A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots - WIRED
Technology

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

- 3 min read - Source: WIRED
TOP SUMMARY

As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows...

Related topics

Key points

  • As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways to cover their tracks.
  • Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups are targeting the AI software supply chain.
  • As the malware gains privileges, it further unpacks itself and continues to grab credentials, particularly “npm" tokens that give access to key software package management servers and other development capabilities like pull requests.
  • “This looks very much like a lot of the automation organizations are using to build code, so it’s very difficult to detect.” Meyers adds, too, that in these AI software development pipelines, it is harder to gather the data points that security scanners and analysis tools traditionally use to detect potentially suspicious activity.

What happened

More photos

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways to cover their tracks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups are targeting the AI software supply chain. As the malware gains privileges, it further unpacks itself and continues to grab credentials, particularly “npm" tokens that give access to key software package management servers and other development capabilities like pull requests. “This looks very much like a lot of the automation organizations are using to build code, so it’s very difficult to detect.” Meyers adds, too, that in these AI software development pipelines, it is harder to gather the data...

Read full story (WIRED) Share on X Facebook WhatsApp

Related on this blog

Source: WIRED

Automated digest: summary generated from publicly available RSS + article pages.

Post a Comment

Previous Post Next Post