Navigation
Search
|
Sloppy AI Defenses Take Cybersecurity Back To the 1990s, Researchers Say
Wednesday August 13, 2025. 12:00 AM , from Slashdot
![]() We -- not just the cybersecurity industry, but any organization bringing AI into its processes -- need to understand the risks of AI and develop ways to mitigate them before we fall victim to the same sorts of vulnerabilities we faced when Bill Clinton was president. 'AI agents are like a toddler. You have to follow them around and make sure they don't do dumb things,' said Wendy Nather, senior research initiatives director at 1Password and a well-respected cybersecurity veteran. 'We're also getting a whole new crop of people coming in and making the same dumb mistakes we made years ago.' Her fellow panelist Joseph Carson, chief security evangelist and advisory CISO at Segura, had an appropriately retro analogy for the benefits of using AI. 'It's like getting the mushroom in Super Mario Kart,' he said. 'It makes you go faster, but it doesn't make you a better driver.' Many of the AI security flaws resemble early web-era SQL injection risks. 'Why are all these old vulnerabilities surfacing again? Because the GenAI space is full of security bad practices,' said Nathan Hamiel, senior director of research and lead prototyping engineer at Kudelski Security. 'When you deploy these tools, you increase your attack surface. You're creating vulnerabilities where there weren't any.' 'Generative AI is over-scoped. The same AI that answers questions about Shakespeare is helping you develop code. This over-generalization leads you to an increased attack surface.' He added: 'Don't treat AI agents as highly sophisticated, super-intelligent systems. Treat them like drunk robots.' Read more of this story at Slashdot.
https://it.slashdot.org/story/25/08/12/2037200/sloppy-ai-defenses-take-cybersecurity-back-to-the-199...
Related News |
25 sources
Current Date
Aug, Wed 13 - 18:50 CEST
|