Cybersecurity experts: human attackers with AI remain bigger threat than rogue AI
Energy infrastructure remains dangerously vulnerable to cyberattack, but AI in criminal hands poses a greater near-term risk than autonomous agents.
What to know
- Recent high-profile rogue AI cyberattacks have raised concerns about autonomous agents threatening critical infrastructure, but cybersecurity experts say malicious humans wielding generative AI pose a more immediate and severe risk.
- Energy infrastructure is inherently vulnerable: much of it was built decades ago without internet connectivity, manufacturers have gone out of business, and utilities often lack resources to patch systems that only accept updates quarterly or annually.
- Generative AI acts as a force multiplier for human attackers, enabling them to move faster than defenders can respond—the core worry among security experts interviewed.
“We were always prey. We were just kind of surviving at the appetite of our predators.”
Joshua Corman, Executive in residence, Institute for Security and Technology · The Verge ↗
Joshua Corman Executive in residence for public safety and resilience, Institute for Security and TechnologySophie McDowall Research associate, Foundation for Defense of DemocraciesJustine Calma Reporter, The Verge
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
Calma details structural vulnerabilities in aging energy infrastructure
The article explains that much critical energy infrastructure was never designed for internet connectivity and now faces patching challenges: some equipment manufacturers have gone out of business, and operational technology systems typically only accept updates quarterly or annually, leaving smaller utilities without resources to defend against modern threats.
“The true difference from AI is that it's letting adversaries move more quickly — but it's very challenging for those defending the infrastructure to match that pace.”
— Sophie McDowall -
I
Artificial intelligence has been a “force multiplier” for bad actors targeting our critical infrastructure systems, IST’s @joshcorman.bsky.social told @theverge.com. “A bad actor...can use these tools... to attack things they normally don’t know how to,” Josh explained. 🛡️ Read more:
-
-
background
Cybersecurity experts warn human attackers wielding AI are the greater threat — Experts interviewed by Calma, including Joshua Corman of the Institute for Security and Technology, argue that while rogue AI agents are concerning, generative AI in the hands of malicious humans poses a more immediate risk. Corman characterizes AI as a force multiplier that lets adversaries move faster than defenders can respond.
-
background
Verge reports on AI's role in cyberattack vulnerability after recent rogue agent incidents — Justine Calma reports on recent high-profile incidents of rogue AI agents orchestrating complex cyberattacks, and examines whether AI poses an existential threat to energy infrastructure. The article focuses on the persistent vulnerability of critical energy systems, many built decades ago without internet connectivity in mind.
Also covered reported alongside — the timeline has no entry for these yet
-
first by theverge.com, 3d ago · also The Verge