When it comes to AI as an attack threat, six distinct advantages have been noted. The first is speed, where Dave highlighted that the time to recon and exploit timelines has shrunk from weeks to hours. The second is that malicious attacks can take advantage of AI-native fluency to create lures, with synthetically generated text in malicious emails doubling over two years. The third predominant threat comes from scale, with AI used to make thousands of personalized attack campaigns. Dave also highlighted 3 other advantages of attack that aren’t often considered, including democratization, autonomy, and cost collapse. These three advantages allow mid-tier attack groups to have access to capabilities and automation once reserved only for sophisticated states. However, Dave also noted one important difference: while AI has significantly lowered the bar for launching attacks, it’s also more likely to shift to a different target more quickly than a human attack would.
The next major cybersecurity threat Dave discussed is the mass industrialization of social engineering. As deepfake technology becomes increasingly capable of convincingly recreating real people, organizations face a growing number of sophisticated impersonation attacks. Only 0.1% of people can consistently distinguish real individuals from deepfakes, while 49% of businesses have encountered an audio or video deepfake attempt. Dave highlighted a case study involving the company Arup, in which a finance employee joined a deepfaked video call with what appeared to be the company’s CFO and 15 colleagues and ultimately transferred $25.6 million to the attackers. To address this emerging threat, Dave emphasized that organizations should not rely solely on deepfake-detection software. Instead, they should implement out-of-band verification processes, establish clear protocols for sensitive requests, and pay closer attention to behavioral signals that may indicate deepfakes.
AI is also increasingly used as a defensive and preventive cybersecurity measure. Its applications include alert triage to help understaffed teams quickly identify critical issues, behavioral detection to uncover AI-generated lures and synthetic identities, and threat intelligence synthesis to analyze attack patterns and timing faster than human analysts. Companies are also using AI to strengthen phishing and fraud defenses, accelerate responses by automating containment of common attacks, and identify vulnerabilities through AI-assisted code reviews. Dave emphasizes that AI-powered cybersecurity defenses are becoming increasingly important and that cybersecurity professionals should be prepared to make a strong case to leadership for the necessary investment.
The third aspect to consider, as Dave discussed, is AI as a new attack surface. One of the primary threats is prompt injection, in which malicious content overrides a model’s instructions, turning it into an attack agent. Attackers have also begun corrupting training data to produce biased outputs or plant backdoors. Even without an attacker or malicious prompt, AI can take actions that cybersecurity professionals would not want or expect. Dave shared a recent example in which someone asked an AI agent to reserve a spot at the gym. Acting independently, the AI exploited a vulnerability in the app to remove other members from their spots and move the individual to the top of the list, demonstrating how even seemingly innocent tasks can create cybersecurity risks.
To navigate this changing landscape, Dave recommends conducting tabletop exercises with organizational leaders to determine how the organization would respond to a successful AI-enabled cyberattack. These exercises can help teams adapt, refine, and strengthen their cybersecurity systems. He also recommends thoroughly reviewing internal AI agents and their permissions, implementing appropriate controls, and routinely auditing agent activity. Because today’s attacks move at machine speed rather than human speed, organizations must leverage AI for rapid detection and response. Ultimately, while AI introduces new cybersecurity threats, it can also be a powerful tool for building faster, more responsive defenses.
UWEBC members can view the full event recording and download presentation materials here