AI Agents Are Poised to Reshape Cybersecurity — And Not for the Better

We’re standing at the edge of a new era in cybersecurity — one where AI agents could very well be on both sides of the battlefield.

2 mins read
A representational image [FreePik]

MIT Technology Review reports a looming shift in cybercrime tactics as AI agents begin to demonstrate hacking potential.

AI agents — the next generation of intelligent assistants capable of planning, reasoning, and executing complex tasks — are quickly becoming the cybersecurity world’s biggest concern. While these tools can help automate useful actions like scheduling or device management, experts warn they could just as easily be used for more sinister purposes: launching autonomous cyberattacks.

According to a recent MIT Technology Review report, researchers and cybersecurity professionals are seeing signs that AI agents may soon become powerful tools for hackers. These agents are far more adaptive than traditional bots and could identify vulnerable targets, infiltrate systems, and steal data with unprecedented speed and scale.

So far, these attacks are largely theoretical — but not for long. Security researchers have already demonstrated AI agents executing successful simulated attacks. Anthropic, for instance, reported that its Claude LLM was able to replicate an information-stealing exploit, raising alarms about how close we are to real-world threats.

“I think ultimately we’re going to live in a world where the majority of cyberattacks are carried out by agents,” said Mark Stockley, a security expert at Malwarebytes. “It’s really only a question of how quickly we get there.”

To anticipate that reality, Palisade Research launched the LLM Agent Honeypot — a project that lures potential AI agents into interacting with fake servers filled with mock government and military data. Since launching in October last year, the honeypot has logged over 11 million access attempts. Among those, eight appeared to be AI agents, and two were confirmed: one traced to Hong Kong, the other to Singapore.

These agents weren’t simple bots. Unlike scripted programs that rely on brute force, AI agents displayed adaptive behaviors. They passed prompt-injection tests designed to gauge reasoning ability and responded faster than a human ever could — a key marker of LLM-powered action.

The cost advantage is also enormous. Instead of hiring skilled hackers, cybercriminals could deploy AI agents to scale up attacks like ransomware campaigns. “If you can delegate the work of target selection to an agent, then suddenly you can scale ransomware in a way that just isn’t possible at the moment,” said Stockley.

What’s more, these tools aren’t just threats — they could be assets. Edoardo Debenedetti, a PhD student at ETH Zürich, noted that AI agents could also be used for defense. If a friendly agent can’t find vulnerabilities, odds are a malicious one can’t either.

Chris Betz, Chief Information Security Officer at Amazon Web Services, emphasized that while AI accelerates the pace of attacks, it doesn’t fundamentally change them — yet. “Certain attacks may be simpler to conduct and therefore more numerous; however, the foundation of how to detect and respond to these events remains the same,” he said.

To measure how good current agents are at actually exploiting systems, Daniel Kang, a professor at the University of Illinois Urbana-Champaign, and his team built a benchmark. Their findings: AI agents with no prior training could exploit about 13% of unknown vulnerabilities — and with just a brief description of the flaw, their success rate jumped to 25%. That’s far beyond what any traditional bot could achieve.

Kang hopes benchmarks like his will drive responsible development of these technologies before it’s too late. “I’m hoping that people start to be more proactive about the potential risks of AI and cybersecurity before it has a ChatGPT moment,” he said. “I’m afraid people won’t realize this until it punches them in the face.”

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog