AI Poses New Challenges and Opportunities in Global Cybersecurity Landscape, Says Bugcrowd's Report
A recent report from Bugcrowd, titled "Inside the Mind of a Hacker 2024," casts a spotlight on the rapidly evolving role of Artificial Intelligence (AI) in the field of cybersecurity. This comprehensive study collected insights from 1,300 ethical hackers based across 85 countries, including major tech hubs such as the United States, India, the United Kingdom, and Australia, among others. The findings reflect both the apprehensions and potential benefits associated with AI in the realm of cyber threats and defence strategies.
According to the report, an overwhelming 82% of hackers surveyed expressed concerns that the AI threat landscape is changing at a pace too swift for current security measures to keep up. Furthermore, 93% of the respondents believe that the AI tools employed by companies potentially introduce new vulnerabilities that could be exploited by malicious actors.
Patrick Harr, CEO of SlashNext Email Security+, commented on these findings, underscoring the dual role of AI as both a business enabler and a hacking accelerator. Harr noted that AI-assisted attacks have become commonplace in business email compromise (BEC), phishing, and social engineering. He also predicted an increase in AI’s use in malware development and the manipulation of large language models through techniques such as poisoning and model injection.
The report highlights a significant transformation in hacking practices, with 71% of ethical hackers acknowledging that AI has enhanced the value of hacking in 2024. This is a marked increase from 21% who held the same view in 2023. Jason Soroko, Senior Fellow at Sectigo, emphasised that while AI amplifies both offensive and defensive strategies, human expertise remains irreplaceable, particularly in uncovering complex vulnerabilities. Soroko noted that 83% of hardware hackers feel confident in their ability to breach AI-powered devices, indicating a growing concern about the intersection of AI and hardware security.
Beyond technical capabilities, the report also delves into the ethical considerations within the hacking community. John Bambenek, President of Bambenek Consulting, highlighted an encouraging finding: 87% of hackers surveyed prioritised reporting critical vulnerabilities over financial gain. This demonstrates a strong ethical foundation within the community, as these skills are in high demand by authoritarian regimes that might exploit vulnerabilities for harmful purposes.
The role of AI in enhancing cybersecurity is not wholly negative. Piyush Pandey, CEO of Pathlock, pointed out that AI can significantly enhance the field by automating intelligent responses, analysing behaviours, and improving vulnerability management. As AI takes on more roles traditionally filled by human professionals, the role of these experts will evolve, focusing more on guiding the deployment of AI tools and providing valuable insights.
As compliance demands and data volumes continue to grow, AI and machine learning (ML) are expected to play an integral role in automating compliance processes and predicting security risks. Pandey stressed that AI’s capabilities to monitor compliance continuously and automate sophisticated risk assessments would reduce manual errors and improve risk management.
The Bugcrowd report presents a nuanced picture of AI's dual role within cybersecurity: introducing new threats while simultaneously offering new tools for defence. As the landscape continuously evolves, the report suggests that the combined strength of AI tools and human expertise will be vital in navigating the complexities of global cybersecurity challenges.
Source: Noah Wire Services