New Cyberattack Risks Emerge from AI Misuse

The misuse of artificial intelligence (AI) is creating new risks for cyberattacks, cybersecurity firm Sophos has warned. Its “AI Security 2026” report says attackers are now actively using AI at different stages of cyberattacks, allowing them to complete weeks of work within days. The report says AI is not necessarily creating new forms of cyberattacks. Instead, it is helping criminals carry out traditional attacks faster and more efficiently, leaving security teams less time to detect and stop them. “Attackers first have to break into a system, then spread throughout the network and eventually steal information,” said John Peterson, Sophos’ chief technology officer. “But what has changed is the speed at which attacks are conducted. AI is being actively used as a tool to accelerate attacks.”

Enterprise AI identities, OAuth tokens, AI agents, APIs and development tools are becoming key targets. Attackers are also using AI-assisted social engineering and deepfakes to make scams more convincing. Sophos identified a campaign called “STAC6994” in which attackers used about a dozen AI agents to test attacks against security systems. They created nearly 80 modules and more than 70 evasion techniques within days. The report warns that coding agents, AI assistants and open-source models with access to critical systems are creating new risks involving credentials, permissions and API keys. AI development infrastructure and supply chains are also becoming targets. The findings are based on Sophos X-Ops investigations, SophosLabs analysis, threat intelligence, AI research and feedback from more than 625,000 customers.

Leave a Reply

Your email address will not be published. Required fields are marked *

error: Content is protected !!