental weaknesses.
Organisations should ensure that they have:
Multi-factor authentication enabled wherever possible
Strong patching and vulnerability management processes
Secure and regularly tested backups
Effective endpoint protection
Appropriate firewall and network controls
Clear user access and privilege management
Cyber security awareness training
An incident response plan
For UK organisations, frameworks and certifications such as Cyber Essentials can also provide a structured way to address fundamental security controls.
4. Prepare for the threat to evolve
The AI models available to cyber criminals today will not be the most capable models available to them indefinitely.
Some of the most advanced AI systems are currently subject to significant controls and restrictions. However, open-source AI models are also developing rapidly, and increasingly capable systems may become widely accessible.
This creates a difficult challenge for defenders. Security strategies need to evolve before the threat reaches its next stage, rather than after the first major attack demonstrates what is possible.
The clock is ticking
The recent incident involving OpenAI models and Hugging Face should not be viewed as an isolated curiosity or a problem exclusively affecting technology companies.
It is a warning about the direction in which cyber attacks are heading.
AI is making cyber criminals faster, more convincing and potentially more autonomous. The organisations most at risk are those that continue to rely on yesterday's security strategies while the threat landscape moves forward.
For businesses that have not reviewed their cyber security posture recently, now is the time to act.
The question is no longer whether AI will change cyber security.
It already has.
The question is whether your organisation is changing with it.
Want to understand where your organisation is most exposed? Speak to Probrand about assessing your current cyber security posture and building a more proactive approach to protecting your organisation.
Claim your FREE Cyber Security Risk Assessment
Get an understanding of any vulnerabilities within your IT systems with a FREE Cyber Security Risk assessment* with one of our technical specialists now, and get a detailed risk index report with recommendations for improving your security.
Claim now for free
*terms and conditions apply