Google Threat Intel Findings on Adversarial AI 

A new report by Google Threat Intelligence Group (GTIG) took a look at the Q2 standings of adversarial AI, finding that threat actors are using multi-agent AI frameworks to automate credential theft, with one attacker building and deploying a campaign that harvested thousands of credentials in under six hours. 

Scott Miserendino, Chief Technology Officer at DataBee, A Comcast Company:

“GTIG’s findings point to a shift in the threat landscape, the same AI tools that accelerate software development and other business processes are now targets themselves. It is little surprise that threat actors have found success in leveraging AI across the kill chain. The fact that attackers are stealing API credentials to AI models and hijacking cloud environments, however, to run unauthorized AI workloads signals that access to frontier AI may be becoming as valuable as traditional data theft. Threat actors are adapting to the economics of AI not just using the technology.”

Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth

“These multi-agent attacks move faster and hit more systems than most security platforms can detect. The prize now goes beyond ransoming or selling your confidential data – access to your proprietary AI models and compute resources are a direct target too. LLMjacking, the arbitrage of stolen IaaS and premium-model compute, is a booming business, and against the top-tier models it can cost victims over $100,000 a day.

The best defense remains short-lived tokens (and the monitoring to ensure they are not being used by attackers), keeping credentials safe from LLMs by using secrets managers, and strong permission models that enforce least privilege at every layer of the stack.”

I’ve said it before and I will say it again. Your plans to defend yourself have to include AI. If not, it is a matter of when not if you will get pwned.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading