惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
F
Fortinet All Blogs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
量子位
博客园 - 三生石上(FineUI控件)
I
InfoQ
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
D
Docker
美团技术团队
雷峰网
雷峰网
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
AI Is Making Attacks Cheaper, Faster and More Covert, Say...
https://www.infosecurity-magazine.com/profile/phil-muncaster/ · 2026-06-24 · via www.infosecurity-magazine.com

AI is making cyber-attacks cheaper, faster to scale, easier to customize and harder to spot, but it’s not fundamentally changing the tradecraft of intrusions, a new ReliaQuest report has revealed.

The threat intelligence specialist has been tracking the progress of the technology on the cybercrime underground over the past two years.

In 2024, AI was mainly used for “polishing” phishing emails, generating basic scripts, and in malicious tools like FraudGPT. By mid-2025, that picture had expanded to include “deepfake services, AI-assisted scripts, and a growing underground market for AI-enabled tools,” it said.

Today, AI has moved “closer into the heart of the offensive workflow,” according to ReliaQuest.

Read more on AI threats: AI Accelerates Attacker Breakout Time to Just Four Minutes

In the incidents ReliaQuest reviewed, AI appeared in two main roles.

“First, it was embedded in the attack workflow: clues pointed to attackers using it to it generate phishing pages, build web shells and credential harvesters, pad code to frustrate static analysis, and improve the fluency of social-engineering content,” the report noted.

“Second, AI was the lure itself. Attackers used demand for AI tools and trust in AI brands to get users to install malicious extensions, run commands, or follow fake setup steps that looked routine enough to pass initial scrutiny.”

It’s being used by all types of threat actor, from ShinyHunters to North Korean hackers, with goals as varied as extortion, initial access, fraud and espionage. The central theme is that it “consistently enabled these operators to achieve more, faster, with less effort,” the report explained.

AI is treated as operational infrastructure – something to buy, tune and slot into existing workflows – and as such the focus for threat actors is on balancing efficiency with reliability and cost, ReliaQuest said.

Six Ways AI Is Being Used for Cyber-Attacks 

The report revealed six key ways AI is used in intrusions today:

  • Phishing at industrial scale: Lowering the barrier to entry for cybercriminals by enabling mass generation of phishing pages and lures and ensuring campaigns can be launched, adjusted, and repeated at speed
  • Malicious tools produced faster: Generating key components like web shells and credential harvesters, as well as “varying or padding code to frustrate static analysis”
  • Social engineering polish: Erasing the typos, awkward phrasing, poor grammar, and clumsy design which used to be tell-tale signs of phishing
  • Identity fabrication: Making North Korean worker fraud easier to scale, and harder to spot thanks to rapid development of fake profiles and convincing deepfakes for meetings and interviews
  • Initial-access acceleration: Moving targets from “interaction to compromise” via AI-generated obfuscation in ClickFix attacks and AI-assisted pages in device-code phishing campaigns
  • AI-branded tools as the lure: Tricking users into running malicious installation commands or extensions disguised as Claude or other branded downloads

An Action Plan to Tackle AI Threats

“Security teams don’t need a new strategy built around AI as a category," the report explained. "But AI does change the pace of attacks, so they do need strong fundamentals, defense-in-depth, and AI and automation wherever operationally possible to match the new pace."

With that in mind, CISOs should consider actioning the following:

  • Use behavioral detection across endpoint, identity, network, and cloud, especially after access is granted
  • Automate containment to keep pace with machine-speed attacks
  • Retrain users on the full range of what AI can fake (eg voice, video, profile photos, and polished text), and require out-of-band verification for sensitive requests such as installs, approvals and payments
  • Invest in threat research to track the volume and timing patterns that AI-scaled campaigns create
  • Use external threat intelligence to spot AI-enabled tradecraft before it reaches your environment and route it to the right teams