In the context of AI developing at a dizzying pace and expected to continue to help businesses improve productivity, Kaspersky experts warn about the risks of overconfiding in AI and lack of verification. These gaps are being exploited by cybercriminals to carry out attacks without relying on technical vulnerabilities, but only taking advantage of user trust.
How do bad guys take advantage of users' overconfidence in AI agents?
Recently, experts from the Kaspersky GReAT research group discovered 92,000 fake AI services attacks in 2026. Nearly half of them (49%) faked the ChatGPT application, 18% faked Claude and 18% faked Gemini.
These are all legitimate applications and play an important role in the process of working with AI agents, and are also tools used from the beginning in the software development environment. However, bad actors take advantage of trust in these applications to spread fake versions to attack those who use them.
In addition, cybersecurity experts also discovered more than 15,000 samples of malware disguised as AI agent software. These malware groups include Trojans, spyware, exploitation codes, malware download codes, malware installation codes and backdoor malware.
Although disguised as AI software, they all have the harmful function of a real malware. Just running a fake application, users can unintentionally create conditions for attackers to steal internal information and set up remote control over the device.
Mr. Sojun Ryu, a security research expert at Kaspersky GReAT, also pointed out another risk related to the development and application of AI: open source components.
The supply chain attack targeting Axios in March 2026 shows that cybercriminals are increasingly targeting software components trusted by many to be able to access a larger number of victims.
Axios is one of the most widely used JavaScript libraries in the world, with more than 100 million downloads per week and integrated into more than 170,000 software packages. The attacker first infiltrates the Axios project manager's computer, then accesses the project's account on the source code repository, and then releases versions containing malware.
Recommendations
In the context that productivity is increasingly becoming a decisive factor in operating efficiency as well as profitability of businesses, Mr. Ryu gave many recommendations to help businesses maintain productivity while still ensuring safety.
Businesses need to establish clear security boundaries between external content and internal resources used to develop software. At the same time, businesses need to strengthen security not only for the integrated development environment (IDE), but also for extensions, workspaces and access rights granted to AI agents.
In addition, he said that businesses need to strictly control how software is put into the development environment, and monitor all activities taking place in the system. The goal is not to increase the required approval steps, but to help the safe process become the simplest and most effective choice for users.
