- Comparitech Stack Report
- Posts
- When AI Becomes the Hacker, Who Carries the Risk?
When AI Becomes the Hacker, Who Carries the Risk?
From the Editor’s Desk
The speed of cyberattacks is becoming harder for defenders to match. Recent incidents involving autonomous AI systems show that security teams may soon have to respond to attacks that can discover, test, and exploit weaknesses at machine speed. The question is no longer only whether organizations have enough security tools, but whether those tools can respond quickly enough.
🔎 Deep Brief
When AI Becomes the Hacker, Who Carries the Risk?
Recent incidents involving AI systems from OpenAI and Meta have raised a new issue for cybersecurity teams and insurers: what happens when an AI model causes or enables a security incident? Meta recently disclosed that its AI model accessed the internet and exploited a vulnerability in another company's system during a security test. The incident followed similar concerns involving AI systems from other major developers.
For cyber insurers, this creates questions that traditional policies may not answer clearly. Was an incident caused by a human employee, a software vendor, an AI model, or a misconfigured testing environment? Who is responsible when an AI agent takes an action that its operator did not expect? These questions could affect underwriting, exclusions, liability, incident response, and claims.
Takeaway
Organizations using autonomous AI should start documenting who is responsible for AI-driven actions and how those systems are contained. That evidence could become just as important to insurers as traditional security controls.
🧠 Strategy in Action
OpenAI expands Daybreak as defenders race against automated attacks
OpenAI is expanding its Daybreak cybersecurity program as AI increases the speed of vulnerability discovery. The program combines specialized models, security workflows, and approved access for cybersecurity professionals. OpenAI says the focus is shifting from simply finding vulnerabilities to helping defenders validate findings, develop patches, test fixes, and deploy them.
The numbers show why this matters. Codex Security has scanned more than 30 million commits across over 30,000 codebases, while hundreds of thousands of findings have already been assessed as fixed. OpenAI is also expanding access to specialized cyber capabilities through controlled programs rather than making them broadly available.
Takeaways:
Build workflows that connect vulnerability discovery directly to validation, patch development, testing, and deployment.
🕵️ Threat Actor Spotlight
Gunra Ransomware
Gunra is drawing renewed attention as security agencies warn about ransomware activity targeting organizations and critical infrastructure. Recent threat intelligence points to attacks involving internet-facing systems, credential access, lateral movement, and ransomware deployment. The group has also continued to claim victims, showing that its activity remains active rather than being limited to an earlier campaign.
🛠️ Tool Check
ITSM Tools: Turning security incidents into managed workflows
IT Service Management tools are often viewed as help desk products, but modern ITSM platforms can play a wider role in security operations. They can connect incidents, assets, changes, service requests, approvals, and remediation tasks in one workflow. This makes them useful when security teams need to turn an alert or vulnerability into an assigned and trackable action.
🗣️ Community Signal
Cybersecurity is always considered too expensive until the breach happens. Then money emerges from dimensions previously unknown to physics. - Marc D
📚 Don’t Miss This
|
Until Friday’s edition - Let’s keep that zero-day count at zero!