Malware and cyber intrusion — AI in the news (overview)
### What this danger is
What this danger is
Criminals and opportunistic attackers already use automation. Generative AI can make phishing writing faster, social engineering more personalized, and some coding tasks easier for people who want to break systems. Defenders also use AI. This chapter is about awareness, not offense.
What has already shown up
Security agencies and companies publicly report AI being used to improve phishing lures and impersonation at scale (related to the scams chapter). Industry threat reports discuss AI-assisted productivity for both sides. Exact capabilities change quickly; treat vendor marketing carefully and prefer primary advisories.
We will not explain how to write malware, bypass antivirus, or run intrusion campaigns.
Why ordinary people should care
You are more likely to meet AI-polished phishing than Hollywood “AI viruses.” Slowing down on unexpected links and MFA prompts remains foundational hygiene.
Healthy responses
- Use password managers + MFA
- Report phishing to your IT/security team
- Patch systems; distrust urgent money/gift-card requests
- Follow official CERT/CISA advisories in your country
Myths
- ⚠️ Myth: AI invented hacking.
- ✓ Reality: Intrusion is old; AI changes speed and polish of some steps.
- ⚠️ Myth: Only experts are targeted.
- ✓ Reality: Commodity phishing still works because humans are busy.
Sources
- CISA (US) cybersecurity guidance hub: https://www.cisa.gov/ ↗
- FBI IC3: https://www.ic3.gov/ ↗
- OWASP LLM Top 10 (application security for LLM apps): https://owasp.org/www-project-top-10-for-large-language-model-applications/ ↗
