AI is making bad actors craftier. Here’s how security companies are using AI to fight back

Are you human?

It’s an increasingly important question, and one that’s getting harder to answer.

With its squiggly letters, the old CAPTCHA, the Completely Automated Public Turing Test To distinguish Computers from Humans, was developed in the early 2000s to stop malicious bots from creating new email accounts and was later used, somewhat ironically, to train machines to “read” garbled text. But given recent advancements in machine learning, the test and its various successors can’t keep the bots at bay the way they used to.

This isn’t just a problem if you’re trying to buy concert tickets. Automatic CAPTCHA solving fuels a fusillade of online attacks, including phishing, password spraying, malware, and propaganda campaigns. Last December, Microsoft and a startup called Arkose Labs took down Storm-1152, a Vietnam-based operation that sold CAPTCHA-cracking services—powered by machine learning—to hacker groups like Octo Tempest that perpetrated ransomware attacks that eventually inflicted hundreds of millions of dollars in damages. 

Which is why, if you sign in to some of the world’s biggest online platforms these days, you’re more likely to see something else: Instead of a text or image CAPTCHA, there might be a puzzle asking you to rotate a toy pickup in the direction of a pointing hand, or listen to three tunes and indicate which has a second instrument. The tests were developed by Arkose, which makes AI-enabled tools that help companies like LinkedIn, Roblox, X, and OpenAI stay ahead of the bots. Thanks to the explosion of generative AI and cybercrime vendors like Storm-1152, malicious bot activity is booming, now estimated to account for more than half of the web’s traffic.

A new AI-fueled arms race is erupting across the internet and everything connected to it. Machine learning has become “this incredible acceleration mechanism” for attacks, says Sherrod DeGrippo, director of threat intelligence at Microsoft. And if miscreants are using AI to break in, she says, “we should use machine learning, data science, and AI to improve our security tools and make it harder.” (To see how companies are making important strides in these areas today, read the full list of the Most Innovative Companies in the Security category.)

As AI supercharges ransomware attacks, by making it easier to construct convincing phishing campaigns, for instance, Texas-based Halcyon is using machine learning to block infections prior to execution, and in some cases, it says, even decrypt devices without the need for ransoms. The company is also armed with a deep fund of human intelligence about how attackers get in: the founders’ previous Thiel-backed venture Boldend got its start building cyberweapons for the U.S. government.

Before the hackers arrive, defenders are using AI to help organizations keep their posture from slouching. Cyera, founded by veterans of the Israeli military’s Unit 8200, uses AI to automatically and continuously identify an organization’s sensitive data and lets security teams literally interrogate their systems for vulnerabilities, generate and enforce new policies, or ask why a defense was triggered. DataGrail and Vanta are also leveraging AI and LLMs to help businesses map their data landscape, allowing customers to manage security and privacy workflows and comply with a growing raft of industry and regulatory frameworks like HIPAA and GDPR.

Being human is one thing—but are you who you say you are? Security mainstay Yubico is focused on a simple but growing vulnerability: the password-based login, which thanks to infostealers and other crimeware, is still a popular entry point for the bad guys. The YubiKey security key lets you log in using numerous multifactor authentication protocols, including biometric identification—without the need to quickly copy a code off your phone. 

“We cannot depend on people” to be a security tool, says DeGrippo, but we can depend “on technology configured properly.” She thinks it’s pointless to blame us humans for getting duped by a hacker’s email—especially as AI gets ever better at tricking us.

Clicking on a phishing link “doesn’t make you unintelligent,” she says. It just “means that there’s someone out there with an organized crime organization going after you while you’re trying to do your job.”

You’re only human after all.

Right?

Explore the full 2024 list of Fast Company’s Most Innovative Companies, 606 organizations that are reshaping industries and culture. We’ve selected the firms making the biggest impact across 58 categories, including advertising, artificial intelligence, design, sustainability, and more.

https://www.fastcompany.com/91038985/security-spotlight-most-innovative-companies-2024?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 1y | Mar 28, 2024, 11:40:04 AM


Login to add comment

Other posts in this group

Tally lets you design great free surveys in 60 seconds

This article is republished with permission from Wonder Tools, a newsletter that helps you discover the most useful sites and apps. 

Jul 4, 2025, 1:50:03 PM | Fast company - tech
How China is leading the humanoid robots race

I’ve worked at the bleeding edge of robotics innovation in the United States for almost my entire professional life. Never before have I seen another country advance so quickly.

In

Jul 4, 2025, 9:20:03 AM | Fast company - tech
‘There is nothing that Aquaphor will not fix’: The internet is in love with this no-frills skin ointment

Aquaphor has become this summer’s hottest accessory.

The no-frills beauty staple—once relegated to the bottom of your bag, the glove box, or a bedside drawer—is now dangling from

Jul 3, 2025, 11:50:07 PM | Fast company - tech
Is Tesla screwed?

Elon Musk’s anger over the One Big Beautiful Bill Act was evident this week a

Jul 3, 2025, 5:10:05 PM | Fast company - tech
The fight over who gets to regulate AI is far from over

Welcome to AI DecodedFast Company’s weekly new

Jul 3, 2025, 5:10:03 PM | Fast company - tech
Agentic AI is driving a complete rethink of compute infrastructure

When artificial intelligence first gained traction in the early 2010s,

Jul 3, 2025, 12:30:02 PM | Fast company - tech