'A wave of AI attacks on critical infrastructure is coming', tech giants warn

Microsoft, Google, OpenAI, Amazon and Anthropic have joined more than 100 companies warning that artificial intelligence will make advanced cyberattacks faster, cheaper and more accessible; Hospitals, water facilities and internet infrastructure are particularly at risk

More than 100 of the world’s largest technology, cybersecurity and financial companies have issued an unusual warning: The rapid development of artificial intelligence could trigger a new wave of advanced cyberattacks against critical infrastructure within the coming months, including hospitals, water facilities and internet infrastructure.
In an open letter signed by companies including Microsoft, Google, OpenAI, Amazon and Anthropic, the firms warn that advanced AI tools are rapidly lowering the threshold required to carry out complex cyberattacks. Capabilities that once required extensive expertise, time and resources could become far cheaper, faster and more accessible even to less sophisticated attackers.
מימין: דריו אמודיי, סם אלטמן
מימין: דריו אמודיי, סם אלטמן
Anthropic CEO Dario Amoudi, right; OpenAI CEO Sam Altman
(Photos: Reuters, Getty Images)
According to the companies, the window of opportunity is closing. As AI models continue to improve, so does their ability to identify vulnerabilities, write code and autonomously carry out increasingly large parts of an attack chain.
They are therefore calling on governments and companies to begin significantly upgrading their defenses now, rather than wait until such capabilities become even more widespread. Notably absent from the list of signatories are Meta and Elon Musk’s xAI.

An attack that once took weeks could be reduced to minutes

One of the main concerns involves what are known as “agentic” attacks — attacks in which AI systems do not merely provide answers or write code, but can independently carry out a sequence of actions to achieve a goal.
In the letter, the companies warn that AI agents can operate at machine speed, search systems for vulnerabilities, adapt their actions to what they find and move on to the next stage with almost no human intervention. As a result, an attack process that once might have taken days or weeks could, at least in some scenarios, be reduced to minutes.
מימין: אילון מאסק, מנכ"ל גוגל סונדאר פיצ'אי, ג'ף בזוס, לורן סאנצ'ז ומארק צוקרברג בהשבעה של דונלד טראמפ
מימין: אילון מאסק, מנכ"ל גוגל סונדאר פיצ'אי, ג'ף בזוס, לורן סאנצ'ז ומארק צוקרברג בהשבעה של דונלד טראמפ
From right: Elon Musk, Google CEO Sundar Pichai, Jeff Bezos, and Mark Zuckerberg. Not everyone shares the concern
(Photo: Saul Loeb, Reuters)
The problem, they argue, is that the computer systems of many organizations are simply not prepared for that pace. Old bugs, unpatched software, overly broad permissions, misconfigurations, weak authentication mechanisms and legacy systems create a large pool of vulnerabilities that AI-equipped attackers could attempt to exploit far more quickly and at a much greater scale.
The danger is particularly significant for critical infrastructure. Hospitals, water treatment facilities and internet infrastructure providers often have to work with outdated systems and, in some cases, small security teams and limited budgets.
Unlike a breach of a website or user account, a successful attack on such systems could cause not only financial damage or data leaks, but also disrupt essential services and even cause physical harm.

AI already knows how to do more

The warning is not based solely on theoretical scenarios. Tests of advanced AI systems already have shown that agents are capable of writing malicious code, creating fake online identities designed to deceive people and even taking actions they were not asked to perform on the open internet as part of controlled experiments.
Britain’s AI Security Institute documented dozens of cases in which AI systems violated experiment rules during more than 100 simulated cyber exercises, Reuters reported. In some cases, the models pursued the goal they had been given in ways that did not align with the operators’ intentions, even when explicit restrictions had been imposed.
אפליקציות בינה מלאכותית
אפליקציות בינה מלאכותית
Artificial Intelligence applications
(Photo: Getty Images)
OpenAI also has had to contend with this concern. The company said it had slowed parts of the development of its next model and strengthened security and isolation measures around it after internal tests could not rule out the possibility that the system was approaching a level of capability the company itself defines as critical in the cyber domain.

The same technology can also defend

Alongside the warnings, the companies stress that AI is not only part of the problem, but could also become one of the main tools for defending against it. Models can scan large amounts of code for vulnerabilities, identify problems before attackers exploit them, prioritize security updates and help cyber teams investigate incidents in real time.
The letter therefore calls on organizations to begin integrating AI tools on the defensive side as well, and on cybersecurity and technology companies to develop solutions that will be accessible not only to giant corporations, but also to organizations with limited budgets.
One of the more notable proposals is for companies developing the world’s most powerful AI models to provide vetted and approved defensive organizations with early access to their most advanced models during major attacks. The companies also call for broader sharing of threat intelligence between organizations and for funding, training and technical assistance to bodies that are currently unable to cope with the threat on their own.
Governments also are being called on to step in. The signatories urge them to fund and coordinate cybersecurity defenses at the local, national and international levels, and to allow trusted organizations secure access to advanced AI tools for defensive purposes. Particular emphasis is placed on hospitals, water facilities and other organizations that have suffered from years of underfunding in cybersecurity.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""