Rapidly Escalating Cyber Security Threat Faced by US States and Localities
US states and localities have just a few months to prepare for widespread and fast-moving cyber attacks powered by a new generation of extremely powerful artificial intelligence tools. This warning comes from a senior security industry executive involved in assessing frontier artificial intelligence models from Anthropic and OpenAI.
“We’ve had the opportunity to test these models firsthand to see how good they are at finding vulnerabilities and generating exploits, and the short answer is, they are incredibly good at it,” said Lee Klarich, chief product and technology officer at Palo Alto Networks.
Palo Alto Networks is one of a dozen security firms testing Anthropic’s Mythos artificial intelligence model through a preview programme known as Project Glasswing. The company is also testing OpenAI’s latest models through a similar Trusted Access for Cyber programme. Security and software companies received early access to the models, which sit at the cutting edge of artificial intelligence development, to better understand their implications as both potential cyber weapons and defences.
Rapid Spread of Advanced Capabilities
Although Anthropic and OpenAI have restricted access to their newest models, Klarich expects similar capabilities to become widely available within the next three to five months. “That’s generally how long it takes other models to catch up to whatever Anthropic, OpenAI and Google Gemini are building,” he said. “As these capabilities work their way into Chinese models and open source models, they will become more and more available.”
Significant Disruption to IT Security
Palo Alto Networks’ testing found that Mythos’ coding ability was 50 percent better than Anthropic’s previous artificial intelligence models. That capability translates into an extraordinary aptitude for spotting and exploiting weaknesses in software. In two weeks, Mythos discovered vulnerabilities that would have taken several years using traditional penetration testing, Klarich said.
Technology companies will use the models to address security flaws in existing software and create new products that are much more resistant to attack. At the same time, the models could also gain knowledge that makes them more effective as cyber weapons.
“When you teach a model how to write secure code, you are also, perhaps even without knowing it, teaching a model how to find insecure code, which ultimately means finding and understanding vulnerabilities, which leads to exploits,” Klarich said.
Impact on Public Sector Organisations
The impact for states and localities will likely be significant new stress on organisations that already struggle to keep up with security threats.
A deluge of vulnerabilities and patches will emerge as companies use artificial intelligence to scour existing software products for weaknesses in a race to patch security flaws before attackers can exploit them. “This means lots, lots, lots more patches will be coming your way,” Klarich said.
As that happens, there will be an increasing number of unpatched systems, giving attackers more opportunities to write exploits.
Increased supply chain risk will follow, with new artificial intelligence models triggering a spike in malware attacks delivered through standard software updates. Open source environments could be particularly hard hit. “The nature of open source means attackers will have access to the source code, and while source code isn’t required for these models to find vulnerabilities, it certainly makes it easier,” Klarich said. Attackers will be able to scan millions of open source packages for vulnerabilities and target organisations for exploitation.
Faster, automated attacks will become the norm. New artificial intelligence tools will largely automate the process of finding a software vulnerability and developing and executing an attack. Organisations can no longer tolerate response and recovery times measured in days or even hours. “With these models, we’ll start to measure attacks in minutes from start to finish,” Klarich said.
Immediate Response Measures
As artificial intelligence accelerates attacks, Klarich urged agencies to use automation to speed up the deployment of security patches and reduce the time it takes to detect and respond to security incidents. “Start thinking about how you can reimagine your patching process,” he said. “Everyone I talk to, honestly, like 100 percent, doesn’t have enough automation in their patching process.”
Klarich added that companies like Palo Alto Networks are exploring virtual patching, a technique that would automatically deliver protections for unpatched systems. This could prove especially valuable for open source software, where the volume of patches could become overwhelming, and for industrial control and Internet of Things systems that are infrequently patched.
The evolving threat environment also heightens the need for security measures such as extended detection and response, attack surface management, secure browsers, enhanced identity controls and zero-trust strategies.
“These are the types of technologies you’ll need, and you’ll want to make sure you have them fully deployed in optimal configurations,” Klarich said. “You have to take everything that is manual and turn it into artificial intelligence and automation, there’s no way around it.”
Long-Term Steps
Organisations regardless of industry can benefit from taking several longer-term steps as they adapt to the rapidly shifting nature of artificial intelligence-enabled exploits. These should addresss the foollowing viatal questions:-
- How do our vulnerability and patch-management operations need to be enhanced to accelerate discovery and timely patching as artificial intelligence-enabled threats evolve?
- Do we need to review and update our contractual protections with our most significant vendors regarding artificial intelligence-enabled threats?
- Do the existing threat intelligence service providers and managed detection tools have the ability to detect attack signatures that have no CVE match and no prior pattern in threat feeds?
- Do tabletop exercises and incident response plans account for multi-vector, simultaneous attack scenarios?
- Do board and executive briefings incorporate updated threat frameworks that reflect the development of frontier artificial intelligence models in the threat landscape?
- Do the existing cyber insurance policies provide adequate coverage and do the underlying risk questionnaires and policy terms remain accurate in the current threat landscape?
Theres is an ugent mesage in this advice. US states and localities must urgently enhance automation and deploy advanced security technologies to counter the emerging wave of AI-driven cyber attacks.
Image: mesh cube
Source: Cyber Security Intelligence