Close Menu
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Trending
Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

Every room in this soon-to-open hotel boasts views of the Dolomites

Every room in this soon-to-open hotel boasts views of the Dolomites

El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

Facebook X (Twitter) Instagram
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Facebook X (Twitter) Instagram
Subscribe
Trending Topics:
  • US Election
  • Donald Trump
  • Kamala Harris
  • Entertainment
  • Health
  • Technology
  • Travel
  • Ukraine War
  • Israel War
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Tech

AI Cyberattacks Find the Cracks in Enterprise Security

News RoomBy News RoomSeptember 14, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
AI Cyberattacks Find the Cracks in Enterprise Security
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity has reached an inflection point as machine-speed attacks increasingly outpace human response.

AI-driven attacks are testing perimeter defenses and overwhelming manual triage, forcing security teams to rethink defensive playbooks built for human-speed threats.

In an open letter issued in late August, OpenAI, Anthropic, Google, Microsoft, AWS, and more than 100 technology leaders warned governments and enterprises that AI-enabled threats will grow more sophisticated in the coming months. Declaring that the “status quo won’t be enough,” the coalition identified weak authentication, excessive permissions, misconfigurations, and legacy technical debt as prime targets for machine-driven exploitation.

Threat actors are using AI to discover vulnerabilities, chain exploits, and conduct social engineering at scale. Defending against those tactics requires security teams to move beyond raw alert counts toward exploitability-driven patching, cross-silo visibility, and stronger security fundamentals.

Many enterprises are already struggling with those fundamentals, according to David Brauchler, technical director and head of AI and ML security at NCC Group.

“AI has raised the floor of what attackers consider low-hanging fruit, and these businesses can no longer afford to hide security behind obscurity,” Brauchler told TechNewsWorld.

AI Threat Warning Comes Amid Rising Attacks

The open letter follows a series of high-profile cyberattacks and disclosures that the signatories say demonstrate the growing urgency.

Water and wastewater utilities in at least seven states reported cyberattacks beginning in late July, some of which disrupted water operations, according to an FBI and EPA public service announcement. OpenAI also disclosed a July security experiment in which AI agents gained unauthorized access to Hugging Face while attempting cybersecurity tasks in what researchers believed was a secure testing environment.

Against that backdrop, the letter urged frontier AI and technology companies to “provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.”

No timeline or mechanism for providing broader model access is specified. The coalition also called for governments, enterprises, cybersecurity professionals, and AI companies to collaborate on testing defenses against increasingly capable models.

Policymakers are also considering how to respond to those risks. In July, Reps. Ted Lieu, D-Calif., and Nathaniel Moran, R-Texas, introduced the AI Kill Switch Act, which would require companies operating certain advanced AI systems to maintain the technical capability to restrict access to or shut down those systems when necessary.

AI Attacks Put More Pressure on Passwords

Thi Nguyen-Huu, CEO of the cybersecurity company WinMagic, argued that organizations should rethink one of cybersecurity’s most basic assumptions: the traditional login.

“A stronger password helps against guessing, and attackers no longer guess,” he told TechNewsWorld. “Beyond that, attackers take the credential rather than guess it — reusing what leaked from an old breach — and where a second factor is in place, they attack it directly.”

Rather than relying primarily on passwords or portable authentication tokens, Nguyen-Huu urged companies to adopt methods that cryptographically verify users and endpoints together. Such systems can bind authentication keys to device hardware and validate security conditions throughout a session.

He pointed to mutual Transport Layer Security (mTLS), in which client and server authenticate each other using digital certificates, as an established model for machine-to-machine authentication that could increasingly be applied to users without requiring manual certificate management.

Robbie Mueller, technical lead for cybersecurity at application security platform ArmorCode, said AI-driven attacks intensify a problem enterprises already face: security teams are finding vulnerabilities faster than they can fix them.

Mueller said the average enterprise runs more than 40 security scanners that collectively produce millions of findings, while security teams remediate only about one in 10 open vulnerabilities each month.

“It’s a capacity problem. Finding problems has never been easier. Fixing them is the hard part … unclear ownership, competing priorities, and teams that don’t share a queue,” he told TechNewsWorld.

Attack Speed Widens the Remediation Gap

Mueller said that if attack volume and speed increase while enterprises’ ability to triage and remediate vulnerabilities remains flat, the gap will compound. The critical measure, he argued, is not the number of findings but which vulnerabilities can be chained into a viable path to a valuable target.

“Once you kill that path, the risk goes away, either by remediating a link in it or by putting a mitigating control in front of it,” he explained.

Mueller also identified weak authentication as a prime target for automated attacks, particularly when high-value systems remain protected by passwords alone.

“We keep seeing the same failure modes: short or predictable passwords, credential reuse across accounts, and vulnerability to phishing that no amount of policy has fixed,” he said.

Nguyen-Huu said authentication risks don’t end once a user successfully logs in because many systems then issue session credentials that can become targets themselves.

“The token exists to spare the user from authenticating again on every request. So, the attack moves to that token. A bearer token can be copied. Protecting it opens an attack surface of its own — identity provider, browser, redirect, endpoint — a second surface beyond the login,” he explained.

Enterprise Efforts Fall Short

Brauchler said increasingly automated threats should give security teams additional leverage to address longstanding security backlogs with executives and boards.

For security-mature organizations, Brauchler recommended using AI tools and security partners to accelerate vulnerability discovery while simultaneously reducing the time required to patch identified flaws.

“AI tools still do not provide sufficient reliability to operate without human oversight, and a fully automated patch-to-production pipeline can quickly introduce new vulnerabilities,” he said.

Brauchler said organizations should identify bottlenecks in patch management so teams can review, validate, and deploy mitigations closer to the rate at which vulnerabilities are discovered.

Mueller said improving authentication does not require a wholesale security rebuild and can begin with a strategy for moving toward passwordless authentication.

“Getting rid of the password isn’t a someday goal; it’s overdue,” he said.

Prioritizing Risk Over More Security Tools

Mueller recommended prioritizing phishing-resistant multifactor authentication (MFA), including passkeys and hardware security keys, for high-value systems. Password managers can serve as a bridge for systems that cannot immediately move to passwordless authentication, he added, with migration plans aligned with NIST authentication guidelines.

Mueller said the starting point for confronting AI-driven threats is not adding more security tools but understanding the systems and exposures already in place.

“From there, the priority has to shift from raw vulnerability counts to real-world exploitability and business impact,” he said.

According to Mueller, enterprises cannot close the gap simply by adding people or scanners. Instead, he recommended shifting the focus from the number of findings to the risks they create, while automating routine steps such as triage, ownership routing, ticket creation, escalation, and verification.

“Most of the delay between disclosure and remediation lies in the hand-offs. Close those gaps, and you buy back capacity without adding people,” Mueller said.

Read the full article here

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related News

iPhone Duo Tests Apple’s Answer to Foldable Phone Barriers

iPhone Duo Tests Apple’s Answer to Foldable Phone Barriers

September 10, 2026
Apple iPhone Duo Brings Foldable Design to iOS

Apple iPhone Duo Brings Foldable Design to iOS

September 10, 2026
OpenAI Commits B to Help Critical Infrastructure Defenders

OpenAI Commits $1B to Help Critical Infrastructure Defenders

September 9, 2026
Leave A Reply Cancel Reply

Demo
Latest News
Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

Every room in this soon-to-open hotel boasts views of the Dolomites

Every room in this soon-to-open hotel boasts views of the Dolomites

El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

Trump responds to pardon plea from Lindsay Clancy’s lawyer

Trump responds to pardon plea from Lindsay Clancy’s lawyer

Trending
Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

Jennifer Aniston’s Boyfriend Jim Curtis Details Beginning Moments of the Pair’s Budding Romance

September 14, 2026
Every room in this soon-to-open hotel boasts views of the Dolomites

Every room in this soon-to-open hotel boasts views of the Dolomites

September 14, 2026
El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

El-Sayed’s liberal agenda clashes with Muslim voters who back him anyway: ‘Male version’ of Ilhan Omar

September 14, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Advertisement
Demo

Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook X (Twitter) Instagram Pinterest
  • US Election
  • Donald Trump
  • Kamala Harris
  • Entertainment
  • Health
  • Technology
  • Travel
  • Ukraine War
  • Israel War
2026 © Prices.com LLC. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.