Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Mythos Outperforms GPT5.5 on Google Chrome Vulnerability Exploits

June 5, 2026

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

June 5, 2026

AI Adoption Creates New Opportunities for Attackers

June 4, 2026
Facebook X (Twitter) Instagram
Friday, June 5
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AI Adoption Creates New Opportunities for Attackers
News

AI Adoption Creates New Opportunities for Attackers

Team-CWDBy Team-CWDJune 4, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The Microsoft Detection and Response Team (DART) has issued advice on how organizations and their security teams should respond to the rising issue of AI-powered cyber threats.

“AI is amazing, it makes our job easier. “But the same AI that’s useful can be easily manipulated by threat actors, we’ve seen it in social engineering and in our day-do-day investigations,” said Mary Asaolu, senior security researcher at Microsoft, during Infosecurity Europe on June 3.

In addition, while AI is being deployed within the enterprise to provide benefits to organizations and employees, if not managed correctly, AI code can introduce cybersecurity risks.

“AI really is the emergent angle,” said Meaghan Bradshaw, principal security researcher at Microsoft. “But AI code introduces another layer of risk. Nearly half of AI code contains flaws. Attackers can exploit it to compromise applications or data.”

This is not a theoretical concept: cyber criminals have already exploited AI tools as part of the attack chain, as demonstrated during Microsoft’s Infosecurity Europe talk titled ‘Securing AI in the Age of Intelligent Threats’, which detailed a campaign dubbed ‘JustAskJacky’.

The JustAskJacky attack tricks users into downloading what looks like a legitimate AI assistant, but is in fact a backdoor which cybercriminals use to deliver malware.

The campaign combines this with professional-looking interfaces and valid digital signatures which make it harder for both users and security tools to distinguish it from legitimate software, thus allowing it to stay under the radar.

In fact, the malicious AI assistant was so good at avoiding detection that it was only discovered when Microsoft DART was brought into an organization to investigate a separate issue.

“They found this application was masquerading as an AI assistant to help day-to-day workflows,” Bradshaw added

At first glance, it appears to function normally; however, during installation, a backdoor written in Java is deployed, along with a persistence mechanism that creates a scheduled task running every four hours to maintain control and send telemetry.

The lesson to take from this, Bradshaw explained, is that organizations and users need to take a step back and think about what AI services they are installing and where they come from, because threat actors know that employees are looking for AI tools.

“Everyone is excited to leverage it to enhance the day-to-day. But on the other side, it often leads to users putting their guard down and not knowing what they are running. All it takes is one user to be convinced to gain that foothold,” she said.

“One of the most common recommendations we give customers is to take the time to assess nonstandard applications installed. If there is no business need, get rid of them. Because as much as it is useful for you, it is useful for threat actors too. Make sure you know what employees are using,” Bradshaw added.

Securing AI Augmented Employees

Like many cybersecurity challenges, one of the best ways to solve a problem – in this case, the cybersecurity risks around installing AI applications – is to get ahead of it.

Throughout the business, from board level to junior staff, employees should be informed about the potential risks around downloading unauthorized AI tools and be provided with information on how to safely adopt and deploy AI assistants.

“Provide a clear roadmap for safe adoption,” said Asaolu. “Make AI security a leadership priority, ensuing you have security reviews in place and AI is at a board discission level.”

“Ensure AI is used responsibility, make sure that good AI is the default behavior. And ensure security teams are equipped and coordinated for carrying out risk assessments and monitoring for unusual behavior,” she added.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalicious npm Package Stole Files From Claude AI User Directory via GitHub
Next Article Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Team-CWD
  • Website

Related Posts

News

Mythos Outperforms GPT5.5 on Google Chrome Vulnerability Exploits

June 5, 2026
News

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

June 5, 2026
News

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

June 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

Here’s how to avoid a ‘second strike’

April 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.