Cyberscoop

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching


Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official.

The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities.

Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.” 

“You’re going to have additional offensive actions coming at your environment, targeting the network at speed and capability,” he said. And he expects it to keep getting worse, with AI-enabled attacks already having a measurable impact, as demonstrated by the numbers in a new section of the annual FBI report on digital crimes.

“The wave is coming. I don’t think we’ve hit the crest yet,” Bilnoski said. “We see an exponential increase in the use of AI, whether it’s nation-state or criminal.”

Still, AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent, Bilnoski said. It’s something the FBI sees again and again when it conducts investigations, even those with an AI element.

“The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following,” he said, referring to a recent FBI emphasis on 10 fundamental defensive measures like multifactor authentication. “If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment.”

“What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said.

The FBI, meanwhile, will “continue to pursue AI in a way that will help us defend at scale,” Bilnoski said.

Patching pacing

The speed at which AI models are uncovering vulnerabilities means organizations need to rethink their approach to patching, another FBI official said at the Billington event.

“We no longer can essentially do the quarterly patching,” said Colleen Ferranti, assistant section chief, cyber engagement and intelligence section. “We have to evolve with the time, and we have to do more risk-based type patching, and we have to be doing that continuously.”

“So, from our perspective, the day-to-day or quarterly or Patch Tuesday — this needs to be a patch-all-of-the-time, and making sure that we are trusting our systems to also be engaging with that type of technology and at that speed and that level,” she continued.

AI now in FBI cyber strategy

The FBI strategy also has a section devoted to artificial intelligence.

“FBI Cyber will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, support attribution, and identify patterns that no human analyst could process at the required pace,” it states. “Consistent with President Trump’s Cyber Strategy for America, FBI Cyber will rapidly adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate.”

The FBI likewise wants to develop additional tools and techniques, according to the strategy.

“The FBI will continue to develop its Computer Network Operations (CNO) program, providing investigative teams with the court-authorized or otherwise lawfully authorized technical operations tools to remotely collect, conduct surveillance, and disrupt the activities of nation-state and cybercriminal actors when traditional investigative techniques will not achieve the required outcome,” it reads.

The strategy largely reflects a number of existing practices at the agency, such as a focus on disrupting attackers. But one emphasis is on relief and justice for victims.

It contains a “pledge” in support of them: “Pursuing our mission, we recognize that we will encounter unique and novel issues related to privacy and the handling of sensitive data. We will always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

It also promises to quickly share threat intelligence, swiftly respond after incidents and expand “its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office.” 

It’s the latest document of the Trump administration to focus on cyber strategy, following the release earlier this year of its overall cyber strategy and the Defense Department’s version expected to publish soon as well.

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Source link