惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
D
Darknet – Hacking Tools, Hacker News & Cyber Security
M
MIT News - Artificial intelligence
腾讯CDC
IT之家
IT之家
Microsoft Azure Blog
Microsoft Azure Blog
M
Microsoft Research Blog - Microsoft Research
阮一峰的网络日志
阮一峰的网络日志
H
Help Net Security
L
LangChain Blog
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
T
The Blog of Author Tim Ferriss
罗磊的独立博客
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
D
DataBreaches.Net
爱范儿
爱范儿
Schneier on Security
Schneier on Security
P
Palo Alto Networks Blog
Spread Privacy
Spread Privacy
Hugging Face - Blog
Hugging Face - Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
K
Kaspersky official blog
P
Privacy & Cybersecurity Law Blog
博客园_首页
T
Threat Research - Cisco Blogs
I
InfoQ
有赞技术团队
有赞技术团队
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Recorded Future
Recorded Future
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
GbyAI
GbyAI
Cyberwarzone
Cyberwarzone
B
Blog
C
Check Point Blog
P
Proofpoint News Feed
S
Securelist
A
Arctic Wolf

Computerworld

Apple’s iPhone satellite ambition goes beyond rescuing hikers Total Android recall: Never lose an important notification again The AI tech job slaughter gets real The big winner in Elon Musk’s suit against OpenAI and Microsoft — hypocrisy Microsoft previews automatic device isolation in Defender for Endpoint ECB warns banks of new AI risks Apple opens its post-Quantum encryption vault FAQ: What you need to know about expiring Windows Secure Boot certificates Microsoft cheat sheets: Dive into Windows, Office, and Copilot Google adds open source Agent Executor to support AI agents in production DeepSeek’s steep V4-Pro price cut escalates AI pricing war Q&A: How video helps build robot brains for physical AI FBI warns of Kali Oauth stealers Meta says goodbye to those who won't use AI Police take down VPN service (this time with a good reason) The AI that cracked Apple Silicon is only the beginning Microsoft says it's making AI 'safe for work' in your browser Microsoft, EY to spend $1 billion on helping customers buy agentic AI Workday extends Sana AI to ITSM after HR, finance With AI, typing's out, talking's in EU moves forward on $5.8B scale-up fund to keep startups from leaving Do Apple's accessibility efforts point at its AI plans? Microsoft refreshes Surface line with biz-friendly features – and a high price tag The world of AI tokens — and why they matter Microsoft is working on a patch for 'YellowKey' attack on Bitlocker, offers temporary fix Google focuses on autonomous AI agents in Gemini 3.5 Flash Beth Tschida takes over at Jamf as AI transforms Apple in the enterprise Google talks ‘singularity’ while scaling up agentic AI for enterprises Copilot Chat: Your hub for document creation and analysis 10 Android Circle to Search superpowers you probably never noticed EnterpriseClaw wants to bring governance to the OpenClaw era The Big Four accounting firms are now hiring more AI specialists than accountants Arxiv: Researchers who submit AI-generated junk could get 1-year suspension Coming Bright Up: Apple's AI moment looms How Apple turned circular manufacturing into a competitive edge Why ‘open AI’ models are gaining ground on LLMs Microsoft May security patch fails for some due to boot partition size glitch Microsoft to retire ‘Together Mode,’ its virtual meeting space for Teams 5 ways to curb AI sprawl without stifling innovation For May, Patch Tuesday means 139 updates — but no zero-days Here’s one career emerging from the AI shift: ‘forward-deployed engineers’ Why Apple needs Intel — and America needs them both Microsoft business software faces UK antitrust probe over bundling, AI lock-in The trouble with emotion-reading AI Apple’s App Store model for AI How Southwest Airlines is putting endpoint operations on autopilot Nearly every enterprise is investing in AI, but only 5% say their data is ready Jobs lost to AI could reappear elsewhere — and solidify AI-focused roles Cyberattack: First they come for Foxconn, then they come for you Microsoft’s new AI system finds 16 Windows flaws, including four critical RCEs 8 critical questions about the Googlebook, Android, and ChromeOS Who’s the winner in the new Microsoft-OpenAI deal? AI is ready to take over Python programming, but not much else WWDC: From NeXTStep for Apple to Apple’s next step for AI OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos Arm’s software chief sees human language as the new way to program IMF warns of the potential for AI attacks on global financial systems The European Commission eyes rules to restrict US cloud services Apple needs to fix admin authentication in ABM No hire, no fire: Employers get picky on tech skills amid AI disruption Apple vs. social engineering: Terminal paste trap blocked AI clones: the good, the bad, and the ugly LinkedIn illegally blocking free accounts from seeing 'who's viewed your profile' data, group alleges EU lawmakers strike provisional deal to soften AI Act WWDC 2026: How Apple can take a great leap in AI US government agency to safety test frontier AI models before release Chrome's AI features can take up to 4GB of space on your computer ServiceNow continues its AI transformation with an integrated experience Apple Intelligence hype cost the company $250M Give yourself an on-demand Android taskbar Edge browser leaves passwords exposed in plain text, says researcher Ask Jeeves bites the dust Apple can't make chips fast enough, but that's only part of the story AI-led job cuts don’t always mean stronger ROI — Gartner Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs Microsoft, Google push AI agent governance into enterprise IT mainstream Microsoft now has more than 20M paying Copilot users AI is more accurate than doctors in emergency diagnoses — study Start small, but start now: How to bring AI into your small business Apple is preparing to spend, but not necessarily on AI 10 quick productivity tips for Microsoft 365 mobile apps Relying on LLMs is nearly impossible when AI vendors keep changing things AI agents can bypass guardrails and put credentials at risk, Okta study finds Windows shell spoofing vulnerability puts sensitive data at risk Apple breaks records, admits it can’t make Macs fast enough Spotlight report: Transforming software development with AI - Whitepaper Repository - 25 great uses for an old Android device AI chatbots need ‘deception mode’ Are we ready to give AI agents the keys to the cloud? Cloudflare thinks so Friendlier chatbots can be less reliable, study says Gartner sees untamed growth in agentic AI Apple reportedly abandons Vision Pro AI venture funding to shoot up this year as bubble looms Scaling up a tech startup in Europe is hard — 'EU Inc.' aims to help Apple will be behind on AI — until it isn’t EU lawmakers fail to agree on watered-down AI Act, talks pushed to May Android reminders, reinvented Who’s the better CEO, Apple’s Tim Cook or Microsoft’s Satya Nadella? AWS unveils trio of key AI strategy announcements SAS makes AI governance the centerpiece of its agent strategy
Another IT governance headache: AI-enabled sanction evasion
2026-05-28 · via Computerworld

Over the next three to five years, both governments and the private sector will need to rapidly adapt identification and mitigation protocols as adversaries move from AI-assisted to AI-enabled sanctions evasion and proliferation financing (PF), a new research paper warns.

The report, Algorithms of Evasion: The Rise of AI-Enabled Proliferation Financing, from the Royal United Services Institute (RUSI), a UK-based defense and security think tank, defines PF as the use of funds or financial services to acquire, develop or otherwise deal in weapons of mass destruction (WMD). It states, “North Korea and Iran are now developing and deploying AI models to aid with sanctions evasion activities.”

Key findings include the fact that AI is now capable of mass producing high-quality fraudulent documents, as well as automating what the report describes as “the administrative minutia of managing extensive shell company  networks.” AI powered systems, it states, can also “analyze blockchain patterns in real time to dynamically adjust cryptocurrency mixing strategies, effectively evading detection tools.”

In addition, it says, “[tools such as generative AI] which can produce sophisticated fraudulent identification documents, for example, have helped North Korea perpetrate phishing attacks against Western companies.”

Dr. Aaron Arnold, senior associate fellow with the Centre for Finance and Security at RUSI, who authored the paper, said in an email that what prompted it was an uptick over the last year in North Korea’s use of AI to facilitate and enhance its cyber operations, in the form of phishing schemes designed to generate revenue for the country’s ballistic missile and nuclear weapons programs.

He advised enterprise IT managers who need to protect their organizations from becoming victims of sanction evasion activities that “[it] means largely adapting to a landscape where traditional human-focused security boundaries are being bypassed by automated technologies.”

For IT managers, said Arnold, “this might entail incorporating defensive AI, the use of behavior-based analytics, using ‘circuit breakers’ when there is heavy use of API or MCPs, updating personnel training, and hardening identity verification, especially for any remote hiring.” 

Distinction between AI-assisted and AI-enabled activity is ‘central’

Sanchit Vir Gogia, chief analyst at Greyhound Research, said that the RUSI report matters “because it names the right structural shift. AI is not creating sanctions evasion from thin air, it is compressing and scaling methods that already work.”

He pointed out that none of the sanction-evading techniques such as fraudulent documents, synthetic identities, shell companies, hidden beneficial ownership, crypto laundering, and others are new. “What changes is the speed, quality, volume and coordination with which these methods can now be assembled,” he said.

According to Gogia, “the distinction between AI-assisted and AI-enabled activity is central. AI-assisted evasion uses AI for discrete tasks: writing a better email, producing a cleaner document, generating a stronger false profile, translating a pitch, summarizing regulations or preparing a plausible job application. AI-enabled evasion is more serious.”

A ‘structural asymmetry’

This tactic, he said, “begins to coordinate the system itself. It links identity, documents, ownership structures, payment routes, cloud access, crypto wallets, API calls and timing. The difference is not whether AI helps someone fake a document. The difference is whether AI begins to orchestrate the deception.”

That is why the report’s findings should worry enterprise leaders, he noted: “Many organizations still assume the bad actor is mostly human, mostly linear and mostly slow. That assumption is expiring. AI lets adversaries run more attempts, with fewer errors, across more channels, in more languages, with better paperwork and greater patience than most enterprise review processes can absorb. This is not a tale of genius criminals discovering magic. It is the story of ordinary controls meeting industrialized plausibility.”

The evidence today, he pointed out, is strongest around tactics such as identity fraud, document fraud, synthetic personas, remote-worker deception, phishing, social engineering, crypto obfuscation and workflow abuse. “Fully autonomous evasion networks sit on the horizon,” he said. “They are serious, but they are not yet the everyday baseline.”

This distinction matters, said Gogia: “If enterprises obsess over cinematic autonomous agent scenarios while leaving remote hiring, vendor onboarding, payment approvals, and document review full of holes, they will lose in the most prosaic way imaginable.”

The report, he said, also gets the “asymmetry” right. “Offensive actors can learn across the ecosystem,” he said. “They can scrape open information, reuse leaked records, study enforcement patterns, test onboarding forms, inspect public procurement data, watch court filings, probe compliance thresholds and [use the information to] refine their behavior.”

Defenders, by contrast, are hemmed in by privacy rules, fragmented data, explainability requirements, jurisdictional boundaries, conservative operating models and siloed technology estates. “Offensive AI learns broadly,” he said. “Defensive AI often learns from fragments. That is the structural asymmetry.”

He explained that the regulatory landscape also amplifies the problem, in that regulatory bodies “still speak in separate dialects. [For example] the EU AI Act pushes organizations toward stronger obligations for high-risk AI. NIST-style frameworks push risk management, transparency, and governance.”

A trust architecture problem

Financial Action Task Force (FATF) expectations push national risk assessment and counter-proliferation controls, he noted, while banking regulators focus on model risk, accountability and operational resilience. “None of these streams is irrelevant. The trouble is that criminals do not organize themselves around regulatory workstreams. They organize around outcomes.”

What that means, said Gogia, “is that enterprise cannot wait for a clean global rulebook. It will not arrive in time. CIOs, CISOs, compliance officers and boards need a working governance model now. They need privacy-preserving analytics, controlled data environments, audit trails, legal safeguards and clear model-risk accountability.”

He said that enterprise IT managers should treat the situation as a trust architecture problem rather than a narrow sanctions-screening problem. “The uncomfortable truth is that AI is not simply helping bad actors write better phishing emails or forge tidier documents,” he noted. “It is helping them manufacture legitimacy across a chain of enterprise workflows.”

Likely outcome an ‘AI arms race’

Report author Arnold also noted that there are signs that cyber criminals have discovered new AI technologies and abilities that legitimate enterprises could adopt for legitimate applications.

History, he said, “is replete with [criminals] developing novel solutions to tough problems, [which are] later adopted by law enforcement. Much of our anti-financial crime policy is effectively a response to bad actors exploiting systems or using technology in novel ways to perpetrate crimes. In this scenario, I think an ‘AI arms race’ between enforcement authorities and bad actors is the most likely outcome.”

Gogia added, “the baddies are not teaching enterprises how to invent AI. They are teaching enterprises where trust is leaking. That is the lesson worth taking seriously.”

This article originally appeared on CIO.com.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.