The NCSC’s report makes for concerning reading for all organisations, especially those running operational technology (OT) systems that may be less well secured.
Over the next two years, threat actors will continue to use AI to help to improve reconnaissance, vulnerability research and exploit development (VRED), social engineering, basic malware generation, and exfiltrating data. VRED is highlighted as the “most significant” use case, with sophisticated adversaries potentially even using their own models to discover new zero-day exploits. However, all threat actors will benefit, as AI-as-a-service and AI-powered pen testing tools become more widespread, driving an increase in the “volume and impact” of intrusions over the next two years, the NCSC says.
...



