CrowdStrike warns AI expands attack surface while aiding defenses
CrowdStrike's latest report says AI is both helping and hurting cybersecurity.
While companies use AI to boost business, hackers are using the same tech to make attacks sneakier and harder to spot.
The more businesses rely on AI, the bigger their weak spots get, making it easier for cybercriminals to slip through.
Cybercriminals use deepfakes and LLMJacking
Cybercriminals now use AI just like everyone else, which makes them tougher to catch.
Groups like Famous Chollima are using AI-generated resumes and deepfake interviews to try to gain entry to companies working in cryptocurrency and the blockchain, while others like Cordial Spider can steal data in minutes through clever phone scams.
There's also a threat called LLMJacking: hackers gain access to keys or credentials used to access a company's AI models and flood systems with requests, as one victim's LLM generated close to 200,000 API requests in two minutes.
All this means security teams need to stay sharp and rethink their defenses as attacks get faster and more advanced.