AI v kibernetski varnosti: nov napadalni vektor in pametnejša obramba
Synopsis
Artificial intelligence is rapidly transforming the cybersecurity landscape. It enables attackers to execute existing techniques such as reconnaissance, phishing, synthetic content creation, and malicious code customization more quickly and cheaply, while AI-powered systems are also becoming an attack surface in their own right. The paper presents how this is changing the attack surface of organizations and illustrates the findings with publicly documented cases – fake video conference fraud, the EchoLeak vulnerability in Microsoft 365 Copilot, and an espionage campaign led by AI agents. The OWASP community guidelines, in particular the Top 10 list for applications with large language models and for agent-based applications, are used to understand key risks. The second part of the paper discusses the use of AI in defense – alert enrichment and triage, reducing false positives, event correlation between SIEM, EDR/XDR, cloud environments, and identity management systems, and more effectively prioritizing actual risks. Artificial intelligence should therefore be considered simultaneously as a risk, an attack surface and a new defensive capability.
Downloads
Pages
Published
Categories
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.





