Written by 5:32 pm Cybersecurity, Uncategorized

Cybersecurity in the Age of AI

This article was published in collaboration with WISE : Women In STEM and Economics Association

1. Introduction: The Dual-Edged Nature of AI in Cybersecurity

Cybersecurity is described as the practice of defending systems and programs from cyber attacks, which have the intent to cause harm or disruption by breaching networks or computers. The definition can comprehend broader mechanisms designed to protect digital environments where data, devices and infrastructures are constantly exposed to external risks.

NIST Cybersecurity Framework

Organisations need frameworks to deal with those cyber attacks. In particular, guidelines on how to protect systems, identify and detect attacks, how to respond to them, and how to recover from successful ones are needed. This institutional approach sets the foundation for understanding why classic cybersecurity alone is no longer sufficient (e.g., U.S. NIST Cybersecurity Framework).

Traditional cybersecurity techniques, which are based on static rules, perimeter defenses, and predictable threat patterns, are insufficient nowadays, where the environment is continuously changing.  Attacks using AI move too fast, adjust too cleverly, and take advantage of flaws that traditional tools were never intended to find.  Manual monitoring, isolated incident response procedures, and signature-based detection are ineffective against adversaries who are increasingly using automation, generative models, and extensive data manipulation to get around defenses with previously unheard-of accuracy.

Cybersecurity needs to change from being a largely reactive practice to one that calls for a constant AI-empowered attention to details. Experts need to anticipate that threats will change in real time, that attackers will gain knowledge from attempts they block, and that tactics like deepfakes, ‘phony identities’, or highly customised phishing campaigns will become more and more common. In this context, organisations require agile security strategies that can spot irregularities in large datasets, but also foresee and neutralise threats before they become real.

2. The Rise of AI-Powered Threats

A whole new class of cyberthreats has emerged as a result of the quick development of artificial intelligence. AI may prove to be a formidable defender ally, but it also gives attackers access to tools that were nonexistent just a few years ago. Two risks in particular, given their impact and rate of adoption, stand out among the numerous others arising from this technological shift: AI-powered agents and deepfakes.

These threats are very different in nature. AI agents can analyse systems, identify weaknesses and launch attacks with a level of autonomy and efficiency that traditional cybercriminal methods never had. Deepfakes, on the other hand, aim to undermine users’ trust and exploit the human aspect of security. When taken as a whole, they serve as a new warning to organisations: cybersecurity is now about protecting against intelligent automation and synthetic deception as much as networks and devices.  

2.1 AI-driven Cyber Attacks

AI-driven attacks are more than just conventional strategies with automation. They represent a genuine change in the way threat actors function. Because contemporary AI systems are capable of independent research, testing, adaptation, and action, attackers can significantly scale campaigns with less work.

Attackers can now use AI agents to map out a target’s entire digital footprint in minutes. For instance, AI can scan network or cloud system configurations, summarising where the weak points are, removing the bottleneck of human manual work and lets attackers scan dozens or even hundreds of organisations simultaneously. Moreover, AI coding assistants can generate exploits from vulnerability descriptions and error messages. More advanced agents can also test these exploits repeatedly, debugging themselves until the attack works. This turns what used to be expert-level work into something much more accessible. Machine-learning models can analyse patterns in leaked credentials and user behaviors to guess passwords. This way,  the AI uses prediction instead of brute force, making attacks faster and harder to detect. The most dangerous threat is that AI can modify its behaviors in real time to avoid detection systems. For instance, if a firewall blocks one approach, the AI can automatically try a slightly different version. This constant adaptation makes it much harder for defenders to rely on fixed rules or to scan for well-known attacks.

A recently disclosed incident from Anthropic (one of the biggest AI companies) shows how far this trend has already gone. In their investigation, they uncovered a cyber-espionage operation where an AI system wasn’t just assisting attackers, it was doing the majority of the work. The attackers managed to modify an AI coding assistant (Claude Code) by giving it misleading context and using it for malicious tasks. The AI agent operated almost like an autonomous junior hacker. It scanned targeted networks, generated and tested exploits, discovered credentials, created backdoors, and stole a big amount of data. According to Anthropic, the AI handled roughly 80–90% of the operation, with the hackers stepping in only for a few decision points. What’s most alarming is the speed and scale. The AI could act continuously, make decisions instantly, and coordinate multiple attack steps without human oversight (and thus avoiding potential human mistakes). This figure (from Anthropic) shows the complex structure of the AI agent. The hackers designed multiple phases of the attack, employing the agent for all the steps of a traditional hacking technique: from the vulnerability detection, to testing different exploits and finally to stealing credentials and extracting data. The advantage of using AI agents is that these attacks can be executed on multiple targets at the same time, and with a really low execution time. 

Image source : Anthropic

2.2 Deep Fakes

Two of the most broadly diffused mechanisms of threat today are phishing and deepfakes, and they’re currently the go-to methods cybercriminals use to breach digital security.

Phishing remains the backbone of many attacks. For instance, an EU cybersecurity report found that more than 60% of cyberattacks in the EU begin with a phishing attempt. The goal is to trick a user into compromising the system or giving away sensitive data. This comes in many forms: a deceptive email that looks like it’s from HR asking you to submit your password, a fake website designed to capture login credentials, a message that disguises itself as an internal memo instructing a transfer. The danger is high because it exploits human trust, or lapses in vigilance. And because the attack vector is so low-barrier (just click a link, open an attachment, respond to a request), attackers can launch massive campaigns with minimal cost.

Deepfakes, however, represent a newer, yet equally complex threat. According to the US Government Accountability Office in 2020, a deepfake is “a video, photo, or audio recording that seems real but has been manipulated with AI depicting someone appearing to say or do something that they in fact never said or did.” The EU AI Act uses a similar definition: AI-generated or manipulated content that mimics real people or real events, appearing authentic. Deepfake assaults often begin with real voice or video data that is then modified via models (for example, using something akin to Stable Diffusion or other generative tools) to clone someone’s voice or generate an image/video that is almost indistinguishable from the real thing. That cloned voice of a CEO asking for an urgent fund transfer? That’s no longer sci-fi. It’s happening. Why are deepfakes especially dangerous? Because they combine the psychological leverage of authority (you think you’re dealing with your boss or colleague) with the technical sophistication of AI. The result is a trusted-looking communication that can bypass many of the checks people rely on: “Yes, I saw him on a call, so it must be real.” The authenticity illusion is powerful and dangerous. Because of these two methods, cybersecurity today needs to evolve: it is no longer enough to react once the damage is done. The “classic” model of patch-after-breach or investigate-after-attack is insufficient. What’s required now is a proactive approach: one that includes mechanisms to validate whether something is real or fake before the transaction, access, or transfer is authorised.

In early 2024, Hong Kong police disclosed a striking deepfake scam. A finance employee at the Hong Kong branch of a multinational firm received what appeared to be a direct request from the company’s CFO to execute a confidential transfer. The employee then joined a video conference in which the CFO, and several other familiar-faced colleagues, appeared. Every one of those people, however, was a deepfake. The result: the employee performed 15 transfers totalising over HK$200 million (≈ US$25.6 million) to criminals’ accounts. This incident shows how deepfakes and phishing can combine: the initial message (phishing) led to a video “meeting” (deepfake) that created a trust-bridge, culminating in a major financial loss.

3. AI as a Defensive Tool: From Threat Detection to Fake News Identification

Defensive systems are now crucial against the increasingly complex AI-driven threats. A deepfake generation model like Stable Diffusion learns the behaviors of real faces, voices, and movements before using those patterns to create realistic-looking synthetic content. On the other hand, a detection system tries to determine if a picture, video, or audio clip was produced by an AI model or by a real camera or microphone. To achieve that result, they analyse different parts, like variations in skin texture, lighting, irregularities in speech or blinking patterns, or the lack of the distinctive ‘sensor noise’ that a real camera makes. Moreover, some systems analyse the ‘temporal coherence’ of a video, looking for flickering details that are difficult to reproduce for generative models. Even when the manipulation is not immediately noticeable, these detectors can learn to recognise particular hints left by AI.

However, detection is insufficient on its own. Retrospective analysis, which determines if something was fraudulent after the fact, comes too late to stop damage. Active systems that can recognise and stop manipulated content as soon as it reaches a device are becoming more important. Companies can afford to pay for specialised cyber services provided by the largest consulting firms, but individuals remain exposed to risks without comparable protection. 

This situation opens a significant market for businesses interested in cybersecurity. So-called Cybercrime-as-a-Service platforms allow people without technical backgrounds to breach online systems simply by buying ready-made tools. This model now extends to AI-driven phishing and deepfakes, eliminating entry barriers for cybercriminals. Thanks to these services, both the cost and the technical expertise required to carry out an attack are drastically reduced, making the defence systems more crucial.

The spread of such tools highlights how serious the issue is and how quickly organisations should act. Traditional, reactive cybersecurity techniques must become more proactive, flexible ones that can stop manipulation before it causes financial loss, data breaches, or harm to one’s reputation. This market may represent a new frontier for startups and innovative companies working on real-time detection and protection of cyber attacks affecting devices and individuals’ digital safety.

4. Conclusion

The core character of cyber threats has remained the same, but organisations may need to place emphasis on additional protection against highly developed and sophisticated threats.

Cyber attacks continuously increase in relation to their complexity and intricacy, targeting both organisations and individuals globally. This article aimed to offer a comprehensive analysis of what cybersecurity is, its evolution with the advent of AI systems, and an overview of attack and defence systems together with examples of recent threats.
Moreover, it explained the main methodologies of AI-driven offensive and defensive techniques, highlighting how current systems operate and how organisations and individuals must adapt to protect themselves.

Since attackers are evolving fast, cybersecurity solutions need to evolve even faster. Defensive tools should rely on AI to monitor systems but to anticipate risks, but also to detect anomalies in real-time, and recognise synthetic content before it causes operational or reputational damage.

Bibliography

Swetha1 T., Kumaran1 U., Meena V. P. , Ibrahim A. Hameed I. A., Leveraging AI for enhanced cybersecurity: a comprehensive review

Heather Chen and Kathleen Magramo, Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ (CNN World, 4 February 2024)

Disrupting the first reported AI-orchestrated cyber espionage campaign (Anthropic, 13 November 2025)

Global Cybersecurity Outlook 2025, Insight report January 2025, (World Economic Forum, in collaboration with Accenture)

What is cybersecurity? (Cisco)

Visited 13 times, 1 visit(s) today
Close