As we step into an era where artificial intelligence (AI) plays an increasingly significant role in cybersecurity, discussions surrounding its offensive capabilities are becoming more prominent.
By Michelle Alvarez, Manager, X-Force Strategic Threat Analysis, IBM & Chris Thompson,Global Head of X-Force Red
This piece was made possible thanks to contributions made by Patrick Fussell and David McMillen.
A recent report by Anthropic—a leading AI research lab—has sparked the latest conversation on this topic, with questions raised about their claim that an AI-assisted attack they observed was “90% autonomous.” Critics argue that the report didn’t provide sufficient detail to understand the tools used or the methodologies employed during these attacks.
While the report may lack specific detail concerning the AI-assisted attacks, IBM X-Force recognizes the following, perhaps overlooked, important key takeaways:
- Current cyber capabilities observed today are merely side effects of AI models trained on coding datasets. These tools were not specifically designed to create sophisticated malware or conduct complex attacks. That said, many frontier labs and private groups are pursuing the creation of training datasets for software vulnerability discovery and weaponization, as well as network and web-application attacks and offensive cyber operations. These datasets will be used to train and tune models to perform security testing at greater speed, scale and sophistication than is possible today. The recent emergence of initiatives like OpenAI’s Aardvark shows that we are beginning to see advancements in this area.
- Frontier labs, private teams, startups and adversaries alike have various motivations for pursuing the aforementioned work; from finding and patching bugs faster to better protect organizations, to finding and exploiting weaknesses in target infrastructure faster than they can be patched.
- Many analysts and industry veterans suggest that the offensive capabilities of AI are merely coincidental—an unintended outcome of training on coding datasets. As institutions and individuals pivot towards training AI models using tailored offensive datasets, the effectiveness of AI applications in both open and closed frameworks will rise exponentially.
- The attackers in the campaign reported by Anthropic employed a guardrail bypass strategy that exploited architectural vulnerabilities in current AI safety models. By breaking malicious tasks into smaller, seemingly legitimate components, individual requests appeared benign when evaluated in isolation. Framing inquiries as security testing scenarios bypassed content filters, while distributing requests across sessions exploited gaps in prompt-based detection. This demonstrates that prompt inspection alone may be insufficient, pointing to deeper questions about AI safety architectures.
- As multi-modal models’ capabilities mature, they will be able to automate increasingly complex tasks, creating the potential for more adaptive and faster-moving threats.
The democratization effect
The substantive development appears to be that less experienced and resourced groups can now potentially perform operations that previously required deeper technical expertise. This democratization of capability—not the creation of novel attack methods—represents the shift in threat landscape.
A blend of human and AI efforts
As organizations and researchers focus on developing autonomous AI-based security testing, semi-autonomous operations, and AI-driven vulnerability research, we should recognize that the effectiveness of these models will significantly increase when coupled with refined offensive datasets. The future landscape promises a blend of human and AI efforts, moving towards more sophisticated cyber operations and advanced ransomware attacks.
Therefore, it is essential for the cybersecurity community to understand and leverage AI responsibly as we navigate this rapidly changing domain. In doing so, we not only enhance our defensive postures but also prepare for the offensive capabilities that these technologies can offer. As the discourse evolves, so too must our frameworks and strategies for balancing ethical considerations alongside the technological advancements that AI introduces.
Current cyber capabilities as byproducts
The underlying capabilities of AI models in offensive operations are mostly a byproduct of training on general coding datasets rather than being a central focus area. Current models possess cyber capabilities that arise from their code generation training processes. These tools were not specifically designed to create sophisticated malware or conduct complex attacks, but are evolving in that direction.
The widening gap between open-source and closed-source offensive AI
The widening gap between open-source and closed-source offensive AI is becoming a defining feature of the emerging threat landscape. As major labs place tighter restrictions on model outputs and limit the release of advanced capabilities, sophisticated threat actors are increasingly turning to privately trained, forked, or fully closed systems that operate outside traditional oversight. This creates a tiered ecosystem in which criminal groups, nation-states and opportunistic actors gain access to increasingly differentiated levels of AI sophistication.
Open-source models provide broad accessibility but often lack the raw power, fine-tuning and safety bypasses that closed systems can achieve. Meanwhile, closed and privately trained models are more likely to incorporate tailored offensive datasets, advanced reasoning loops and custom tooling, all of which can significantly accelerate exploit development, automated reconnaissance and multi-stage attack orchestration. This divergence raises the risk of an asymmetry in which defenders rely on constrained, sanitized tooling while adversaries freely enhance AI models for stealth, precision and scale.
AI’s role in adversary infrastructure automation
AI’s role in adversary infrastructure automation is rapidly expanding as models become capable of managing and optimizing the systems that support large-scale cyber operations. Emerging research shows that AI can streamline the creation and maintenance of command-and-control infrastructure by automating tasks such as domain rotation, payload customization, hosting logistics, traffic obfuscation and infrastructure hygiene.
These capabilities reduce the operational burden on attackers and allow even less-skilled actors to deploy resilient and adaptive infrastructure that once required significant expertise.
Advanced groups can take this further by using AI to dynamically reconfigure infrastructure in response to detection, generate variations of malicious content on demand and coordinate distributed assets across multiple regions. As this automation matures, adversaries gain the ability to scale campaigns more quickly, maintain persistence with greater stealth and shift infrastructure in real time, making traditional takedown and disruption strategies far less effective for defenders.
The shift toward multi-modal offensive capabilities
The evolution of AI from text-only systems to fully multi-modal models represents a major change in how offensive cyber operations may unfold. Multi-modal models can interpret code, natural language, screenshots, network diagrams, logs and even audio or video, giving attackers the ability to automate reconnaissance at a level that was previously dependent on human expertise. By correlating insights across diverse data types, these systems can map target environments, identify misconfigurations, analyze traffic flows and uncover weaknesses with greater accuracy and speed than traditional automated tools.
As these capabilities mature, multi-modal models will be able to automate increasingly complex tasks such as generating tailored exploits, validating attack paths and combining physical, cyber and social information into a unified operational picture. This creates the potential for more adaptive and faster-moving threats, where AI assists attackers in analyzing their environment, selecting optimal techniques and orchestrating multi-stage operations. Defenders should anticipate a future where automated decision-making and cross-domain analysis become central components of offensive AI, raising the urgency for enhanced detection, monitoring and defensive AI research.
The future of cyber operations
As frontier model labs prioritize adapting current models, we can expect a transformation in the way offensive cyber operations are engineered. With a clear focus on creating stealthy and evasive strategies, advanced ransomware threats can be anticipated. The implications for cybersecurity, both in terms of attackers and defenders, will be profound.
This landscape is why initiatives such as Offensive AI Con have emerged—to foster community discourse and guide advancements in this space while enabling defense systems to keep pace with these developments. There are a multitude of avenues for attackers, from malware development, identifying and weaponizing vulnerabilities and carrying out cyber attacks/operations:
- Autonomous AI-based security testing
- Semi-autonomous offensive cyber operations
- AI-based vulnerability research and discovery
- Exploit development acceleration using AI
- Offensive security tool and capability development with AI
- AI-based target identification and analysis
- OODA workflows and multi-stage orchestration
- Offensive agentic AI frameworks and specialized models
By critically analyzing incident reports and ongoing developments in offensive datasets, we can ensure that the deployment of AI in this realm is both responsible and strategic.
The evolution of AI in offensive cyber operations signals a need for increased dialogue within the security community and calls for more robust defensive tactics. By actively participating in these discussions and sharing knowledge across the landscape, we can cultivate a safer digital environment for all stakeholders.
Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.
IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn:
LATEST COMMENTS
MC Press Online