Categories

No categories

Cybersecurity and Artificial Intelligence

June 04, 2025
Eye23
Book11 min
Background

In this article, we will discuss how Cybersecurity and Artificial Intelligence are related, what dangers AI technologies pose to organisations and what you need to consider when implementing AI tools in your data protection systems.

Definitions and concepts that we will break down in this article.

Cybersecurity is the state of the information system that ensures the integrity, confidentiality and availability of its digital information assets: documents, files, systems and services, personal data of partners, employees and customers, Internet resources, etc.

Artificial Intelligence (hereinafter referred to as AI) is the set of technological solutions that enable machines to perform tasks that normally require human intelligence. In particular, learning, reasoning and finding optimal solutions to problems.

Neural networks — a mathematical model embodied programmatically or technically. Reproduces the principle of operation of human neural connections. The concept is not identical to artificial intelligence and is a part of it. The ability to learn is the most important advantage of neural networks.

Major Cybersecurity threats associated with the use of Artificial Intelligence technologies

The unprecedentedly rapid development of AI technologies has significantly changed many aspects of modern human life, bringing convenience and opening up almost limitless opportunities for work, learning and creativity.

However, as AI technology has become more sophisticated and accessible to masses, the cyber threat landscape has become more complex, both for individual users and for entire organisations. Below we look at the most common AI-related cyber threats to organisations.

AI-based malware

Today, Artificial Intelligence technologies are being used to develop sophisticated malware that can learn how the organisation's information system works and cleverly circumvent traditional security measures. Cybercriminals can also use AI to automate the process of finding and identifying IS vulnerabilities and targeting attacks.

Alarming trend is AI's ability to generate a huge number of malware variants and overwhelm security systems — and IS specialists in particular. At the same time, AI as a tool does not require deep IT expertise, which significantly lowers the threshold of entry for cybercriminals — and that too will contribute to increase in threats.

Malware created with artificial intelligence has a number of features.

  1. The ability to mimic known malware families — and with very high accuracy. Imitation can mislead security services, making it difficult to identify the threat.
  2. Polymorphism. AI-based malware can automatically change its code with each replication or infection. Continuous "mutations" make it difficult for traditional signature-based detection methods to recognise and block malware.
  3. Real-time adaptation. AI-based malware is able to adapt its behaviour to environment in real time.

Another important thing to consider when organising Information Security is the relative novelty of AI attacks. According to recent surveys, most organisations still do not have response plans in place for Cybersecurity incidents involving AI systems.

Deepfakes

As practice shows, even the most stable and reliable Information Security system will be ineffective if organisation's employees are not aware of rules of the safe online behaviour.

With the development of Artificial Itelligence technology, dipfakes are widespread, and their numbers are growing daily.

Using this AI technology, cybercriminals can create convincing videos, images or voice recordings of key individuals.

According to Human Constanta, the number of recorded dipfake videos increased by 550% between 2019 and 2023. However, it is important to realise that scale of attacks using dipfake videos can be much wider than this figure, as not every attack is actually recorded.

What's important to know? Dipfake technology can pose threat to individual users, to organisations and even to the national security of entire nations, especially in the current geopolitical climate.

Goals of dipfake attacks can be different: spreading disinformation, blackmail, inciting ethnic hatred, creating panic among the public, creating compromising images and videos, stealing confidential data, impersonating a high-ranking person for financial gain, etc. Attackers can also use dipfake attacks as a means of spreading disinformation, blackmail, inciting ethnic hatred, creating panic among the public, creating compromising images and videos, stealing confidential data, impersonating a high-ranking person for financial gain, etc.

Detecting dipfakes today is a difficult task. AI algorithms are constantly improving their ability to generate highly realistic content, highlighting the need for organisations to train employees on how to recognise dipfakes, as well as implement software tools to combat fake content.

Social engineering

Social engineering techniques have long been used by criminals, and with the widespread adoption of AI technology, cyber fraud has reached new, unprecedented levels.

AI algorithms can collect and process huge amounts of user data from social networks, news resources, personal websites and use of information to create targeted phishing attacks, i.e. aimed at a specific person.

The success rate of attacks can be very high because AI can automate the process of creating persuasive messages backed by personal information about users. At the same time, AI-powered chatbots or voice assistants can impersonate trusted individuals or organisations, making it difficult for victims to identify fraudulent activity.

It is important to realise that new technologies are ahead of the law. Many of the concepts we discussed above do not yet exist normatively, so imposing liability for offences using them can be problematic.

Considering the circumstances, today it is much easier and financially advantageous to deploy the stable and reliable Information Security system than to face with the breach, find the culprit, prove guilt in court and recover compensation.

AI capabilities for Cybersecurity

Artificial Intelligence and neural networks in particular can both pose threat to Information Security and be an effective defence tool.

When it comes to Cybersecurity, Artificial Intelligence has key advantage over the IS professional — ability to quickly process massive amounts of data, identify breaches of security policies and establish complex patterns that could indicate possible incident, and respond instantly. The speed of response to IS incidents is critical.

It is important to realise that today AI cannot fully replace an Information Security specialist. At the same time, the use of artificial intelligence and machine learning technologies allows an IS specialist to act preventively, eliminating security threats before they materialise.

Applications of AI for Cybersecurity

Today, Artificial Intelligence is used to solve the following range of tasks:

  • analysing user behaviour, detecting suspicious activity;
  • detection of malicious activity and various anomalies in operation of the information system;
  • user Access Control and authentication;
  • automatic response to IS incidents; 
  • identifying and preventing Information Security threats;
  • detecting and preventing leaks of confidential data;
  • monitoring the information system for IS threats.

Advanced generative models of Artificial Intelligence can solve more complex problems:

  • code analysis for vulnerabilities;
  • collecting and analysing data on current Information Security threats;
  • blocking bots designed to attack web resources and applications, steal sensitive information, and more;
  • searching for and identifying relationships, such as recognising AI-generated phishing emails.

A list of processes that can be automated using AI is quite extensive. However, when introducing AI tools into an Information Security system, it is extremely important to take into account their vulnerabilities and potential limitations.

Limitations and challenges in the use of AI in Cybersecurity

AI tools may contain their own vulnerabilities

Typically, lifecycle of AI tools consists of 4 stages: design, development, deployment, maintenance. At each of these stages, they can be infiltrated with critical vulnerabilities that can later be exploited by cybercriminal groups to bypass security mechanisms and introduce malware into the organisation's information system.

For example, weak or incorrectly implemented authentication and authorisation mechanisms already at the design and development stages can lead to information leaks and unauthorised changes within the system.

During the development phase, attackers can exploit coding errors to execute arbitrary code, manipulate AI models, or gain unauthorised access to system resources.

Also, the behaviour of an AI model can be deliberately or accidentally altered, leading to the execution of unauthorised tasks or the generation of incorrect responses. The potential consequences are manifold: unauthorised access, information leaks, undermining output data.

The possibility of insecure supply chain is also important to consider. This means that components purchased from external vendors to develop an AI tool may also contain vulnerabilities. Attackers can use them to inject backdoors, malware or other malicious code into the system.

When implementing AI tools into the cybersecurity system, it is important to keep in mind that a list of potential vulnerabilities is extensive, as evidenced by the number of incidents identified.

For example, in January 2025, it became known that the developers of Chinese artificial intelligence chatbot DeepSeek left one of their critical databases unprotected. This led to the leak of more than a million records. The history of users' correspondence with the neural network, secret keys and parts of the API, backend data and other sensitive information became publicly available.

A month earlier, experts discovered vulnerability in ChatGPT — the search tool from OpenAI can be tricked, and can also generate malicious code if it finds corresponding instruction on the website.

In June 2024, researchers identified serious vulnerability in the open source AI platform Ollama. The vulnerability with identifier CVE-2024-37032, known as Probllama, poses a threat — it can be exploited for remote code execution.

Data Privacy Security issues

Based on the information presented above, attacks by attackers can be directed not only at the information system, but also at the AI tools themselves. The process of training AI models involves collecting, storing and processing large amounts of data of varying degrees of sensitivity, including information about IT assets, business processes, information system architecture, user authorisation data, and so on.

All of this increases the risks of leaks, loss of privacy and data misuse.

AI tools are difficult to implement and customise

Implementing and customising the data protection system using AI technologies requires rare skills at intersection of cybersecurity and programming. In addition, application of AI models involves lengthy learning curve, taking into account the need to adapt to business processes unique to each business area.

As an example of the difficulties that can be encountered when implementing AI tools, security rules can be configured for software packages designed to automatically monitor security events and analyse for breaches and suspicious activity. A high number of detected incidents indicates that anti-virus policies are not configured well enough. And a large number of false positives indicates that the rules that detect suspicious activity are not working correctly. Both are bad.

Factors described above emphasise the need for highly skilled workforce — hence the next challenge.

There is critical shortage of highly skilled IS specialists in the labour market

Today, we can see significant increase in the number of open Сybersecurity jobs and the actual number of qualified professionals. According to explodingtopics.com, 57% of companies lack cybersecurity skills. In the US alone, there is shortage of 377,000 Сybersecurity professionals.

The gap has arisen for many reasons, for example, due to unprecedented rapid development of technology, rapid digitalisation of the economy and industries, and mass transition of specialists to the remote format of work. In just a few years, companies have equipped staff workplaces with laptops, tablets, smartphones; cloud applications have been connected and much more — all of this can become an entry point into an organisation's information system and therefore needs to be protected.

Cybercrime is also making rapid progress. Cyberattacks have become more complex, their number and intensity have grown, and the landscape of Information Security threats has also increased significantly. As mentioned above, attacks on information systems are being made using Artificial Intelligence technologies, and security measures in place at many companies are not yet robust enough to withstand the activities of cybercriminal groups.

Shortage of highly skilled Cybersecurity professionals, and especially in such narrow profile as implementing and countering AI technologies, has far-reaching consequences.

Thus, small businesses will be significantly affected. Small organisations cannot allocate large budgets to organise the sustainable protection system.

How does Anexet Ultimate DLP leverage neural networks to protect organisations' data?

The Anexet Ultimate DLP system also uses neural networks to protect company data.

Text recognition on images. The system allows you to analyse text in documents of graphic formats. When such data is detected, the system performs image recognition and text analysis and applies security policies to the recognised data. Depending on the image recognition tool selected, the system can recognise documents with .PDF, .DJVU, .JPEG, .PNG, .GIF, .BMP, .TIF extensions.

Seal recognition. The system automatically analyses documents circulating within the information network and checks them for seals. If a document with the seal is detected, Anexet Ultimate will compare it with reference sample. If match is detected, it will trigger the system in accordance with the configured security policies.

Speech recognition. The Anexet Ultimate system allows you to analyse voice calls. When intercepting calls, the system will perform recognition, analyse the text component and apply security policies set in the User Console to intercepted data.

Recognise faces in webcam photos. The system automatically detects the presence of a person in webcam photos and compares it with photos in your account. If a stranger or another employee is detected in front of a screen, Anexet Ultimate will automatically send the notification to a security officer and, if pre-set, block the user's session, regardless of whether a computer is connected to the network or not.

In conclusion

As you can see, AI can solve quite a large set of Cybersecurity challenges, and this list will only grow in the future.

At the same time, when organising the Information Security system, it is important to consider the exponential growth of Artificial Intelligence and machine learning capabilities, and with it, the growing number of threats.

Advertisement

Explore the power of Anexet right now!

Start Free Trial