成人小说亚洲一区二区三区,亚洲国产精品一区二区三区,国产精品成人精品久久久,久久综合一区二区三区,精品无码av一区二区,国产一级a毛一级a看免费视频,欧洲uv免费在线区一二区,亚洲国产欧美中日韩成人综合视频,国产熟女一区二区三区五月婷小说,亚洲一区波多野结衣在线

首頁 500強 活動 榜單 商業(yè) 科技 商潮 專題 品牌中心
雜志訂閱

新的網(wǎng)絡安全威脅:AI代理

Christian Vasquez
2025-02-26

新型AI代理可能對網(wǎng)絡安全防御者和企業(yè)形成巨大沖擊。

文本設置
小號
默認
大號
Plus(0條)

圖片來源:Getty Images, Surasak Suwanmake

科技界正在熱議能夠自主執(zhí)行任務的AI“代理”所蘊含的商業(yè)潛力。但對于負責保護企業(yè)免受網(wǎng)絡犯罪侵害的安全從業(yè)者而言,這類AI工具的涌入意味著他們需要應對一個棘手的新對手。

安全專家將這種能夠分多個步驟自主解決問題的"代理型"AI工具列為2025年最大的威脅之一。盡管基于OpenAI的GPT模型等生成式工具的AI黑客攻擊,尚未如人們所擔心的那樣猖獗,但AI代理正為網(wǎng)絡罪犯進行強大的軍火庫升級,使這種工具的角色從基礎助手轉(zhuǎn)變?yōu)橛啦黄>氲摹胺e極且活躍的幫兇”。

令人擔憂的是,在現(xiàn)有安全團隊已疲于應對的當下,這些新型AI代理可能對網(wǎng)絡安全防御者和企業(yè)形成巨大沖擊。

網(wǎng)絡安全公司Malwarebytes的技術布道師馬克·斯托克利表示:“代理型網(wǎng)絡攻擊者帶來的風險在于,‘大型’網(wǎng)絡攻擊可能成為日常操作,令安全團隊不堪重負?!贝祟惞敉ǔa槍ψ鴵砬f乃至上億美元資金的高價值目標。

斯托克利指出,AI代理“能極大擴展大型勒索軟件攻擊的規(guī)模,使網(wǎng)絡罪犯擺脫當前的技術瓶頸”。

與此同時,谷歌(Google)威脅分析小組的最新研究顯示,以牟利為目的的黑客與試圖隱匿惡意行為的國家行為體正加強勾結。隨著犯罪生態(tài)對執(zhí)法行動的韌性增強,美國及其盟國采用破壞性打擊手段的難度日益增加;在當今網(wǎng)絡犯罪黑市中,黑客更替猶如走馬燈般頻繁。

谷歌威脅情報副總裁桑德拉·喬伊斯在聲明中表示:“網(wǎng)絡犯罪生態(tài)的核心市場讓每個參與者都易于被替代,整個體系具備抗干擾韌性。遺憾的是,我們的諸多行動只能給犯罪分子帶來暫時的困擾,但我們絕不能掉以輕心,必須加倍努力實現(xiàn)實質(zhì)性打擊?!?/p>

迭代越快,風險越高

專家警告稱,正如OpenAI在2024年2月的報告中所言,當前AI模型對“惡意網(wǎng)絡安全任務僅有有限增量能力”的時代即將終結。更嚴峻的是,AI編程工具的普及將導致劣質(zhì)代碼激增,黑客及其AI代理可利用的漏洞也將隨之暴增。

軟件安全公司Contrast Security的聯(lián)合創(chuàng)始人兼首席技術官杰夫·威廉姆斯表示:“不幸的是,所有模型都基于存在漏洞的代碼訓練,它們所生成的代碼必然繼承缺陷。這意味著代碼越多、漏洞越多、迭代越快,用戶面臨的風險就越大。”

Malwarebytes的斯托克利指出,勒索軟件攻擊的天然瓶頸在于,高水平黑客的數(shù)量與防御專家規(guī)模的制衡。但隨著AI代理的擴散,這種平衡可能被打破。

以釣魚郵件為例:針對已識破“尼日利亞王子”等低劣騙局的警惕用戶,黑客利用文本生成工具設計更逼真的騙局。生成式AI工具能輕易擴大此類攻擊的規(guī)模并提升可信度,但它能為潛在黑客做的只有這些,而如何將惡意點擊轉(zhuǎn)化為持續(xù)收益仍是難題。AI代理則可能指導潛在黑客在得手之后如何進行后續(xù)操作。

斯托克利認為:“短期內(nèi),企業(yè)需借助自動化技術盡量將攻擊面最小化,讓安全團隊專注于高影響、高價值工作?!彼硎荆瑸榱藨獙σ?guī)模不斷擴大的威脅,企業(yè)未來的防御方向應是投資網(wǎng)絡安全專用AI代理。

Malwarebytes的報告警告,資金雄厚的勒索軟件團伙可能利用AI代理同時攻擊多個目標。2024年,盡管LockBit、ALPHV等大型犯罪團伙遭到執(zhí)法機構的更多打擊,但已知攻擊增加數(shù)量仍創(chuàng)歷史新高。

谷歌的最新報告顯示,隨著更多國家試圖從黑客處購買網(wǎng)絡工具和能力,攻擊規(guī)?;?qū)⑦M一步擴大。

報告指出:“每日海量發(fā)生的逐利型網(wǎng)絡入侵會產(chǎn)生累積效應,不僅削弱國家經(jīng)濟競爭力,更令防御者不堪重負,導致戰(zhàn)備水平下降與職業(yè)倦怠。”

一場看似普通的勒索軟件攻擊,幕后可能是國家扶持的黑客,他們擁有遠超普通黑客的資源與耐心,對企業(yè)的威脅程度將呈指數(shù)級上升。

面對國家扶持的黑客,企業(yè)雖常處劣勢,但可通過基礎安全措施實現(xiàn)自我保護,例如升級遺留系統(tǒng),這類系統(tǒng)最容易成為勒索軟件團伙和國家黑客的首選目標。(財富中文網(wǎng))

譯者:劉進龍

審校:汪皓

科技界正在熱議能夠自主執(zhí)行任務的AI“代理”所蘊含的商業(yè)潛力。但對于負責保護企業(yè)免受網(wǎng)絡犯罪侵害的安全從業(yè)者而言,這類AI工具的涌入意味著他們需要應對一個棘手的新對手。

安全專家將這種能夠分多個步驟自主解決問題的"代理型"AI工具列為2025年最大的威脅之一。盡管基于OpenAI的GPT模型等生成式工具的AI黑客攻擊,尚未如人們所擔心的那樣猖獗,但AI代理正為網(wǎng)絡罪犯進行強大的軍火庫升級,使這種工具的角色從基礎助手轉(zhuǎn)變?yōu)橛啦黄>氲摹胺e極且活躍的幫兇”。

令人擔憂的是,在現(xiàn)有安全團隊已疲于應對的當下,這些新型AI代理可能對網(wǎng)絡安全防御者和企業(yè)形成巨大沖擊。

網(wǎng)絡安全公司Malwarebytes的技術布道師馬克·斯托克利表示:“代理型網(wǎng)絡攻擊者帶來的風險在于,‘大型’網(wǎng)絡攻擊可能成為日常操作,令安全團隊不堪重負?!贝祟惞敉ǔa槍ψ鴵砬f乃至上億美元資金的高價值目標。

斯托克利指出,AI代理“能極大擴展大型勒索軟件攻擊的規(guī)模,使網(wǎng)絡罪犯擺脫當前的技術瓶頸”。

與此同時,谷歌(Google)威脅分析小組的最新研究顯示,以牟利為目的的黑客與試圖隱匿惡意行為的國家行為體正加強勾結。隨著犯罪生態(tài)對執(zhí)法行動的韌性增強,美國及其盟國采用破壞性打擊手段的難度日益增加;在當今網(wǎng)絡犯罪黑市中,黑客更替猶如走馬燈般頻繁。

谷歌威脅情報副總裁桑德拉·喬伊斯在聲明中表示:“網(wǎng)絡犯罪生態(tài)的核心市場讓每個參與者都易于被替代,整個體系具備抗干擾韌性。遺憾的是,我們的諸多行動只能給犯罪分子帶來暫時的困擾,但我們絕不能掉以輕心,必須加倍努力實現(xiàn)實質(zhì)性打擊?!?/p>

迭代越快,風險越高

專家警告稱,正如OpenAI在2024年2月的報告中所言,當前AI模型對“惡意網(wǎng)絡安全任務僅有有限增量能力”的時代即將終結。更嚴峻的是,AI編程工具的普及將導致劣質(zhì)代碼激增,黑客及其AI代理可利用的漏洞也將隨之暴增。

軟件安全公司Contrast Security的聯(lián)合創(chuàng)始人兼首席技術官杰夫·威廉姆斯表示:“不幸的是,所有模型都基于存在漏洞的代碼訓練,它們所生成的代碼必然繼承缺陷。這意味著代碼越多、漏洞越多、迭代越快,用戶面臨的風險就越大?!?/p>

Malwarebytes的斯托克利指出,勒索軟件攻擊的天然瓶頸在于,高水平黑客的數(shù)量與防御專家規(guī)模的制衡。但隨著AI代理的擴散,這種平衡可能被打破。

以釣魚郵件為例:針對已識破“尼日利亞王子”等低劣騙局的警惕用戶,黑客利用文本生成工具設計更逼真的騙局。生成式AI工具能輕易擴大此類攻擊的規(guī)模并提升可信度,但它能為潛在黑客做的只有這些,而如何將惡意點擊轉(zhuǎn)化為持續(xù)收益仍是難題。AI代理則可能指導潛在黑客在得手之后如何進行后續(xù)操作。

斯托克利認為:“短期內(nèi),企業(yè)需借助自動化技術盡量將攻擊面最小化,讓安全團隊專注于高影響、高價值工作。”他表示,為了應對規(guī)模不斷擴大的威脅,企業(yè)未來的防御方向應是投資網(wǎng)絡安全專用AI代理。

Malwarebytes的報告警告,資金雄厚的勒索軟件團伙可能利用AI代理同時攻擊多個目標。2024年,盡管LockBit、ALPHV等大型犯罪團伙遭到執(zhí)法機構的更多打擊,但已知攻擊增加數(shù)量仍創(chuàng)歷史新高。

谷歌的最新報告顯示,隨著更多國家試圖從黑客處購買網(wǎng)絡工具和能力,攻擊規(guī)?;?qū)⑦M一步擴大。

報告指出:“每日海量發(fā)生的逐利型網(wǎng)絡入侵會產(chǎn)生累積效應,不僅削弱國家經(jīng)濟競爭力,更令防御者不堪重負,導致戰(zhàn)備水平下降與職業(yè)倦怠。”

一場看似普通的勒索軟件攻擊,幕后可能是國家扶持的黑客,他們擁有遠超普通黑客的資源與耐心,對企業(yè)的威脅程度將呈指數(shù)級上升。

面對國家扶持的黑客,企業(yè)雖常處劣勢,但可通過基礎安全措施實現(xiàn)自我保護,例如升級遺留系統(tǒng),這類系統(tǒng)最容易成為勒索軟件團伙和國家黑客的首選目標。(財富中文網(wǎng))

譯者:劉進龍

審校:汪皓

The tech industry is abuzz over the business potential of AI “agents,” which can execute tasks on their own. For those tasked with protecting organizations against cybercriminals however, the influx of AI agents will mean preparing for a challenging new adversary to contend with.

Security experts now view “agentic” AI tools that engage in multi-step problem solving and act on them autonomously as one of 2025’s biggest threats.And while the explosion of AI-enabled hacks powered by generative tools like OpenAI’s GPT models may not have been as bad as some feared, AI agents present cybercriminals with a powerful new upgrade to their arsenal, changing the tool from a basic assistant to an active and eager co-worker that never needs to sleep.

The concern is that these new AI agents could overwhelm cybersecurity defenders and businesses alike at a time when the workforce is struggling to keep up.

“The risk of agentic attackers is that it could make ‘big game’ attacks an everyday norm, overwhelming security teams,” said Mark Stockley, cybersecurity evangelist at the cyber firm Malwarebytes. Big game attacks are typically high-profile targets with millions or billions in company coffers.

Stockley said that AI agents “could scale up big game ransomware attacks enormously, freeing cybercriminals from the scaling problems that currently hold them back.”

At the same time, new research from Google’s Threat Analysis Group is showing tighter collaborations between criminal hackers looking for financial gain and nation-states seeking to hide malicious activity. The U.S. and international allies face increasing difficulty using disruptive methods as the criminal ecosystem becomes more resilient against law enforcement activities; malicious hackers are quick to replace and be replaced in today’s criminal underworld.

“The marketplace at the center of the cybercrime ecosystem has made every actor easily replaceable and the whole problem resilient to disruption. Unfortunately, many of our actions have amounted to temporary inconveniences for these criminals, but we can’t treat this like a nuisance and we will have to work harder to make meaningful impacts,” Sandra Joyce, vice president of Google Threat Intelligence, said in a statement.

More velocity, more risk

Experts warn that the time is drawing to a close when current AI models amount to “l(fā)imited incremental capabilities for malicious cybersecurity tasks” as OpenAI noted in a February 2024 report. What’s more, the increase of AI-tools for software development will inevitably result in an increase in bad code, and as a result, more vulnerabilities will be available for hackers and their AI agents to abuse.

“Unfortunately, all the models were trained on code that has vulnerabilities, so the generated code will too. That means more code, more vulnerabilities, more velocity, and more risk for consumers,” said Jeff Williams, co-founder and chief technology officer at the software security firm Contrast Security.

Stockley, of Malwarebytes, points out that one of the natural bottlenecks on ransomware attacks has long been the amount of skilled hackers plying their trade, versus the skilled security professionals working to stop them. That balance could be upset as AI agents proliferate.

Take email phishing as an example: hackers use text generation tools to create realistic lures for victims who have become wise to lower-quality scams such as the fake Nigerian prince. Generative AI tools are an easy way to increase the scale and believability of those types of attacks — but that can only get a would-be hacker so far, since learning how to turn a malicious click into steady income is a challenge not as easily solved. Agents could be the next step to advising those would-be hackers on what to do after successfully tricking a victim.

“In the short term, organizations will need to turn to automation to ensure their attack surface is always as small as possible, and that security teams are free to focus on high impact, high value work,” said Stockley. Future goals for a business looking to keep up with the scale of threats would be to invest in cybersecurity-focused AI agents to further scale up defensive efforts, he said.

Malwarebyte’s report warns that well-funded ransomware gangs could use agents to attack multiple targets at the same time. Already, 2024 saw the biggest increase of known attacks even as some of the largest players like LockBit and ALPHV saw increased disruptions from law enforcement.

The scale of attacks is further expected to be exacerbated by the increase of states looking to purchase cyber tools and capabilities from criminal hackers, according to Google’s latest report.

“The enormous volume of financially motivated intrusions occurring every day also has a cumulative impact, hurting national economic competitiveness and placing huge strain on cyber defenders, leading to decreased readiness and burnout,” said Google’s report.

A cyberattack that appears to be a run-of-the-mill ransomware extortion could actually be state-backed hackers with far more resources and patience than your typical hacker and raising the threat to a business exponentially.

Businesses looking to protect themselves against state-backed hackers are often far outmatched, but can protect themselves by taking some basic security steps to modernize legacy systems, which is often an easy first target by ransomware gangs and state-backed hackers alike.

財富中文網(wǎng)所刊載內(nèi)容之知識產(chǎn)權為財富媒體知識產(chǎn)權有限公司及/或相關權利人專屬所有或持有。未經(jīng)許可,禁止進行轉(zhuǎn)載、摘編、復制及建立鏡像等任何使用。
0條Plus
精彩評論
評論

撰寫或查看更多評論

請打開財富Plus APP

前往打開
熱讀文章
玩弄人妻少妇500系列视频| 久久久精品波多野结衣| 无码少妇一区二区| 99久久免费高清热精品6| 久久精品国产亚洲AV果冻传媒| 亚洲日韩国产新品| 日韩免费无码成人久久久久久片| 办公室娇喘的短裙老师在线视频| 特级无码毛片免费视频尤物| 欧美V国产V亚洲V日韩九九| 人妻系列无码专区五月天| 国产午夜亚洲精品理论片不卡| 亚洲人成自拍网站在线观看| 久久无码精品一区二区三区| 精品人妻大屁股白浆无码| 欧美多人片高潮野外做片黑人| 精品无码一区二区三在线观看| 93精91精品国产综合久久香蕉| 又色又爽又黄的视频日本| 国产成人免费视频精品| 产欧美日韩综合精品一区二区三区| 国产在线精品观看一区欧美国产精品不卡在线观看| 99久久精品免费看国产一区二区三区| 久99中文在线视频| 国产精品欧美亚洲韩国日本久久| 日韩一区二区三区无码视频| 亚洲中文字幕无码亚洲人成影院| 中文字幕无码a∨高清毛片在线看| 2024国内精品久久久久精品k8| 中文字幕一区二区无码厨房| 国产三级精品三级男人的天堂| 办公室特殊服务2在线观看| 国产无玛精品一区二区三区| 亚洲精品国产电影| 国产精品日韩专区第一页| 国产精品视频久久久久久久久久| 少妇午夜中文字幕无码无删减| 国产福利113精品一区二区三区| 尤物爽到高潮潮喷视频大全| 国产老妇伦国产熟女老妇视频| 国产婷婷一区二区三区|