Key takeaways

  • Can you imagine a future when script kiddies -- low- or no-skill wannabe hackers who use prewritten scripts or tools to cause havoc -- can…
  • Launched in April, Unit 42's service combines threat intelligence, threat telemetry, and frontier AI models to help enterprise clients…
  • If we consider this result and how the speed of AI-based vulnerability discovery and testing can be applied, we can also understand just…

What happened

Can you imagine a future when script kiddies -- low- or no-skill wannabe hackers who use prewritten scripts or tools to cause havoc -- can shake the foundations of cyberdefense? According to Palo Alto Networks' Unit 42 research team, that's a "probable" scenario. In a briefing on Wednesday, Unit 42 discussed early findings from its new service, Frontier AI Defense.

" The elements of a cyberattack, from discovering vulnerabilities to developing malware or conducting social engineering, used to require manual execution. But now, AI can take over many of these tasks -- which gives cybercriminals "the time and energy back to be more effective," according to Rubin. There's also the matter of speed.

During the cybersecurity firm's work on its new service, the team found that AI could be used to identify and exploit vulnerabilities, escalate privileges, and steal data all within 10 hours in an operation that would normally take a penetration testing team around two weeks.

We asked DeGrippo if she could see a future in which old-school hacktivism, like Anonymous, makes a resurgence powered by AI -- and whether this is something defenders and organizations should be concerned about.

" There's also the prospect that attribution will become far more difficult in the future, as AI and open access to associated tools will make identifying who is responsible for attacks and their origins even more challenging for defenders. "[AI] is opening up the landscape to the groups that haven't been that much of a concern," DeGrippo says.

Why it matters

Launched in April, Unit 42's service combines threat intelligence, threat telemetry, and frontier AI models to help enterprise clients address security issues that have become urgent due to AI. The team says that in three weeks of internal tests, Unit 42 completed the equivalent of about one or two years of penetration testing, uncovering dozens of vulnerabilities across customer environments using AI pen-testing models.

If we consider this result and how the speed of AI-based vulnerability discovery and testing can be applied, we can also understand just how much impact AI models could have for cybercriminals using the same tools for their own malicious ends. We're not just talking about skilled, well-funded cybercriminals, either.

When we consider cyberattacks today, we tend to organize them into two main categories: cyberattacks driven by financial goals, or attacks carried out by state-sponsored threat actors, who may seek information, disrupt or destroy, or conduct surveillance. There are smaller categories, too, such as hacktivists and those who commit malicious actions for social or political reasons.

According to Unit 42, it's the sudden AI-enabled power boost for these individuals that we need to watch. In the briefing, Sherrod DeGrippo, VP Threat Intelligence at Unit 42, said that the traditional categories of cyberattacks have shifted, and that socially motivated groups are being "enabled with the same tooling and sophistication as a state-sponsored group" due to artificial intelligence.

"This part of the landscape will continue to increase and bring in low-skilled actors that now have exponentially bigger and better capabilities than we've seen before," DeGrippo commented. " In the past, most script kiddies and hacktivists -- lacking an adequate understanding of the underlying technology or programming languages to modify digital weapons for their specific goals -- have relied on others' tools, scripts, and programs.

Now, with the backing of AI to run analyses, reverse-engineer, or even develop tools for them (if the right guardrails aren't in place), these lower-skilled groups have far more at their disposal without the need to upskill. Unit 42 calls AI a "force multiplier" that is changing how cybersecurity operates.

While we've seen threat actors experimenting with AI and large language models (LLMs) piece by piece in the attack chain -- such as improving phishing campaigns, translating language, or assisting with ransomware negotiations -- AI is now being used across the entire process. An example is JadePuffer, which is believed to be a fully agentic ransomware attack, with every stage handled by AI from beginning to end.

What to watch

"Individuals who have a vendetta against previous employers, a business they did business with and didn't get what they were promised -- now have the capabilities where they are well-enabled with tooling to carry out malicious activity if they want to.

" There's only so much that can be prepared for, DeGrippo noted, as the impact of AI on cybersecurity threats and defense is constantly changing, and this "transformative period" is one we simply have to get through. AI threats have now become a board-level conversation, which is certainly a start. Best practices that organizations should consider adopting include: "None of us are prepared for what is constantly evolving," DeGrippo added. "CISOs need to think about what their agentic AI strategy is, top to bottom.