The global expansion of generative AI has dramatically changed the cybersecurity landscape.
While AI is helping strengthen software security on one hand, it has also emerged as a powerful “force multiplier” for cybercriminals.
Even without advanced expertise in conventional cyberattacks, criminals can now use artificial intelligence to launch sophisticated cyberattacks more quickly and easily.
In the past, launching a major cyberattack required considerable technical expertise and weeks of research.
Now, the same tasks can potentially be accomplished within hours using an advanced large language model (LLM).
Moreover, cybersecurity is inherently asymmetric.
A security expert must identify and close every possible vulnerability or digital loophole, whereas a hacker needs to find just one hidden flaw or “zero-day vulnerability” to launch an attack.
AI has made it considerably easier to identify such previously unknown software vulnerabilities.
One of the biggest targets for cybercriminals is human error and lack of awareness among ordinary users.
In the past, phishing emails could often be identified through grammatical mistakes or inconsistencies.
With AI, however, criminals can now create highly fluent, accurate and personalised “spear-phishing” messages targeting specific individuals.
Various studies have found that the use of AI in phishing emails has pushed the rate at which users click on fraudulent links sharply upward—from 12% to around 52%. At the same time, fraud involving voice cloning and deepfakes has also increased several times over.
To speed up digital tasks, organisations and individuals are increasingly using AI agents or automated assistants, such as OpenClaw.
These agents are often given extensive administrative access to email, calendars, financial accounts and internal systems. However, because AI agents have fundamental security limitations, they are becoming easy targets for cybercriminals.
Through “prompt injection” attacks, malicious instructions can be hidden inside website code or messages. AI agents may unknowingly follow those instructions and end up leaking an organisation’s sensitive information.
Although cybercriminals are rapidly adopting new technologies, security professionals are not giving up.
According to a Trend Micro survey, preventing deepfakes and application-level attacks such as prompt injection is being treated as a major priority.
Technology companies such as Microsoft are also developing agent-based AI security systems such as “Project Perception.”
These systems involve red teams for penetration or hacking tests, blue teams for risk assessment and green teams for prevention, with the aim of automatically preparing for and blocking potential attacks.
Overall, the rapid rise of AI has turned the cyber world into a never-ending race. For the time being, the opportunities available to attackers appear to have gained a slight edge over those available to defenders.