Generative AI: The Double-Edged Sword of Cybersecurity
好的,我现在需要帮用户总结一篇关于AI在网络安全中的作用的文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住主要观点。 文章主要讲的是生成式AI(GenAI)正在改变网络安全的风险格局。它被用于攻击和防御,60%的网络攻击涉及人为因素,而GenAI能够利用这些人的错误。同时,55%的组织还没有准备好应对AI驱动的威胁,存在准备不足的问题。 另一方面,GenAI也能增强防御能力,比如帮助分析数据、检测异常行为,提升人类防火墙的作用。文章还建议领导者从小处着手,利用GenAI进行防御,并培训员工识别AI生成的内容。 总结时需要涵盖这些要点:GenAI对攻击和防御的影响、人类因素的重要性、组织准备不足的情况以及建议的应对措施。同时要保持简洁,不超过100字。 可能的结构是:首先说明GenAI如何改变风险格局,然后提到攻击和防御两方面的影响,最后提到组织需要采取的措施。 比如:“生成式AI正在改变网络安全风险格局。它被用于攻击和防御,60%的网络攻击涉及人为因素。尽管意识到风险,但55%的组织未准备好应对AI驱动威胁。同时,GenAI也能增强防御能力。领导者需利用GenAI进行防御,并培训员工识别其生成内容。” 这样既涵盖了主要观点,又符合字数限制。 </think> 生成式人工智能(GenAI)正在改变网络安全风险格局。它被用于攻击和防御中,60%的网络攻击涉及人为因素。尽管意识到风险,但55%的组织未准备好应对AI驱动威胁。同时,GenAI也能增强防御能力。领导者需利用GenAI进行防御,并培训员工识别其生成内容以提升安全防护能力。 2025-11-10 13:41:25 Author: securityboulevard.com(查看原文) 阅读量:40 收藏

The AI hacking era is here – and it’s reshaping the human risk landscape as we know it. With good and bad actors increasingly using generative AI (GenAI) to deploy and defend against attacks, organizations must understand the root of it all: People.  

The 2025 Data Breach Investigations Report by Verizon found that 60% of cybersecurity breaches involved a human element. Seeing how easily mistakes are made, AI is positioned to take advantage of human flaws. Despite most organizations being aware of this, 81% are concerned about GenAI leading to sensitive data leaks –over half (55%) aren’t prepared with strategies for AI-driven threats, showing a significant gap in readiness. 

Cruise Con 2025

It’s abundantly clear that AI is drastically changing the human risk landscape. To close that readiness gap, it’s critical to work directly with people to develop strategies and adapt accordingly as GenAI’s role continues to evolve in cybersecurity.  

GenAI Supercharges Human-Centric Attacks 

GenAI’s use in cyberattacks has gone far beyond what could have been anticipated, allowing hackers to “supercharge” their attacks. As the rise of GenAI tools has made them widely accessible at a low cost, hackers are no longer facing a barrier to entry. For example, they don’t need advanced coding expertise to develop malware to launch prominent, advanced attacks.  

A striking way hackers are weaponizing GenAI is by further advancing social engineering attacks. Through tactics like custom phishing, voice deepfakes, and synthetic personas, GenAI can make attacks feel alarmingly real. 

One of the most effective examples centered around a deepfake audio call. The attacker took on the persona of a CFO, calling the company’s finance team. The call had every aspect one would assume of a real emergency: Panicked tone, sense of urgency, and emotional cues that humans have. Sure enough, the deepfake had everything to be effective enough for the victim to push through a wire transfer to whom they thought was the CFO.  

The advancement of GenAI comes with many dangers, as it’s moving from static scams to dynamic manipulation, opening a new door for attackers. Despite the real-world impacts we’re already seeing from GenAI, not all its use cases are negative.  

The Flipside – Enhancing the Human Defense Layer 

Despite all the fears AI-generated attacks bring, GenAI’s role in cybersecurity is more than just a threat. When it comes to defense, AI tools equip humans with the support they need to strengthen the human defense layer.  

GenAI helps tackle the signal-to-noise problem that can make attacks difficult to detect. Security teams are constantly drowning in alerts, data logs and fragmented signals, giving them little time to conduct thorough analyses. In tandem, advanced AI techniques have the ability to reduce humans’ cognitive loads significantly by summarizing, clustering, and prioritizing incoming data, pinpointing the problem more efficiently.  

These tools can also be used to understand the people behind the computer, not just endpoints. Advanced AI techniques can be used to pick up shifts in communication behaviors such as sudden tone changes, message sentiment, stress signals, and even anomalies in who’s talking to whom and how, warning security teams of potential internal human risks. 

When combining the identification of communication shifts with intent detection in messages, security teams now have a real-time sense of human exposure, giving them the ability to shut threats down before they arise. 

Practical Steps for CIOs and CISOs 

It’s clear AI-enabled attacks and defenses are already making an impact, and you can’t risk waiting for the perfect framework to begin protecting your organization. You need to encourage security leaders to start small and move fast. The first place to start? Using GenAI and other advanced AI techniques yourself. 

By testing GenAI’s limits and understanding the ins and outs, it’s easier to know what to look out for and how to train your employees to detect AI-generated content in the most effective way. Treating AI like the unknown is a losing game – you must be AI literate to protect your company. 

There’s no way to predict when you’ll be hit with an AI-powered attack, but preparation for the inevitable is key. First and foremost, train your team to be wary of the types of requests that come with these advanced attacks. Whether it’s phishing, spoofing, smishing, etc., knowing what to look for with each type is crucial to maintaining a secure enterprise environment. 

Additionally, leaning into AI solutions as a defense layer is vital. While most of the talk is around AI’s threat, organizations can forget to use GenAI and other AI tools to combat the same threat. Whether it’s flagging suspicious activity or stress signals, using advanced AI defenses is crucial to enhancing human firewalls.  

Shifting from Reactive to Proactive

GenAI is a multiplier of both risk and resilience. As GenAI continues to evolve across the cyber threat and defense landscape, leaders must ensure their people are equipped for the future and have the skills needed to adapt the security lens accordingly.  

The only way to keep up with AI is to use it yourself. Begin by embracing experimentation and cross-functional AI literacy to secure the human layer before internal employees become a critical failure point in your organization.  


文章来源: https://securityboulevard.com/2025/11/generative-ai-the-double-edged-sword-of-cybersecurity/
如有侵权请联系:admin#unsafe.sh