الذكاء الاصطناعي يغير الأمن السيبراني بسرعة وبطرق مخيفة

7 أغسطس 2026·إنجاجيت
الذكاء الاصطناعي يغير الأمن السيبراني بسرعة وبطرق مخيفة

هل تستطيع صناعة أمن المعلومات مواكبة التطور؟

بقلم ماكس ميلر 7 أغسطس 2026، الساعة 12:30 مساءً بتوقيت شرق الولايات المتحدة

تخيل أنني أتيت إليكم بالاقتراح التالي: سأعطيكم تريليونات الدولارات. مقابل ذلك، سأبني آلة تلوث البيئة، وتسرق من كل فنان وأكاديمي على الكوكب، وترفع فواتير الكهرباء وأسعار الأجهزة الحاسوبية، ويمكنها القيام بأشياء مفيدة بشكل هامشي مثل ملء جداول البيانات وكتابة أكواد أساسية. ولتحسين الصفقة، سأضيف جسراً في بروكلين. هل أنتم ما زلتم غير مقتنعين؟ إذن اسمحوا لي بإثارة اهتمامكم أكثر. ستجعل هذه الآلة أيضاً كل برامجكم أقل أماناً، بينما تمكن المجرمين والهاكرز المدعومين من الدولة من تنفيذ هجمات إلكترونية أكثر تطوراً من أي وقت مضى.

هذه صفقة لا يوقع عليها معظم الناس، لكنها بالضبط ما حصلنا عليه بشكل جماعي من طفرة الذكاء الاصطناعي. بالإضافة إلى التأثيرات التي تمت مناقشتها غالباً للذكاء الاصطناعي على الملكية الفكرية والبيئة، فقد كان للذكاء الاصطناعي بالفعل تأثير عميق على أمن المعلومات. الآن، يمتلك أي شخص لديه إمكانية الوصول إلى نماذج اللغة الكبيرة ما يعادل قرصان يرتدي قبعة فيدورا ويشرب مشروب مونستر إينرجي ويعمل طوال اليوم من أجله. وفي حين أن العديد من الهجمات الشائعة مثل التصيد الاحتيالي تتطلب عادةً الوقت والبحث، فإنها الآن تتطلب القليل أكثر من القدرة على النسخ واللصق.

لقد كان للذكاء الاصطناعي بالفعل تداعيات هائلة عبر مؤشرات الأمن، حيث عزز الأساليب الهجومية التقليدية من التصيد الاحتيالي إلى هجمات بيانات الاعتماد، في حين أدى أيضًا إلى ظهور مخططات هندسة اجتماعية جديدة تستفيد من تقنية تزوير الصوت والتزييف العميق وتسريع اكتشاف نقاط الضعف الفريدة. يستجيب المدافعون في جميع أنحاء الصناعة التكنولوجية بحلول الذكاء الاصطناعي الخاصة بهم، ولكن هل يمكنهم تجاوز المجرمين من حيث الإنفاق والهندسة، ناهيك عن الجهات الفاعلة ذات المستوى الحكومي التي تحظى بتمويل جيد؟ إليكم كيف غير الذكاء الاصطناعي وضع الأمن السيبراني.

معضلة أمن الإنترنت

رسم توضيحي لأيدي تضغط على مفاتيح حاسوب محمول مع أيقونات هولوغرافية للذكاء الاصطناعي، التطبيقات والمجلدات العائمة أعلاه. ونان يوسينجكوم/Getty Images

هناك مفارقة جوهرية عند تقاطع الذكاء الاصطناعي وأمن الإنترنت. في حين أن الذكاء الاصطناعي مفيد لتعزيز الأمن، إلا أنه مضاعف للقوة للمهاجمين. ليس فقط لأنه لديه حق الوصول إلى مجموع إحصائي للمعلومات في العالم، بل يمكنه أيضًا التوليف عبر التخصصات من البرمجة إلى الشبكات. لم يعد المجرم الإلكتروني المحتمل بحاجة إلى سنوات من الخبرة تحت أحزمة قبل تنفيذ هجوم معقد. يمكن توجيه نموذج لغة كبير قادر على التعامل مع المهام إلى ضحية محتملة والقيام بالعملة المشفرة بينما يجلس المهاجم البشري مسترخيًا على الأريكة. كما ذكر مقال من كلية هارفارد للتمديد، "لقد ديمقراطية الذكاء الاصطناعي الجريمة الإلكترونية".

وما يزيد المشكلة تعقيدا هو السرعة التي يمكن أن تعمل بها الذكاء الاصطناعي. ففي حين قد يستغرق الأمر أسابيع لعملية إجرامية يقوم بها إنسان في العالم السيبراني، يمكن تحقيقها في فترة ما بعد الظهيرة بمساعدة نموذج اللغة الكبير (LLM). ويتمتع المجرمون بوصول إلى أكثر من نموذج لغة كبير واحد. حيث يعمل الكثير منهم على عدة جلسات ذكاء اصطناعي في نفس الوقت، أو يستخدمون نماذج متعددة. وكما وصف موقع VentureBeat، فقد تم تنفيذ هجوم بمساعدة الذكاء الاصطناعي في فبراير/شباط، والذي نهب قواعد بيانات حكومية في المكسيك من قبل مهاجمين قاموا بتغذية المخرجات ذهابا وإيابا بين كلود وشات جي بي تي. وعندما يرفض أحد الدردشات المساعدة، غالبا ما يكون الآخر على استعداد لالتقاط أخطائه.

لا يزال البشر ضروريين في الوقت الحالي، وتعمل الذكاء الاصطناعي كعامل مضاعف للقوة بدلا من الاستبدال. ولكن المخاوف تتصاعد. فبينما كانت هذه المقالة قيد المعالجة، كشفت شركة أوبن إيه آي أن أحد النماذج تحت المراقبة المحصورة (sandboxed) قد هرب من بيئة الاختبار (المحتملة الثغرات) الخاصة بها واخترق مستودع الذكاء الاصطناعي HuggingFace إلى جانب خدمات أخرى من أجل الحصول على إجابات لمعيار مرجعي اصطناعي.

قد تعتقد أن تعزيز الوضع الأمني أمر سهل بنفس القدر، حيث يمتلك المدافعون نفس إمكانية الوصول إلى نفس نماذج اللغة الكبيرة (LLMs)، وفي بعض الحالات إلى نماذج أكثر تقدمًا غير متاحة للجمهور بعد. لكن أمن المعلومات غير متماثل. في حين أن على المدافع حماية كل ثغرة أمنية محتملة، يكفي المهاجم العثور على واحدة فقط في معظم الحالات. أدى هذا الديناميكي إلى انتشار الثغرات الأمنية التي تم اكتشافها سرًا من قبل القراصنة - وهي عيوب أمنية تم شحنها مع برنامج ما وتم اكتشافها سرًا من قبل القراصنة. وقد أثبتت نماذج الذكاء الاصطناعي براعتها في الكشف عن هذه العيوب.

الذكاء الاصطناعي يعزز مخططات الهندسة الاجتماعية

رسوم بيانية مرسومة لخطاف صيد مُلقي على مقربة من أيدي تكتب على لوحة مفاتيح حاسوب محمول. Tadamichi/Getty Images

من المغري أن نتخيل القراصنة كأشخاص يرتدون معاطف طويلة سوداء ويضربون على لوحة المفاتيح بسرعة مليون كلمة في الثانية، لكن في الغالب الأعم هم أشخاص يرسلون ملايين رسائل البريد الإلكتروني الاحتيالية حتى يثبت شخص ما أنه ساذج بما يكفي لتقديم معلومات بطاقة الائتمان.

وأفضل مثال على ذلك هو التصيد الاحتيالي. تمكن معظمّا من اكتشاف هجوم تصيد واحد على الأقل من مسافة ميل. بريد إلكتروني يزعم أنه من مايكروسوفت لكنه مليء بأخطاء إملائية ونحوية محرجة، هو بوضوح عمل مجرم مبتدئ مع معرفة سطحية باللغة الإنجليزية فقط. أو على الأقل، كانت هذه هي الحال في السابق. بفضل الذكاء الاصطناعي، سيتم كتابة هذا البريد الإلكتروني بشكل مثالي الآن. قد يفوح منه رائحة الكتابة الآلية للذكاء الاصطناعي، لكن المراسلات الفعلية من مايكروسوفت تفوح منها نفس الرائحة الآن.

بالنسبة لجهود التصيد الاحتيالي على نطاق واسع، يمكن لنموذج اللغة الكبير (LLM) كتابة بريد إلكتروني خالٍ من الأخطاء النحوية وبلاغيًا مقنعًا، ثم أتمتة عملية العثور على عناوين البريد الإلكتروني وإرسال الرسالة. التصيد الاحتيالي الموجه، الذي يحدث عندما يتم استهداف فرد معين بجهود تصيد شخصية للغاية، أصبح الآن جهدًا تافهاً. يمكن لمساعد الدردشة البحث عن ضحيتك عبر الإنترنت نيابة عنك، والعثور على معلومات قد لا تكتشفها أثناء بحثك الخاص. يمكن للبوت حتى بدء مراسلة ذات صلة بالموضوع مع الهدف بنفسه، مما يدفعه إلى الكشف عن المعلومات التي تبحث عنها.

وفقًا لمورد الأمن برايتسايد، تستخدم 82 في المائة من رسائل التصيد الاحتيالي الذكاء الاصطناعي في مرحلة ما من العملية، وفي حين أن معدل النقرات لهذه الرسائل كان 12 في المائة فقط سابقًا، فقد أدت الرسائل المدعومة بالذكاء الاصطناعي إلى زيادة هذا الرقم إلى 52 في المائة في البيئات المحاكاة. وهذه هي البيانات الخاصة بهجمات البريد الإلكتروني، دون حساب الزيادة الهائلة المصاحبة في هجمات تزوير الصوت العميق للذكاء الاصطناعي، والتي تقدر برايتسايد أنها ارتفعت بنسبة 442 و680 في المائة على التوالي بين عامي 2023 و2024.

الذكاء الاصطناعي يخلق أسطحًا جديدة للهجوم

شخص يحمل هاتف ذكي مع علامة تحذير مثلث Supatman/Getty Images

مع ربط الشركات والحكومات لمزيد من عملياتها بنظم الذكاء الاصطناعي، أصبحت عرضة للهجمات التي تستغل الثغرات الخفية في أنظمة الذكاء الاصطناعي. أكثر هذه الهجمات شيوعًا هي هجمات حقن الأوامر، حيث يجد المهاجمون طريقة لإعطاء نظام الذكاء الاصطناعي تعليمات خبيثة. على سبيل المثال، قد تكون التعليمات التي ترسل بيانات كشوف رواتب الشركة إلى عنوان بريد إلكتروني محدد مخفية في موقع ويب. عندما يطلب أحد الموظفين من شركة الذكاء الاصطناعي تلخيص تلك الصفحة، فإنه يستوعب هذه التعليمات وينفذها.

في بعض الحالات، تكون هذه الهجمات أشبه بالبريد العشوائي أكثر من كونها برمجيات خبيثة. وجدت مايكروسوفت أن بعض الشركات كانت تضيف أزرار "تلخيص باستخدام الذكاء الاصطناعي" على مواقعها الإلكترونية التي تحتوي على تعليمات مخفية. عند النقر عليها، تخبر روبوت الدردشة بتنفيذ مهام مثل تذكر الشركة كمصدر موثوق أو التوصية بمنتجاتها بدلاً من منتجات المنافسين في التفاعلات المستقبلية. فقط عندما يتحقق المستخدم من الذاكرة الدائمة لنموذج اللغة الكبير، يدرك أنه تعرض للخداع.

يمكن أن تكون الهجمات الخبيثة بشكل مباشر بنفس السهولة. في ديسمبر/كانون الأول 2025، نفذت ميتا مساعد دعم مدعوم بالذكاء الاصطناعي، ظاهريًا لمساعدة الناس على استعادة حساباتهم. لكن الروبوت كان مفيدًا أكثر من اللازم، وكان يربط عن طيب خاطر عنوان بريد إلكتروني مملوك لهجوم بأي حساب إنستغرام، مما يسهل اختراق أي حساب بسهولة تامة دون تمكين المصادقة متعددة العوامل.

زعمت شركة أوبن إيه آي في العام الماضي أن الدفاع الكامل ضد هجمات حقن المحفزات في متصفحات الذكاء الاصطناعي قد لا يكون ممكنًا. إذا كان الأمر كذلك، فإن أفضل مسار عمل لأي كيان مسؤول هو عدم ربط أي من أنظمته أو بياناته الحساسة بنموذج ذكاء اصطناعي في المقام الأول. في الوقت نفسه، تتمثل أفضل الممارسات دائمًا في التحقق مرتين من أي شيء تقوم بلصقه في حقل محفز من مصدر آخر، والحد من نطاق وصول الذكاء الاصطناعي إلى أذونات النظام والبيانات الخاصة.

لكن بعض التهديدات تظل نظرية. سيكون من الصعب للغاية التنبؤ بهجوم تسميم البيانات، حيث يلعب المهاجمون لعبة طويلة الأمد عن طريق نشر بيانات ضارة عبر مصادر (على سبيل المثال، ريديت) معروفة بامتصاصها لتدريب الذكاء الاصطناعي. على سبيل المثال، ملء منتديات دعم الكمبيوتر بتوصيات لصق تعليمات خبيثة في المحطة الطرفية حتى تبدأ روبوتات الدردشة المدعومة بالذكاء الاصطناعي في ظهور تلك التعليمات استجابة لاستفسارات المستخدمين حول مشكلات الكمبيوتر الشائعة. وجدت دراسة نُشرت في أكتوبر 2025 وأجرتها شركة أنثروبيك، بالتعاون مع معهد أمن الذكاء الاصطناعي في المملكة المتحدة ومؤسسة آلان تورينغ، أنه يكفي 250 وثيقة خبيثة لإنشاء باب خلفي مخفي في نموذج الذكاء الاصطناعي يمكن استغلاله لاحقًا. تم بالفعل رؤية بعض الأدلة على هذه الهجمات في البرية، على الرغم من أن أكثرها براءة كانت اختبارات أجراها باحثون غير رسميين فضوليون.

في الوقت نفسه، تقوم نماذج الذكاء الاصطناعي بشكل متزايد بكتابة الكود المرسل إلى كل شيء بدءًا من أنظمة التشغيل إلى البنية التحتية المصرفية. وقد وجدت الأبحاث، بما في ذلك دراسة من جامعة نابولي والبحث الخاص بـ CodeRabbit، أن كود الذكاء الاصطناعي عرضة للأخطاء ويمتلك نقاط ضعف عالية الخطورة، حتى عند مراجعة الكود المُنشأ بواسطة إنسان. إن قدرات الذكاء الاصطناعي التي تتفوق في العثور على الأخطاء ولكنها تتفوق في كتابة الكود يمكن أن تبدو متناقضة بالنسبة للإنسان الذي ترتبط هذه المهارات عنده معًا.

الوكالات الذكية هي زميل عملك الأكثر سهولة في الإقناع والأكثر جهلا بالتكنولوجيا

لقطة مقربة لهاتف ذكي يعرض موقع مساعد OpenClaw AI. Koshiro K/Shutterstock

على مدار العام الماضي أو نحو ذلك، كانت الوكالات الذكية محور الحديث في الصناعة، مع أدوات مثل OpenClaw التي تسمح لأي شخص بتمكين وكالة ذكية لاستخدام حاسوبه نيابة عنه. قام عملاء الشركات بدمج الوكالات كمساعدين دردشة للدعم، ومساعدي الموارد البشرية للتوظيف والرواتب، وفي بيئات الترميز لإنتاج الشفرات، ومعالجة طلبات السحب وحتى نشر الشفرات. في الوقت نفسه، يقوم الأفراد بتوصيل الوكالات بالبريد الإلكتروني، والتقويمات، والمنازل الذكية، وحتى حسابات الاستثمار الخاصة بهم. كل ذلك رائع حتى تفكر فيه لمدة نصف ثانية وتدرك أنك منحت أذونات عالية المستوى - إن لم يكن وصولًا إداريًا كاملًا - لآلة غير مدركة تقوم بكل ما يُطلب منها. ببساطة because an AI can often recall good security practices when prompted doesn't mean it really understands how to enforce them. And while a prompt injection attack on a normal LLM can have devastating consequences, an agentic AI attack chain can do a lot more damage.

Think of your most gullible and tech-illiterate coworker, the one who tells IT their computer is broken before checking whether it's plugged in. Let's call them Greg. Now imagine you've given Greg admin-level access to your computer and online accounts, even when you're not there to supervise. It's only a matter of time before Greg gives your bank password to a phishing scammer. But AI agents are even dumber than Greg, and they've now proliferated through businesses and private devices.

The aforementioned attack on Meta's overly helpful Instagram support bot is an example of an AI agent attack. The bot was plugged directly into tools that let it act as a human support agent would, and the results were as obvious as they were inevitable. Where a human would have been more discerning in the requests it chose to fulfill, the AI acted more like a computer, carrying out the task it was asked to accomplish using the tools available to it.

المدافعون يستجيبون بحلول الذكاء الاصطناعي الخاصة بهم

مطورين يتعاونون في تطوير البرمجيات في بيئة مكتب حديثة. Athvisions/Getty Images

قد يوفر الذكاء الاصطناعي للمهاجمين قدرات معززة، لكن ذلك لا يعني استسلام المدافعين. قال خبراء الأمن السيبراني الذين أجرت شركة Trend Micro استطلاعًا لهم إن أولوياتهم الرئيسية هي الدفاع ضد الاحتيال والتزييف العميق، يليها منع هجمات التطبيقات مثل حقن المحفزات، وتسميم النماذج والاختراق. وقد أدرجوا بيئات الحوسبة السحابية كأكثر الأسطح صعوبة في المراقبة، تليها مراقبة ممارسات الأمن للموظفين عن بعد الذين يستخدمون أجهزتهم الخاصة للعمل.

وبالطبع، تُقدم أكبر الشركات جهودها الخاصة في أمن الذكاء الاصطناعي. بينما كان هذا المقال قيد الإعداد، أطلقت مايكروسوفت مشروع "Perception" (الإدراك)، وهو نظام أمان ذكاء اصطناعي يستخدم مجموعات من الوكلاء ليعكس التعاون التقليدي لأمن المعلومات. تُخصص مجموعة واحدة من الوكلاء للون الأحمر لاختبار الاختراق ومحاكاة الخصم، وأخرى باللون الأزرق للتحقيق وتقييم المخاطر، وثالثة باللون الأخضر للتكامل والتصحيح. يبدو أن الهدف هو تجاوز التهديد.

إذا كان أمن المعلومات لعبة القط والفأر، فإن الذكاء الاصطناعي حولها إلى واحدة من "الطريق السريع" (Roadrunner) و"ويلي إي كايوتي" (Wile E. Coyote). إما أننا جميعًا في ورطة مع تحول النماذج إلى جبن سويسري من كل دفاع، أو دخل الأمن لعالم جديد شجاع يتطلب ببساطة بعض التكيف التطوري. من المبكر معرفة ذلك، لذا الآن، نتخبط في فترة انتقالية لا نهاية لها ومليئة بالقلق.

AIcybersecurityhackers
الخبر متوفّر باللغات التالية:English
المصدر الأصلي للخبر
إنجاجيت

AI is changing cybersecurity in quick and terrifying ways

August 07, 2026·Engadget
AI is changing cybersecurity in quick and terrifying ways

Can the cybersecurity industry keep up?

By Max Miller Aug. 7, 2026 12:30 pm EST Gorodenkoff/Getty Images

Imagine I came to you with the following proposition: You will give me trillions of dollars. In exchange, I will build a machine that pollutes the environment, steals from every artist and academic on the planet, raises electricity bills and computer hardware prices, and can do marginally useful stuff like fill out spreadsheets and write basic code. To sweeten the deal, I will throw in a bridge in Brooklyn. Still not convinced? Then allow me to further pique your interest. This machine will also make all of your software less secure while enabling criminals and state-sponsored hackers to carry out more sophisticated cyberattacks than ever before.

That's a deal most people wouldn't sign off on, but it's exactly what we collectively got out of the generative AI boom. In addition to the oft-discussed impacts of AI on intellectual property and the environment, AI has already had a profound impact on cybersecurity. Anyone with access to LLMs now has the equivalent of a fedora-wearing, Monster Energy-slurping black hat hacker working around the clock on their payroll. And whereas many common attacks such as phishing have traditionally required time and research, they now require little more than the ability to copy and paste.

AI has already had seismic ramifications across security vectors, enhancing traditional attack methods from phishing to credential attacks while also giving rise to new social engineering schemes which leverage voice cloning and deepfakes and turbocharging the discovery of unique vulnerabilities. Defenders across the tech industry are responding with AI solutions of their own, but can they outspend and outengineer criminals, let alone equally well-funded state-level actors? Here's how AI has shifted the state of play in cybersecurity.

The paradox of AI cybersecurity

A graphic of hands pressing keys on a laptop with holographic icons of AI, apps and folders floating above. Wanan Yossingkum/Getty Images

There's a fundamental paradox at the intersection of AI and cybersecurity. While AI is useful for hardening security, it is a force multiplier for attackers. Not only does it have access to the statistical sum of the world's information, but it can synthesize across disciplines from coding to networking. No longer does a would-be cybercriminal need years of experience under their belt before carrying out a sophisticated attack. A capable LLM can be pointed at a potential victim and churn through tokens while the human attacker kicks back on the couch. As an article from the Harvard Extension School put it, "AI has democratized cybercrime."

Compounding the problem is the speed at which AI can work. What might take a human cybercriminal operation weeks to pull off can be accomplished in an afternoon with the help of an LLM. And criminals have access to more than one LLM. Many are running multiple AI sessions at once, or using multiple models. As described by VentureBeat, an AI-assisted attack from February that ransacked government databases in Mexico was carried out by attackers who fed outputs back and forth between Claude and ChatGPT. When one chatbot refused to help, the other was often willing to pick up its slack.

Humans are still necessary for now, and AI acts as a force multiplier rather than a replacement. But concerns are mounting. While this article was in process, OpenAI revealed that a model under sandboxed observation had escaped its (potentially porous) testing environment and hacked AI repository HuggingFace along with other services in order to procure answers for a synthetic benchmark.

You might think it's just as easy to harden a security posture, since defenders have equal access to the same LLMs, and in some cases to even more advanced models that are not yet available to the public. But cybersecurity is asymmetrical. Whereas a defender must protect every possible vulnerability, an attacker only needs to find one in most instances. This dynamic has created a proliferation of zero-day vulnerabilities — security flaws that shipped with a piece of software and were secretly discovered by hackers. Flaws that AI models have proven adept at uncovering.

AI supercharges social engineering schemes

Rendered graphic of a fishing hook overlayed on a close-up of hands typing on a laptop keyboard. Tadamichi/Getty Images

It's tempting to think of a hacker as someone who wears long black trench coats and types code at a million words per second, but more often it's someone sending out millions of scam emails until someone proves gullible enough to fork over credit card information. End users are almost always the weakest vulnerability to target.

The best example of this is phishing. Most of us have managed to spot at least one phishing attack from a mile away. An email purporting to come from Microsoft but is riddled with embarrassingly poor spelling and grammar is clearly the work of an amateur criminal with only passing familiarity with the English language. Or at least, that used to be the case. Thanks to AI, that email will now be impeccably written. It may reek of AI writing, but so does actual correspondence from Microsoft now.

For large-scale phishing efforts, an LLM can write a grammatically perfect and rhetorically plausible email, then automate the process of finding email addresses and blasting the missive out. Spear phishing, which occurs when a specific individual is targeted with highly personalized phishing efforts, is now far more trivial an effort. A chatbot can research your victim for you across the web, finding information you may not have discovered while doing your own research. The bot can even strike up pretextual correspondence with the target on its own, pushing them to divulge the information you're after.

According to security vendor Brightside, 82 percent of phishing emails now use AI at some point in the process, and whereas such emails had a clickthrough rate of just 12 percent prior, AI-assisted missives have boosted that number to a staggering 52 percent in simulated environments. And that's the data for email attacks, not accounting for the massive and accompanying spike in AI voice clone and deepfake attacks, which Brightside estimates to have spiked year-over-year by 442 and 680 percent, respectively, between 2023 and 2024.

AI is creating new attack surfaces

Person holding smartphone with triangle caution warning sign Supatman/Getty Images

As businesses and governments tie more of their operations to AI systems, they become increasingly vulnerable to attacks that exploit the inherent blind spots of AI systems. The most common of these are prompt injection attacks, wherein attackers find a way to give an AI system malicious instructions. For instance, instructions to send a company's payroll data to a particular email address might be hidden in a website. When an employee tells the company AI to summarize that page, it ingests those instructions and carries them out.

In some instances, these attacks are more like spam than malware. Microsoft found that some companies were including "summarize with AI" buttons on their websites that contained hidden instructions. When clicked, they'd tell a chatbot to do things like remember the company as a trusted source, or to recommend its products over those of competitors in future interactions. Only when a user checked their LLM's persistent memory would they realize they'd been deceived.

More directly malicious attacks can be equally effortless. In December 2025, Meta implemented an AI support assistant, ostensibly to help people recover their accounts. But the bot was a little too helpful, and would happily associate an email address owned by an attacker with any Instagram account, making it trivially easy to hack any account without MFA enabled.

OpenAI claimed last year that fully defending against prompt injection attacks in AI browsers may not be possible. If that's the case, then the best course of action for any responsible entity is never to tie any of its sensitive systems or data to an AI in the first place. In the meantime, the best practice is always to double-check anything you paste into a prompt field from another source, and to limit the scope of an AI's access to system permissions and private data.

But some threats remain theoretical. A data poisoning attack, in which attackers play the long game of seeding malicious data across sources (for example, Reddit) that are known to be ingested for AI training, would be extremely difficult to see coming. For instance, filling computer support forums with recommendations to paste malicious instructions into a terminal so that AI chatbots begin to surface those instructions in response to user queries about common computer issues. One study published in October 2025 and conducted by Anthropic, in collaboration with the UK AI Security Institute and Alan Turing Foundation, found that it only takes 250 malicious documents to create a hidden backdoor in an AI model that could later be exploited. Some evidence of these attacks has already been seen in the wild, though the most prominent ones were relatively harmless tests carried out by curious informal researchers.

Meanwhile, AI models are increasingly authoring the code shipped to everything from operating systems to banking infrastructure. Research, including a study from the University of Naples and private research by CodeRabbit, has found AI code to be error-prone and to have more high-risk vulnerabilities, even when the generated code is reviewed by a human in the loop. Worse at writing code but better at finding bugs, AI capabilities can feel paradoxical to a human for whom those skills go hand-in-hand.

AI agents are your most gullible and tech illiterate coworker

A close-up of a smartphone displaying the OpenClaw AI assistant website. Koshiro K/Shutterstock

Over the past year or so, AI agents have been the talk of the industry, with tools like OpenClaw allowing anyone to let an AI use their computer for them. Enterprise clients have integrated agents as support chatbots, HR assistants for hiring and payroll, and in coding environments to pump out code, handle pull requests and even to deploy code. Private individuals, meanwhile, are hooking agents up to their emails, calendars, smart homes, and even their investment accounts. All of that sounds great until you think about it for half a second and realize you've given high-level permissions — if not full admin access — to an unthinking machine that does whatever it's told. Simply because an AI can often recall good security practices when prompted doesn't mean it really understands how to enforce them. And while a prompt injection attack on a normal LLM can have devastating consequences, an agentic AI attack chain can do a lot more damage.

Think of your most gullible and tech-illiterate coworker, the one who tells IT their computer is broken before checking whether it's plugged in. Let's call them Greg. Now imagine you've given Greg admin-level access to your computer and online accounts, even when you're not there to supervise. It's only a matter of time before Greg gives your bank password to a phishing scammer. But AI agents are even dumber than Greg, and they've now proliferated through businesses and private devices.

The aforementioned attack on Meta's overly helpful Instagram support bot is an example of an AI agent attack. The bot was plugged directly into tools that let it act as a human support agent would, and the results were as obvious as they were inevitable. Where a human would have been more discerning in the requests it chose to fulfill, the AI acted more like a computer, carrying out the task it was asked to accomplish using the tools available to it.

Defenders are responding with AI solutions of their own

Programmers collaborating on software development in a modern office setting. Athvisions/Getty Images

AI may provide threat actors with supercharged capabilities, but that doesn't mean defenders are throwing their hands up in defeat. Cybersecurity professionals surveyed by Trend Micro said their top priority was defending against fraud and deepfakes, followed by preventing application attacks such as prompt injections, model poisoning and jailbreaking. They listed cloud environments as the most difficult surfaces to patrol, followed by keeping tabs on the security practices of remote workers who use their own devices for work.

Of course, the largest firms are making their own go of AI security. While this article was in production, Microsoft rolled out Project Perception, an agentic AI security system that uses agentic clusters to mirror traditional cybersecurity teaming. One cluster of agents is designated red for penetration testing and adversarial simulation, another blue for investigation and risk assessment, and a third green for integration and remediation. The goal, it seems, is to outpace the threat.

If cybersecurity is a game of cat and mouse, then AI has turned it into one of Roadrunner and Wile E. Coyote. Either we're all screwed as the models make Swiss cheese of every defense, or security has entered a brave new world that simply requires a bit of evolutionary adaptation. It's too soon to tell, so for now, we grope our way through an interminable and anxious interregnum.

AIcybersecurityhackers
This article is also available in:العربية
Original source article
Engadget