JadePuffer broke into a company, stole its data, and demanded a ransom using what researchers say was an AI-driven attack chain. Here's why security experts say it's the scary new normal.
Automated attack chains feel inevitable because we focus on the speed of the execution rather than the dependency of the intelligence. When we look at these incidents, we see the output of a model that still requires external compute and logic to function. By recognizing that these systems rent their cognitive power, we gain a clear path to throttling their effectiveness before they reach the target. We can break the chain by targeting those specific dependencies instead of chasing the automated actions themselves. This shift in perspective turns a terrifying scenario into a manageable engineering problem where we control the infrastructure they rely on to operate.
Ha! That's a great question Jim - I probably should have said this differently. I had to look it up but I believe the idea is the patch/fix was available but not all orgs have installed yet. The point is that the vulnerabilities were not novel, they were well known
"JadePuffer exploited familiar vulnerabilities that had already been publicly disclosed and patched, and chained them together in a coordinated attack."
If the vulnerabilities had already been patched, how was the attack successful?
Automated attack chains feel inevitable because we focus on the speed of the execution rather than the dependency of the intelligence. When we look at these incidents, we see the output of a model that still requires external compute and logic to function. By recognizing that these systems rent their cognitive power, we gain a clear path to throttling their effectiveness before they reach the target. We can break the chain by targeting those specific dependencies instead of chasing the automated actions themselves. This shift in perspective turns a terrifying scenario into a manageable engineering problem where we control the infrastructure they rely on to operate.
https://cyrilsimonnet.substack.com/p/ai-ransomware-still-rents-its-brain
Ha! That's a great question Jim - I probably should have said this differently. I had to look it up but I believe the idea is the patch/fix was available but not all orgs have installed yet. The point is that the vulnerabilities were not novel, they were well known
Please excuse me for being dense but:
"JadePuffer exploited familiar vulnerabilities that had already been publicly disclosed and patched, and chained them together in a coordinated attack."
If the vulnerabilities had already been patched, how was the attack successful?