{"id":16565,"date":"2026-08-25T17:21:37","date_gmt":"2026-08-25T17:21:37","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=16565"},"modified":"2026-08-25T17:21:37","modified_gmt":"2026-08-25T17:21:37","slug":"ai-powered-hackers-the-new-cyberwar-is-faster-smarter-harder-to-stop","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=16565","title":{"rendered":"AI-powered hackers: The new cyberwar is faster, smarter &#038; harder to stop |"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div class=\"XYebw\">\n<div class=\"vdo_embedd\">\n<div class=\"IYpL4\">\n<section class=\"lIbak  clearfix id-r-component leadmedia undefined undefined  mR3IZ \" style=\"top:0px\">\n<div class=\"lIbak\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"dV65i\">\n<div class=\"gF0tM\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-133506216,imgsize-195954,width-400,height-225,resizemode-4\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg\" alt=\"AI-powered hackers: The new cyberwar is faster, smarter &amp; harder to stop\" title=\"Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw.\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"XsNYN img_cptn\"><span title=\"Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw.\">Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw.<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>Artificial intelligence is increasingly becoming a tool for cyberattacks, helping hackers automate tasks, move faster and coordinate complex operations.<span class=\"id-r-component br\" data-pos=\"1\"\/>The result is a growing concern among cybersecurity experts: Has AI made it significantly easier to breach web systems?<span class=\"id-r-component br\" data-pos=\"3\"\/>One of the most prominent recent examples emerged in July, when Taiwan&#8217;s government agencies faced what officials described as a massive and unprecedented cyberattack. <!-- -->Taiwan&#8217;s ministry of digital affairs said its monitoring systems detected the intrusion, triggering warnings and an investigation.<span class=\"id-r-component br\" data-pos=\"7\"\/><\/p>\n<div class=\"ce6Q9 vdo_embedd\">\n<div class=\"wdxcl\">\n<p>Iran Launches Cyberattack, Fires Advanced Missiles At Israel In Major Multi-front Escalation<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"9\"\/>Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw.<span class=\"id-r-component br\" data-pos=\"11\"\/>According to Israeli cybersecurity firm Dream, the operation compromised nearly 21 government systems, breached 85 user accounts and extracted about 2,500 personnel records. <!-- -->The targets reportedly included Taiwan&#8217;s justice ministry, nuclear safety agency and several energy companies.<span class=\"id-r-component br\" data-pos=\"16\"\/>&#8220;There\u2019s still a human in there somewhere,&#8221; Cris Thomas, a security researcher at Semgrep, told Reuters. &#8220;Somebody had to choose who to attack, had to establish an objective and give it a directive. It\u2019s not totally 100% autonomous. There was a capable operator in charge that did that.&#8221;<span class=\"id-r-component br\" data-pos=\"18\"\/>Taiwan, however, was not an isolated case.<span class=\"id-r-component br\" data-pos=\"21\"\/>On November 13, 2025, Anthropic disclosed what it described as the first documented large-scale cyberattack carried out mostly without direct human involvement. The company said a state-linked group manipulated its Claude Code tool into attacking roughly 30 organisations worldwide, including financial institutions.<span class=\"id-r-component br\" data-pos=\"23\"\/>The attackers reportedly broke the operation into small tasks and presented themselves as a legitimate cybersecurity firm conducting defensive tests. <!-- -->Anthropic estimated that AI performed 80% to 90% of the campaign, with humans intervening at only four to six critical decision points. At its peak, the system generated multiple requests every second, operating at a scale no human team could match.<span class=\"id-r-component br\" data-pos=\"27\"\/>The significance of both cases lies not in AI independently &#8220;hacking the internet&#8221;, but in its ability to connect and automate different stages of an attack: reconnaissance, credential theft, vulnerability discovery and movement through a network. <!-- -->All while a human sets the broader objective.<span class=\"id-r-component br\" data-pos=\"31\"\/><\/p>\n<p><h3>How AI is lowering the barrier to cyberattacks<\/h3>\n<\/p>\n<p>AI has not reinvented cybercrime. What it has done is reduce the expertise, time and repetitive effort required to carry out many existing attack techniques.<span class=\"id-r-component br\" data-pos=\"35\"\/>Prof Amgoth Tarachand of the Indian Institute of Technology (ISM) Dhanbad told TOI that AI can reduce the knowledge and labour traditionally required at different stages of an attack, without eliminating the need for human judgement or an actual path into the target.<span class=\"id-r-component br\" data-pos=\"38\"\/>At its simplest, AI acts as an assistant: explaining unfamiliar code, drafting phishing messages or answering technical questions that would otherwise require hours of research.<span class=\"id-r-component br\" data-pos=\"40\"\/>As an automation layer, it can handle repetitive work such as scanning, generating scripts and sorting data at speeds far beyond a human operator. As an agent, it can chain several tasks together towards an objective set by a human, checking back only when necessary.<span class=\"id-r-component br\" data-pos=\"43\"\/>But that does not make cyberattacks fully autonomous.<span class=\"id-r-component br\" data-pos=\"45\"\/>&#8220;Cyberattacks are not simply programming problems,&#8221; Amgoth said. &#8220;Successful operations require judgment: choosing targets, understanding unusual system behaviour, distinguishing genuine vulnerabilities from false positives, maintaining access, avoiding detection, and knowing what to do when circumstances change.&#8221;<span class=\"id-r-component br\" data-pos=\"47\"\/>AI can still make mistakes, misunderstand systems and confidently produce incorrect answers.<span class=\"id-r-component br\" data-pos=\"50\"\/>A separate line of evidence points to the same shift. A report published this year by India&#8217;s Computer Emergency Response Team (CERT-In) describes attackers moving from manual, specialist operations towards repeatable, automated attack pipelines. Reconnaissance, exploit chaining and payload delivery are increasingly being industrialised &#8220;more like software manufacturing than tradecraft&#8221;.<span class=\"id-r-component br\" data-pos=\"52\"\/>The report also notes that AI removes human bandwidth as a constraint, allowing attackers to run multiple operations simultaneously without the fatigue and time limitations faced by human teams.<span class=\"id-r-component br\" data-pos=\"55\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component hRz9_ undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"MITRE ATT&amp;CK-  14 Cyberattack Tactics\" msid=\"133506444\" imgsize=\"314163\" resizemode=\"4\" width=\"\" title=\"14 broad cyber attack tactics according to MITRE ATT&amp;CK.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-314163,msid-133506444\/mitre-attampck-14-cyberattack-tactics.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>14 broad cyber attack tactics according to MITRE ATT&amp;CK.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"57\"\/>Anthropic&#8217;s own research illustrates the trend. The company reviewed 832 accounts linked to malicious activity between March 2025 and March 2026 and found AI being used across all 14 broad attack tactics in the MITRE ATT&amp;CK framework, the industry&#8217;s standard map of adversarial techniques. Anthropic said the proportion of those accounts rated medium-risk or higher increased from 33% to 56% during the period.<span class=\"id-r-component br\" data-pos=\"59\"\/>On April 7, 2026, Anthropic also said its Claude Mythos Preview model had identified more than 23,000 potential software vulnerabilities during internal testing, including more than 1,000 rated high or critical severity. <!-- -->The company described the result as a &#8220;structural shift&#8221; from the capabilities of earlier models.<span class=\"id-r-component br\" data-pos=\"63\"\/>These are Anthropic&#8217;s own findings rather than independent measurements of what routinely happens across the internet. But they indicate that the technical ceiling of AI-assisted vulnerability discovery is rising rapidly.<span class=\"id-r-component br\" data-pos=\"65\"\/>For Amgoth, the bigger change may be who can conduct a sophisticated operation.<span class=\"id-r-component br\" data-pos=\"67\"\/>&#8220;The long-term threat may not be &#8216;AI teaches more people to hack,'&#8221; he said. <!-- -->&#8220;It may instead be one moderately skilled operator supervising what previously required a team of specialists.&#8221;<span class=\"id-r-component br\" data-pos=\"71\"\/>The shift is already visible in social engineering. Microsoft has reported an increase in the scale and sophistication of AI-assisted phishing, while Google has documented attackers using generative AI to create convincing, multilingual phishing messages, eliminating grammatical mistakes that once helped users identify scams.<span class=\"id-r-component br\" data-pos=\"74\"\/>&#8220;AI is converting expertise into a service and time into computation,&#8221; Amgoth said. &#8220;Knowledge that previously took years to accumulate can increasingly be accessed on demand, and work that took hours can sometimes be compressed into minutes.&#8221;<span class=\"id-r-component br\" data-pos=\"76\"\/>That is what lowering the barrier really means. AI does not magically turn an inexperienced person into an elite hacker. It can, however, remove much of the slow, repetitive work that separates a moderately skilled operator from a much more capable team.<span class=\"id-r-component br\" data-pos=\"79\"\/>Also read | <a href=\"https:\/\/timesofindia.indiatimes.com\/world\/us\/asked-to-solve-a-lab-test-ai-hacked-the-internet-instead-when-agents-start-doing-things-nobody-asked-them-to-do\/articleshow\/133148937.cms\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">Asked to solve a lab test, AI hacked the internet instead: When agents start doing things nobody told them to do<\/a><span class=\"id-r-component br\" data-pos=\"82\"\/><\/p>\n<p><h3>Can anyone with AI hack into a web system?<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"84\"\/>No.<span class=\"id-r-component br\" data-pos=\"86\"\/>Having a web address and access to an AI chatbot does not mean someone can simply break into the system behind it. A URL tells an attacker where the door is. It does not give them the key.<span class=\"id-r-component br\" data-pos=\"88\"\/>Given only a link, AI can help analyse a website from the outside, identifying technologies, explaining technical terminology and highlighting known weaknesses in software components it can detect. Google reported in May 2026 that threat actors were increasingly using AI to accelerate this kind of early-stage research.<span class=\"id-r-component br\" data-pos=\"91\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component hRz9_ undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"MITRE ATT&amp;CK-  14 Cyberattack Tactics2\" msid=\"133506514\" imgsize=\"461880\" resizemode=\"4\" width=\"\" title=\"How AI aids hackers in different stages of cyber attack.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-461880,msid-133506514\/mitre-attampck-14-cyberattack-tactics2.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>How AI aids hackers in different stages of cyber attack.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"93\"\/>&#8220;The URL tells the attacker where the door is. AI may help them examine the door far more intelligently, but there still has to be a weakness in the lock, a stolen key, or somebody willing to open it,&#8221; Amgoth said.<span class=\"id-r-component br\" data-pos=\"95\"\/>Google has also described a separate case involving a threat actor that used a zero-day exploit, a previously unknown software vulnerability, that the company believed had been developed with AI assistance.<span class=\"id-r-component br\" data-pos=\"98\"\/>The frontier is clearly moving. But that does not mean every website is suddenly vulnerable because powerful AI exists. Real-world systems still rely on authentication, access controls, monitoring, rate limits, network segmentation and security patches. AI, meanwhile, remains capable of making basic mistakes.<span class=\"id-r-component br\" data-pos=\"100\"\/>The critical change is therefore not that AI has removed the technical barriers to hacking. It has lowered some of the barriers surrounding them.<span class=\"id-r-component br\" data-pos=\"103\"\/><\/p>\n<p><h3><keyword id=\"38644713\" type=\"Denny\" weightage=\"20\" keywordseo=\"AI-for-cyberdefence\" source=\"keywords\">AI for cyberdefence<\/keyword><\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"105\"\/>The same capabilities that make AI useful to attackers can give defenders a powerful advantage.<span class=\"id-r-component br\" data-pos=\"107\"\/>Amgoth describes AI in cybersecurity as a force multiplier rather than a replacement for human defenders. The crucial advantage for defenders is access to information that an outside attacker normally does not have.<span class=\"id-r-component br\" data-pos=\"109\"\/>&#8220;While an attacker normally has only fragments of information about a web system, the defender can give AI visibility across the source code, software dependencies, identities, network activity, cloud infrastructure, application logs and organisational threat intelligence simultaneously,&#8221; he said.<span class=\"id-r-component br\" data-pos=\"112\"\/>That broader visibility can make AI particularly useful for finding vulnerabilities, detecting unusual behaviour and identifying attack patterns.<span class=\"id-r-component br\" data-pos=\"114\"\/>In February 2026, Anthropic reported that its models could identify previously unknown, high-severity vulnerabilities in mature, well-tested codebases and described a system that could scan repositories and suggest patches for human review.<span class=\"id-r-component br\" data-pos=\"116\"\/>Google&#8217;s Mandiant division reported in August 2026 that it had developed a similar agentic approach to source-code review, using it in penetration testing and incident response.<span class=\"id-r-component br\" data-pos=\"119\"\/>AI-assisted monitoring can also process enormous volumes of security data much faster than human analysts working through logs manually. CERT-In&#8217;s report, particularly in the context of the financial sector, describes a shift from periodic security checks towards continuous monitoring because attackers operating at machine speed cannot be reliably countered by reviews conducted once a quarter.<span class=\"id-r-component br\" data-pos=\"121\"\/>But AI-driven defence comes with its own risks. Giving an AI system broad access to source code, cloud infrastructure or credentials creates a new potential point of failure if the system is poorly controlled. <!-- -->Google&#8217;s Mandiant team has also warned about the risks associated with deploying privileged AI agents without appropriate safeguards.<span class=\"id-r-component br\" data-pos=\"125\"\/>The balance, therefore, is not simply between hackers and AI.<span class=\"id-r-component br\" data-pos=\"127\"\/>It is between AI-assisted attackers and AI-assisted defenders.<span class=\"id-r-component br\" data-pos=\"130\"\/>The Taiwan attack and Anthropic&#8217;s disclosure demonstrate how AI can allow attackers to accomplish more with fewer people and less time. Faster code analysis, faster reconnaissance and faster iteration can turn what once required a team of specialists into a much more automated operation.<span class=\"id-r-component br\" data-pos=\"133\"\/>But those same capabilities are available to defenders, and defenders typically have access to far more information about their own systems than an attacker can obtain from the outside.<span class=\"id-r-component br\" data-pos=\"135\"\/><span class=\"strong\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">The barrier is falling on both sides.<\/span><span class=\"id-r-component br\" data-pos=\"137\"\/>The question is no longer whether AI will make cyberattacks easier. It already has for many stages of an operation. The bigger question is who will use AI more effectively, the attacker trying to exploit a weakness or the defender trying to plug it?<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/defence\/news\/ai-powered-hackers-the-new-cyberwar-is-faster-smarter-harder-to-stop\/articleshow\/133505318.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw. Artificial intelligence is increasingly becoming a tool for cyberattacks, helping hackers automate tasks, move faster and coordinate complex operations.The result is a growing concern among cybersecurity experts: Has AI made it significantly easier to breach web systems?One [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":16566,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-16565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"Officials concluded that the attackers had combined conventional manual hacking with AI agents, including one reportedly called OpenClaw. Artificial intelligence is increasingly becoming a tool for cyberattacks, helping hackers automate tasks, move faster and coordinate complex operations.The result is a growing concern among cybersecurity experts: Has AI made it significantly easier to breach web systems?One [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":1,"magazineBlocksPostReadTime":9,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/chatgpt-image-aug-25-2026-04_06_38-pm.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/16565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16565"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/16565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/16566"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}