AI is making bad actors craftier. Here’s how security companies are using AI to fight back

Are you human?

It’s an increasingly important question, and one that’s getting harder to answer.

With its squiggly letters, the old CAPTCHA, the Completely Automated Public Turing Test To distinguish Computers from Humans, was developed in the early 2000s to stop malicious bots from creating new email accounts and was later used, somewhat ironically, to train machines to “read” garbled text. But given recent advancements in machine learning, the test and its various successors can’t keep the bots at bay the way they used to.

This isn’t just a problem if you’re trying to buy concert tickets. Automatic CAPTCHA solving fuels a fusillade of online attacks, including phishing, password spraying, malware, and propaganda campaigns. Last December, Microsoft and a startup called Arkose Labs took down Storm-1152, a Vietnam-based operation that sold CAPTCHA-cracking services—powered by machine learning—to hacker groups like Octo Tempest that perpetrated ransomware attacks that eventually inflicted hundreds of millions of dollars in damages. 

Which is why, if you sign in to some of the world’s biggest online platforms these days, you’re more likely to see something else: Instead of a text or image CAPTCHA, there might be a puzzle asking you to rotate a toy pickup in the direction of a pointing hand, or listen to three tunes and indicate which has a second instrument. The tests were developed by Arkose, which makes AI-enabled tools that help companies like LinkedIn, Roblox, X, and OpenAI stay ahead of the bots. Thanks to the explosion of generative AI and cybercrime vendors like Storm-1152, malicious bot activity is booming, now estimated to account for more than half of the web’s traffic.

A new AI-fueled arms race is erupting across the internet and everything connected to it. Machine learning has become “this incredible acceleration mechanism” for attacks, says Sherrod DeGrippo, director of threat intelligence at Microsoft. And if miscreants are using AI to break in, she says, “we should use machine learning, data science, and AI to improve our security tools and make it harder.” (To see how companies are making important strides in these areas today, read the full list of the Most Innovative Companies in the Security category.)

As AI supercharges ransomware attacks, by making it easier to construct convincing phishing campaigns, for instance, Texas-based Halcyon is using machine learning to block infections prior to execution, and in some cases, it says, even decrypt devices without the need for ransoms. The company is also armed with a deep fund of human intelligence about how attackers get in: the founders’ previous Thiel-backed venture Boldend got its start building cyberweapons for the U.S. government.

Before the hackers arrive, defenders are using AI to help organizations keep their posture from slouching. Cyera, founded by veterans of the Israeli military’s Unit 8200, uses AI to automatically and continuously identify an organization’s sensitive data and lets security teams literally interrogate their systems for vulnerabilities, generate and enforce new policies, or ask why a defense was triggered. DataGrail and Vanta are also leveraging AI and LLMs to help businesses map their data landscape, allowing customers to manage security and privacy workflows and comply with a growing raft of industry and regulatory frameworks like HIPAA and GDPR.

Being human is one thing—but are you who you say you are? Security mainstay Yubico is focused on a simple but growing vulnerability: the password-based login, which thanks to infostealers and other crimeware, is still a popular entry point for the bad guys. The YubiKey security key lets you log in using numerous multifactor authentication protocols, including biometric identification—without the need to quickly copy a code off your phone. 

“We cannot depend on people” to be a security tool, says DeGrippo, but we can depend “on technology configured properly.” She thinks it’s pointless to blame us humans for getting duped by a hacker’s email—especially as AI gets ever better at tricking us.

Clicking on a phishing link “doesn’t make you unintelligent,” she says. It just “means that there’s someone out there with an organized crime organization going after you while you’re trying to do your job.”

You’re only human after all.

Right?

Explore the full 2024 list of Fast Company’s Most Innovative Companies, 606 organizations that are reshaping industries and culture. We’ve selected the firms making the biggest impact across 58 categories, including advertising, artificial intelligence, design, sustainability, and more.

https://www.fastcompany.com/91038985/security-spotlight-most-innovative-companies-2024?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 1y | Mar 28, 2024, 11:40:04 AM


Login to add comment

Other posts in this group

Inside ‘Elvis Evolution’: AI and immersive tech bring the King’s life to the stage in London

Stage fright is not a term you’d associate with Elvis Presley, but in 1968 he was all shook up—with nerves. Ahead of his

Jul 16, 2025, 1:20:05 PM | Fast company - tech
Gmail’s new ‘Manage Subscriptions’ tool could change email marketing forever

Inbox fatigue is real. According to one analysis, the average person receives more than 120 emails a day, with some o

Jul 16, 2025, 11:10:06 AM | Fast company - tech
This beloved retro gaming computer is making a comeback—and it’ll cost you $299

Tech nostalgia runs strong among Gen Z. The retro movement has made long-outdated devices desirable

Jul 16, 2025, 11:10:04 AM | Fast company - tech
Why sleep-time compute is the next big leap in AI

For much of the AI era, intelligence has been on-demand: a user issues

Jul 16, 2025, 11:10:02 AM | Fast company - tech
Windows 95’s look and feel are more impressive than ever

Every so often, Microsoft design director Diego Baca boots up an old computer so he can play around with Windows 95 again.

Baca has made a hobby of assembling old PCs with new-in-box vin

Jul 16, 2025, 6:30:02 AM | Fast company - tech
Jack Dorsey’s new Sun Day app tells you exactly how long to tan before you burn

Twitter cofounder Jack Dorsey is back with a new app that tracks sun exposure and vitamin D levels.

Sun Day uses location-based data to show the current UV index, the day’s high, and add

Jul 15, 2025, 9:10:06 PM | Fast company - tech
The CEO of Ciena on how AI is fueling a global subsea cable boom

Under the ocean’s surface lies the true backbone of the internet: an estimated

Jul 15, 2025, 6:50:04 PM | Fast company - tech