TechRadar News.
Technology

Microsoft says AI gives cyber attackers a speed edge over defenders

Microsoft says AI gives cyber attackers a speed edge over defenders

Microsoft’s security research group warned that threat actors are already leveraging artificial‑intelligence tools to outrun defenders, widening the gap at the outset of the AI‑driven cyber‑threat arena.

The firm’s study highlights generative AI models and large‑language‑model assistants capable of automatically spotting software vulnerabilities, drafting exploit code, and polishing malicious payloads. By mechanizing steps that formerly required weeks of manual labor, attackers can progress from discovery to active exploitation within hours, hastening the entire kill‑chain.

In contrast, defenders frequently remain dependent on traditional detection signatures and manual analysis processes. Microsoft observed that numerous security teams lack the expertise and tools needed to embed advanced AI into their workflows, exposing them to the swift evolution of AI‑driven threats.

The potential of AI in cybersecurity has been debated for years, with expectations that machine learning could assist in triaging alerts and forecasting attacks. Yet those very technologies are now being weaponized against defenders. Publicly accessible large‑language‑model services that can generate code, craft phishing emails, or produce obfuscated scripts are lowering the entry barrier for less‑experienced actors to conduct sophisticated campaigns.

The tangible effects are already evident. Accelerated vulnerability discovery leads to a larger flow of zero‑day exploits entering the market, and AI‑generated malware can modify its behavior to bypass sandbox detection. For instance, ransomware gangs can employ AI to automatically produce ransom notes in several languages, while supply‑chain attackers can design custom exploits for a wider array of software components.

Microsoft called on the wider security community to speed up the creation and rollout of AI‑enhanced defenses, stressing the need for cooperation among industry, academia and government. The firm disclosed that forthcoming research projects will aim to develop models capable of foreseeing attacker tactics and automating response measures, with the goal of shrinking the present edge held by threat actors.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related