AI-powered cyberattacks against critical infrastructure are no longer a future threat; they are already happening, Check Point Chief of Staff Gil Messing warned in an interview with 103FM on Monday.
Messing addressed a joint warning from major technology companies about the possibility that hostile actors could exploit artificial intelligence to attack critical infrastructure.
"The unusual call comes because more than 100 significant companies around the world, including us, have joined in saying that what has been happening cannot continue," Messing said. "It is becoming more dangerous, and it is not that this will happen soon; it is already happening."
According to Messing, the emergence of increasingly powerful artificial intelligence models has erased much of the gap that once separated major powers from smaller actors in mounting sophisticated cyberattacks.
"Since those significant models from OpenAI, Anthropic, and others were released, at levels we had never seen before, the gaps that previously existed between powers and actors that are not major powers in their ability to create cyberattacks have disappeared," he said.
"The models allow almost anyone with a little knowledge to create attacks and vulnerabilities that have never been seen before. This tool, which is like a weapon, is reaching everyone's hands, and that is at the heart of the approach of the new AI companies, so the attacks have become more sophisticated and more frequent."
Messing: Cyberattacks exploit software vulnerabilities, can lead to critical shutdowns
Messing said cyberattacks generally rely on exploiting vulnerabilities in software, with the consequences ranging from service disruptions to data theft, system crashes, encryption of information, and the shutdown of critical systems.
"The entire cyber world ultimately works on the fact that there is software with a vulnerability through which someone gets in, exploits it, and that becomes an attack," he said. "At the end of the process, what we see is something that does not work, something being shut down, information being stolen, a crash or encryption, and systems that stop functioning."
"The models make possible, although they should not make possible, attacks unlike anything we have seen before, without human involvement," Messing continued. "It has reached the point where the models sometimes attack on their own without a person controlling them and asking them to do it, and that gets out of control. There is an attempt to tell the world that there is something different here.
"Everyone needs to cooperate because this is not the world we knew before," he continued. "We are in a new era. What exists now is not good enough to stop it, and cooperation is needed."
Messing said addressing the threat would require action in three main areas, starting with ensuring organizations regularly update their software.
"There are three main components, and if we deal with them, we will deal with most of the problem," he said. "One is the issue of version updates, because organizations have to constantly update their versions. They do not know how to do this because they do not have enough manpower, so more personnel need to be trained to deal with it."
Trained professionals needed to deal with threat, Messing says
He added that trained professionals would need to operate those systems, while governments would have to establish appropriate regulation for the rapidly developing AI sector.
"There are the people who need to operate it, and there are governments that need to regulate what is happening now with AI models," Messing said. "If we do not deal with each of these components, we will not have the tools to deal with the attacks that are taking place. As the models continue to develop, if there is no effort to stop or confront this, then the warning from the companies is that we will face a world in which breaches will be significant and painful."