2026年8月28日 星期五

人工智能並非網絡安全的最大難題。最大的問題是人 (2/2)

Recently CNN reported the following:

AI isn’t the biggest cybersecurity problem. People are (2/2)

BUSINESS TECH

CNN - By Lisa Eadicicco

AUG 9, 2026

(continue)

How hackers are using AI

AI isn’t acting autonomously to come up with new attacks, experts say. Instead, it’s helping cyber criminals implement existing techniques much faster while being more efficient and effective.

That can include things like using AI to analyze a company’s website to figure out who to target or deploying an AI agent to handle initial negotiation talks with a cyber extortion victim. AI agents can mimic human conversations through both text and even specific voices. Hackers with little expertise can now leverage AI to pull off advanced schemes.

“They’re using (AI) to enhance the cyberattack methodology, essentially, in all the different stages, but it’s still kind of being run by the human,” said Jud Dressler, head of the risk operations center at cyber insurance firm Resilience.

Bad actors used to hastily scrap together basic scripts – instructions for automating tasks – to achieve their goals, according to Meyers. But now they’re able to churn out higher quality work that looks like it would have taken three times as long to produce.

They’re also using AI for behind-the-scenes work like generating the infrastructure needed to put up malicious websites.

“With AI, they could automate that buildout, and so the cost of rebuilding became very small and that changes the game,” said Rob Lefferts, corporate vice president of threat protection at Microsoft.

The bigger threat

For Etzioni, the recent incidents are a “canary in the coal mine” moment for AI and cybersecurity. And he’s not alone; Nobel prize-winning computer scientist Geoffrey Hinton, known popularly as the “godfather of AI,” recently warned that more rogue AI attacks are likely to come.

The rogue AI reports underscore the importance of implementing strong cybersecurity practices, such as patching vulnerabilities, monitoring AI agents in the workplace and being wary of social engineering and phishing scams, experts say.

But as advanced as AI is becoming, it’s still a program being orchestrated by a human. And those humans are the bigger concern because they’re the ones making the decisions, like conducting espionage or scamming users out of huge sums of cash, says Meyers.

Tech giants are racing to make AI as intelligent as humans, a theoretical milestone known as “artificial general intelligence.” The recent incidents, however, have heightened calls for a slowdown.

More than 1,200 workers at top AI companies, including Anthropic CEO Dario Amodei, recently signed an open letter calling for the government to help pace AI development. The White House met with major AI companies last week to discuss a framework that would allow the government to review certain AI models before they’re released.

Cybersecurity researchers have likely considered the threats of AGI because those in the field tend to be paranoid, said IBM’s Fussell. But we’re still far from a reality in which AI agents are as smart as humans, he says.

“It’s like asking someone, ‘What would it be like to live on a different planet?’” he said. “You can sort of imagine, but it’s so beyond our ability to really make a plan for.”

Translation

人工智能並非網絡安全的最大難題。最大的問題 (2/2)

 (繼續)

 駭客如何利用人工智能

 專家表示,人工智能並不會自主地發動新的攻擊。相反,它能幫助網絡犯罪分子更快實施現有技術,同時提高效率和效果。

 這包括利用人工智能分析公司網站,確定攻擊目標;或部署人工智能代理來處理與網路勒索受害者的初步談判。人工智能代理可以透過文字甚至特定語音來模仿人類對話。如今,經驗不足的駭客也能利用人工智能實施高難度計劃。

 網絡保險公司 Resilience 的風險營運中心負責人 Jud Dressler :「他們基本上是在利用人工智能來增強網路攻擊方法的各個階段,但最終還是由人來操控」。

 Meyers稱,過去,惡意攻擊者會匆忙拼湊一些簡單的腳本 - 即自動化任務的指令 - 來達到目的。但現在,他們能夠快速生成更高品質的作品,看起來就像是需要花費三倍的時間才能完成的。

他們也利用人工智能進行幕後工作,例如產生搭建惡意網站所需的基礎設施。

微軟的威脅防護企業副總裁 Rob Lefferts :「有了人工智能,他們可以自動化建造這些基礎設施,因此重建的成本變得非常低,這改變了遊戲規則」。

更大的威脅

對 Etzioni 來說,最近發生的事件是人工智能和網絡安全領域的「警示時刻」。而且這並非是孤例;被譽為「人工智能之父」的諾貝爾獎得主、電腦科學家 Geoffrey Hinton 最近也警告說,未來可能會出現更多惡意人工智能攻擊。

專家表示,人工智能失控事件凸顯了實施強有力的網路安全措施的重要性,例如修補漏洞、監控工作場所中的人工智能代理,以及警覺社交工程和網絡釣魚詐騙。

但 Meyers 指出,儘管人工智能技術日益先進,但它仍然是由人類操控的程式。而人類才是更令人擔憂的對象,因為正是他們做出決策,例如進行間諜活動或詐騙用戶巨額資金。

科技巨頭們正競相使人工智能達到與人類相同的智能水平,這一理論里程碑被稱為「通用人工智能」(“artificial general intelligence.”)。然而,近期發生的事件加劇了人們對放緩人工智能發展步伐的呼聲。

包括 Anthropic 執行長 Dario Amodei 在內的1,200多名頂尖人工智能公司員工近期簽署了一封公開信,呼籲政府協助調整人工智能的發展速度。上週,白宮與多家大型人工智能公司會面,討論一項框架,該框架將允許政府在某些人工智能模型發佈前對其進行審查。

IBM 的 Fussell 表示,網絡安全研究人員之所以會考慮通用人工智能(AGI)的威脅,可能是因為該領域的從業人員往往比較執着。但他又指出,人工智能代理可以達到人類水準的現實還是很遙遠。

他說道:“這就像問別人‘生活在另一個星球上會是什麼感覺?’”; “你可以大致想像一下,但這完全超出了我們為這制定計劃的能力範圍。”

So, cases of AI escaping the lab, infiltrating other companies and trying to deceive people have all made headlines in recent weeks. AI isn’t the mastermind behind today’s most widespread cyber threats; it’s people who use AI to do bad things. More than 1,200 workers at top AI companies recently sign an open letter calling for the government to help pace AI development. For some AI experts, the recent incidents are  wakeup calls for AI and cybersecurity. Apparently, more rogue AI attacks are likely to appear.

沒有留言:

張貼留言