In the Dutch news today (from public broadcast).
Urgent call due to AI hacking: 'We must be able to respond super fast'
Quickly and easily searching for security problems in computer programs: it is possible with artificial intelligence (AI). These AI systems work faster than a human and never get tired. And that can have major consequences for digital security for all kinds of companies and organizations.
The AI systems can detect serious security problems. For example, vulnerabilities that can be used to hack or shut down computers. These could be errors that have been present in computer programs for years, while no one noticed.
"That is why companies and organizations must be able to respond super fast," warns Matthijs van Amelsfort, director of the National Cyber Security Center (NCSC). "In the past, it took days for an attacker to exploit a flaw; now it takes hours," he says. "That will become minutes."
The urgent warning is known to the people in charge, says Dimitri van Zantvliet. He is chairman of the professional association for those people: the CISO Platform. "There is no panic, but it is certainly urgent," he says. This week, hundreds of them gathered at an event, partly to discuss this. "This development means that vulnerabilities are being found in systems that are already twenty years old. We need to accelerate so that we fix those errors before they are exploited."
Government hacked with the help of AI
Rogier Fischer of cybersecurity company Hadrian proves that you can find security problems quickly and automatically using AI programs. At the Amsterdam office, he demonstrates how he was able to hack the government using them.
Fischer had an AI system examine the programming code of a government website. He asked if there was a specific error that would allow him to gain access to files that are not supposed to be accessible. The AI program replied that this was indeed the case.
Because of that error, Fischer was able to download a file, even though he is not supposed to be able to access it. He points it out on his screen. "Here you literally see the passwords," he says.
With that, Fischer was able to log into the website's database. "There was nothing stopping me," says the hacker. "Once you are inside, you can, for example, modify things. Or carry out new attacks in that database. We don't do that: we have already demonstrated that we had access. So we stopped the attack."
'Full access for 10 euros'
Hadrian was able to hack the government using a cheap AI program from OpenAI, the company behind ChatGPT, Fischer explains. He estimates the total attack cost him about 10 euros. "So that gave me full access."
Other cheap AI programs are also suitable for finding these types of errors, according to research by cybersecurity company AISLE. Since September, the company has found more than two hundred errors using various AI systems, says Jaya Baloo, one of the founders.
AISLE investigated, among other things, whether cheap systems could find errors in two computer programs that were also recently discovered using the AI program Mythos. The company behind Mythos used those two errors found by the program to advertise the AI system. This is so good, the company said, that only a very small group gets access to it.
"The story was that AI was 'suddenly' very good at finding vulnerabilities," says Baloo. "But we could find those same flaws with older AI systems. So how is that 'suddenly'? We have been doing this for months."
Finding even more flaws
Baloo and Fischer believe that defenders currently have the advantage. But there is urgency, they say: if criminal hackers get to work with these AI programs, they can also find and exploit these security problems.
"Technology is often used by people with bad intentions after a few months," says NCSC Director Van Amelsfort. It is important to take that seriously into account, because it concerns the digital security of us all, he says. We have already experienced a port being shut down or our data being stolen. The Netherlands is highly digital. That also makes us vulnerable. Attackers and defenders will continue to fight each other, even with this AI development. We really need to ensure that our defenses are in order.