惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
T
Tailwind CSS Blog
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
博客园 - 叶小钗
N
Netflix TechBlog - Medium
罗磊的独立博客
量子位
MyScale Blog
MyScale Blog
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
B
Blog
腾讯CDC
爱范儿
爱范儿
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
F
Fortinet All Blogs
雷峰网
雷峰网
G
Google Developers Blog
Google DeepMind News
Google DeepMind News

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Infosecurity Europe: Cybersecurity Teams Which Don’t Leve...
Danny Palmer · 2026-06-02 · via www.infosecurity-magazine.com

The rapidly evolving threat landscape and the way threat actors are leveraging AI to enhance attacks means that defenders no longer have a choice and must also use AI to help defend networks from cyber threats – otherwise they are “doomed to fail."

That is the warning Joe Slowik, director of cybersecurity alerting strategy at Dataminr, gave at Infosecurity Europe on Tuesday 2 June.

In a session on the AI & Cloud Security Stage, Slowik argued that there is a critical need for defenders to adapt to accelerated adversary timescales, and that organizations which still rely on a human-focused security operations center (SOC) will be left behind – and vulnerable to cyber threats.

“We don’t have a choice anymore. Quite simply, when it comes to security processes, those which are human-in-the-loop driven, just don’t adapt to new adversary timescales,” Slowik explained.

“Having a human analyst being able to dig into an intrusion and provide a summary of what’s going on is just no longer is practical anymore given the acceleration of adversary intent,” he added.

Cybercriminals and other threat actors have leveraged emerging technologies like AI, machine learning and large language models (LLMs) to enhance and speed up attacks, meaning that the window between a vulnerability being discovered and being exploited has significantly decreased.

That means that while security teams may have previously had time to assess their cybersecurity posture in the light of new threats, Slowik estimated it is “no longer practical” as attackers can be leveraging new vulnerabilities or attack methods within days or even hours.

Rethinking Security Operations with AI

“I say this as someone who was skeptical of machine learning: the time has passed for skepticism, human-only solutions are doomed to fail, we don’t have the ability to leverage strictly human-in-the-loop to align with adversary lifecycles,” Slowik warned.

The solution for security teams, he argued, is a “rethinking of security operations” - and that defenders should enhance their workflows with the use of AI. But this needs to go beyond the deployment of LLMs.

For example, using AI agents to gather intelligence on what is known about vulnerabilities, what elements of the network are most vulnerable to an attack and what the best way to implement protection around it is.

Doing this can vastly speed up reaction to an attack at a time when attackers are faster than ever.

“Instead of waiting until after the ransom notice has been delivered or the wiper malware has been deployed, you can improve and enhance your ability to get ahead,” said Slowik.

He used the React2Shell vulnerability as an example of a rapidly exploited vulnerability, which was compromized by adversaries in just hours.

A solely human-focused SOC might have needed days to compile a report on how to react, while a SOC that was enhanced with AI was able to more rapidly compile reports and learn how to defend the network against attackers exploiting  React2Shell.

“From these enrichments, I can embark on an informed and accelerated remediation lifecycle, in real-time, alongside events to enhance improved decision-making processes,” said Slowik. "Adversary operations from time to breach to time to objectives are accelerating. It's a matter of fact defenders have to keep pace, this is not optional."

However, he was also keen to stress that humans are not being replaced by AI and that they are very much a vital cog in the SOC. But it is by combining a human-in-the-loop with AI that is the way forward for cyber defenders – as that is the only way they will keep pace with the cyber attackers doing the same.

“Humans are will still definitely be making decisions, but assisted with AI to align with adversary workflows,” Slowik concluded.