How attackers use AI to exploit business loopholes

Cát Tiên (THEO techcrunch) |

Wiz warned businesses to prioritize security from the start, as attackers are also taking advantage of AI to exploit vulnerabilities quickly.

In the era of artificial intelligence (AI), cybersecurity is no longer just a technical competition but has become a true intellectual game.

According to Ami Luttwak, technology director of Wiz cybersecurity company, AI is opening up both opportunities and risks, both supporting businesses to accelerate development and giving attackers unprecedentedly powerful tools.

Mr. Luttwak said that when businesses rush to integrate AI into processes, from encryption automation, AI agents to internal tools, the scope of attack is expanding rapidly.

"AI helps developers develop code faster, but the speed with shortcuts can easily create vulnerabilities. If you don't require the system to be built in the safest way, AI won't replace you," Mr. Luttwak warned.

Not only the defense is taking advantage of AI, the attackers are also taking the lead. They use prompt injection techniques, even training their own AI agents to explore secrets, delete data, or take control of internal tools.

The case of Drift, a chatbot startup that suffered a breach that leaked Salesforce data of many large corporations, is clear evidence of the risk of third-party supply chain attacks.

Another example is the s1ingularity campaign targeting the build Nx system, where attackers install malware, taking advantage of AI tools such as Claude and Gemini to automatically search for sensitive information. As a result, thousands of token codes and private GitHub access locks were stolen.

Although the rate of businesses deploying new comprehensive AI is about 1%, Wiz has recorded weekly AI-related attacks on a scale of thousands of customers.

AI has penetrated every attack step, and the pace of change is faster than any previous technological revolution. That means the cybersecurity industry must respond faster, Mr. Luttwak emphasized.

To cope, Wiz has developed specialized security tools for the AI era such as Wiz Code ( helping to detect and minimize vulnerabilities right from the development stage) or Wiz Defend (monitoring and responding to threats in the cloud environment).

Along with that, the company calls on businesses, especially AI startups, to consider security as a priority from the very beginning.

Even with only five employees, you still need a CISO, said Mr. Luttwak, emphasizing the importance of designing a secure data architecture, controlling access and complying with security standards such as SOC2 early to avoid future security debts.

According to Luttwak, the current time is a golden opportunity for cybersecurity startups. Because if each security sector is experiencing new forms of attack, it is also an opportunity to reshape the way of defending.

Cát Tiên (THEO techcrunch)
RELATED NEWS

Converting services with AI can be a piece of cake that is not easy to swallow for adventure investors

|

adventure investors are expecting AI to transform the labor-intensive service industry, but the reality is much more complicated than they imagined.

South Korea with AI development ambition defeats OpenAI, Google

|

Korean companies are developing large, compatible language models, ready to compete with major global rivals such as OpenAI and Google.

Prosecution of 2 more defendants in the case at the Bach Mai Hospital project, Viet Duc facility 2

|

Major General Nguyen Quoc Toan said that the Ministry of Public Security has prosecuted 2 additional defendants in the case that occurred at the second facility of Bach Mai and Viet Duc Hospitals.

Cries opened my heart after the fierce storm

|

The crying of choking on the coast of Quang Tri after the storm, the billion-dollar ship was sunk by strong waves, 9 fishermen went missing, a fragile miracle of hope will happen.

13 dead, 13 missing due to storm No. 10 and floods

|

Storm No. 10 and floods caused by the storm have killed 13 people, 13 people are missing, 8 people are out of contact, and 33 people are injured.

Converting services with AI can be a piece of cake that is not easy to swallow for adventure investors

Cát Tiên (THEO techcrunch) |

adventure investors are expecting AI to transform the labor-intensive service industry, but the reality is much more complicated than they imagined.

Các thỏa thuận hạ tầng hàng tỉ USD thổi bùng cơn sốt AI

HẠO THIÊN (THEO techcrunch) |

Để duy trì tốc độ phát triển AI, các tập đoàn công nghệ toàn cầu đang bơm hàng trăm tỉ USD vào hạ tầng điện toán, từ trung tâm dữ liệu siêu quy mô đến hợp đồng dịch vụ đám mây.

South Korea with AI development ambition defeats OpenAI, Google

NGUYỄN ĐĂNG |

Korean companies are developing large, compatible language models, ready to compete with major global rivals such as OpenAI and Google.