AI & Technology

How security blind spots undermine resilience in the age of AI

By Yaz Bekkar, Principal Consulting Architect XDR - International, Office of the CTO, Barracuda  

Generative AI has transformed the way the world works. In the hands of threat actors, however, it can become Degenerative AI, dismantling trust, identity and the confidence we used to have in digital communications, content and conversations. 

AI is powerful because it removes friction. A criminal no longer needs to be fluent in English to write a perfect phishing email. They no longer need to understand a company deeply to personalise an attack. They can scrape public information, imitate writing styles, generate fake supplier messages, create convincing job offers, clone voices, prepare scripts, and scale social engineering in a way that looks human. 

AI makes attacks faster, cleaner, more convincing, and harder to spot. As if that’s not enough, effective threat detection is made even harder by the fact that organizations have blind spots – unseen, unmanaged or under-protected areas in their IT infrastructure. 

These include unpatched firewalls, rogue endpoints, dormant identities, shadow applications and misconfigurations that attackers can target and exploit.   

Understanding how attackers leverage these points of weakness helps organisations to apply the most effective security controls, reduce their exposure, and close critical security gaps. 

Threat actors’ focus on identity-based attacks 

According to the latest DBIR, 31% of breaches now start with software vulnerabilities, beating stolen passwords as the primary way attackers get in.  With the latest advanced AI models, such as Mythos, the number and range of exploitable bugs will increase. But developing exploits can take time and once the gap is patched, the exploit is burned. Humans will always be vulnerable, so attackers will continue to target and compromise identities.  

The goal of threat actors in going after identities is to gain a foothold within networks, which they can then use to elevate their privileges to turn limited access into full sovereign control over their targets’ environments – all while blending in with normal, everyday IT activity. 

The pace at which this can unfold is alarming. New research shows that it can take just five minutes for attackers to get from the first click in a phishing email to stolen credentials and cookie sessions, persistenceand device compromise. 

In another case, the entry point was a dormant account originally provisioned for a third-party vendor. When the contract ended, the account was never removed. Months later, that forgotten credential was all an attacker needed to establish a foothold and ultimately deploy ransomware across the environment. 

Endpoint and firewall weaknesses 

Another clear pattern which emerges from a deep analysis of security alerts, is the risk of unmanaged and unprotected endpoints. Attackers will use these blind spots to bypass corporate security defences and use as a launch pad for further stages of the attack. 

Over the last 12 months, 94% of the disabled security features we found involved endpoint protection agents. 

The vulnerability vortex 

It’s almost impossible to escape reports on how Mythos and similar AI models are uncovering hidden hoards of previously undetected vulnerabilities, and how the time between discovery and abuse is shrinking to almost zero. 

This is a serious issue, and it will transform many aspects of cybersecurity, including patching. It’s easy to panic and worry about ancient CVEs lurking in legacy systems and embedded devices or applications. 

But our own vulnerability scanning data shows that the top security weak spots in organizations are not unpatched CVEs – the first CVE appears in 9th place – but foundational configuration gaps that include broken encryption, outdated security standards, untrusted certificates and weak network controls. None of these require patching.  

The AI accelerant 

Emboldened by AI, threat actors are becoming increasingly stealthy in their methods, disguising malicious activity behind legitimate tools and processes already present in the environment.  

Agentic AI is giving threat actors a significant operational advantage: the ability to probe environments around the clock, pinpoint misconfigured assets within minutes, and modify attack code in real time to evade defences.  

AI is also helping threat actors move faster, adapt more quickly and scale their efforts far more efficiently than before. The same overlooked issues that are already dangerous today will be easier to find and exploittomorrow as these capabilities mature and scale. 

Building cyber resilience 

With attacks being launched at increasing speed and scale, basic security issues like unpatched systems and poor identity controls are more likely to be found and exploited.  

This is why getting the foundations right matters: enforcing multi-factor authentication consistently, tightening access management, maintaining disciplined patch cycles, protecting data robustly, and ensuring employees receive regular security awareness training. 

To fully bridge existing security gaps and ensure blind spots are addressed, organisations need a unified security strategy. A comprehensive, managed security platform and 24/7 managed XDR solution that integrates network, endpoint, server, cloud and email security – providing full end-to-end visibility and management control. This will ensure comprehensive oversight of all potential vulnerabilities and issues, both basic and complex, which is foundational to long-term, effective cyber resilience.  

Author

Related Articles

Back to top button