{"id":8964,"date":"2026-08-03T08:25:00","date_gmt":"2026-08-03T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8964"},"modified":"2026-08-03T08:25:00","modified_gmt":"2026-08-03T08:25:00","slug":"ai-is-making-cybersecurity-fundamentals-more-important-than-ever","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8964","title":{"rendered":"AI is making cybersecurity fundamentals more important than ever"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">When OpenAI disclosed that one of its models <a href=\"https:\/\/www.csoonline.com\/article\/4200043\/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html\">escaped a test environment<\/a> and broke into Hugging Face\u2019s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: <a href=\"https:\/\/cloudsecurityalliance.org\/artifacts\/hugging-face-ciso-post-mortem\">a misconfigured sandbox<\/a> \u2014 the same kind of fundamental security failure that has enabled breaches for decades, with or without AI.<\/p>\n<p class=\"wp-block-paragraph\">AI systems are indeed <a href=\"https:\/\/www.csoonline.com\/article\/4196409\/ai-powered-breaches-provide-wake-up-call-for-incident-response.html\">already finding software vulnerabilities<\/a>, tailoring social-engineering attacks, analyzing enormous volumes of security data, and beginning to act autonomously across interconnected systems. But the more immediate lesson, experts say, may be less glamorous: The fundamental cybersecurity practices that organizations have struggled to perform for decades are becoming more important, not less.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe cybersecurity fundamentals are as important as ever, probably more so,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/ericbrandwine\/\">Eric Brandwine<\/a>, VP and distinguished engineer at Amazon Web Services, tells CSO. \u201cIt\u2019s the exact same story that it\u2019s always been \u2014 all of the cybersecurity fundamentals \u2014 but you\u2019ve got to be more agile, you\u2019ve got to be more responsive.\u201d<\/p>\n<h2 class=\"wp-block-heading\">AI puts security debt front and center<\/h2>\n<p class=\"wp-block-paragraph\">Cybersecurity programs have always operated under pressure to accept unresolved vulnerabilities, incomplete inventories, aging infrastructure, and poorly controlled access, because fixing them is expensive or operationally disruptive. AI changes the consequences: Weaknesses that once took a skilled human considerable time to discover can now be found through automated, repeated examination of applications, infrastructure, and exposed systems.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOur legacy security debt is now front and center,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\/\">Diana Kelley<\/a>, CISO at Noma Security, tells CSO. \u201cEven simple mistakes that maybe a human wasn\u2019t going to exploit previously, or it was sort of too hard for them to find, we\u2019ve got AI looking again and again, going at machine speed, at agentic scale, looking for all of these exposures and exploiting them potentially.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Kelley points to Noma Security research into an indirect prompt-injection vulnerability called <a href=\"https:\/\/noma.security\/blog\/forcedleak-agent-risks-exposed-in-salesforce-agentforce\/\">ForcedLeak<\/a>. A malicious instruction submitted through a web form <a href=\"https:\/\/www.csoonline.com\/article\/4063044\/vulnerability-in-salesforce-ai-could-be-tricked-into-leaking-crm-data.html\">could cause a Salesforce AI agent to exfiltrate sensitive information<\/a> through an image request. Yet the attack relied on a decidedly conventional oversight: A content security policy still trusted a domain the organization no longer controlled. Researchers registered the abandoned domain for $5. Had it been removed from the content security policy, the exfiltration path would have been blocked.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis was an advanced agentic attack that used indirect prompt injection, but something as simple as DNS hygiene would have prevented it,\u201d Kelley says.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/spafford\/\">Gene Spafford,<\/a> distinguished professor of computer science at Purdue University, sees the vulnerabilities AI is uncovering not merely as technical debt but frequently as the product of conscious business decisions. Organizations and vendors have repeatedly prioritized speed, features, and market share over careful engineering, testing, and risk management.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis kind of thing can often be described as a technical debt, but it\u2019s a willful debt,\u201d Spafford tells CSO. \u201cIt\u2019s a misplaced sense of prioritization of where investment and spending have gone over many years.\u201d<\/p>\n<p class=\"wp-block-paragraph\">AI systems trained on vast collections of software and security information are particularly effective at recognizing repeated patterns of bad coding, weak configurations, and familiar errors \u2014 revealing less about the novelty of the technology than about how much avoidable weakness the industry has allowed to persist.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI is simply catching up with [decades of inadequate software engineering] for the lack of appropriate due care over the last few decades in development,\u201d Spafford says.<\/p>\n<h2 class=\"wp-block-heading\">Attackers are moving faster, not necessarily differently<\/h2>\n<p class=\"wp-block-paragraph\">Generative and agentic AI may <a href=\"https:\/\/www.csoonline.com\/article\/4110008\/top-cyber-threats-to-your-ai-systems-and-infrastructure.html\">introduce distinct risks<\/a>, including prompt injection, <a href=\"https:\/\/www.csoonline.com\/article\/4166171\/poisoned-truth-the-quiet-security-threat-inside-enterprise-ai.html\">data poisoning<\/a>, and the manipulation of autonomous agents. But much of AI\u2019s near-term impact comes from making familiar attack techniques faster, cheaper, or more precisely targeted.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/chris-betz-903b739b\/\">Chris Betz<\/a>, CISO at Google Cloud, describes the defining characteristics of AI-enabled activity as speed, scale, and customization. Traditional automation made it possible to perform the same action repeatedly; AI allows attackers and defenders to perform highly individualized actions repeatedly.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhere automation used to mean doing the same thing at scale, AI allows us to do very specific things at scale,\u201d Betz tells CSO. \u201cWhile we have to change the way we think, in a lot of ways it means that we have to do more of what we\u2019ve done in the past, and we have to do it at a massive scale.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Familiar controls such as <a href=\"https:\/\/www.csoonline.com\/article\/570795\/how-to-hack-2fa.html\">multifactor authentication<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/564201\/what-is-zero-trust-a-model-for-more-effective-security.html\">zero-trust architectures<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/3520881\/patch-management-a-dull-it-pain-that-wont-go-away.html\">system patching<\/a>, and <a href=\"https:\/\/www.csoonline.com\/article\/3476179\/how-your-xdr-is-evaded.html\">effective detection and response<\/a> remain critical. But defenders must apply them consistently enough to withstand attackers who can probe environments continuously and adapt to each target.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou can\u2019t bring just that foundation to an AI fight,\u201d Betz says. \u201cBut you need that foundation. That foundation is what gives the defenders their distinct advantage.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The evidence from incident response continues to point toward familiar weaknesses. <a href=\"https:\/\/www.linkedin.com\/in\/jshier\/\">John Shier<\/a>, field CISO at Sophos, says the two leading root causes appearing year after year in the company\u2019s incident investigations are <a href=\"https:\/\/www.csoonline.com\/article\/1308864\/hackers-using-stolen-credentials-to-launch-attacks-as-info-stealing-peaks.html\">compromised credentials<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/4176086\/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html\">exploited vulnerabilities<\/a>. In many of those incidents, multifactor authentication was absent from at least some exposed services, and attackers exploited vulnerabilities for which patches had been available for months.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere are no new vulnerability classes, and there are no new attack types. AI hasn\u2019t changed that yet,\u201d Shier tells CSO. \u201cThe things that we know how to mitigate and how to deal with are still the ones that the attackers are exploiting writ large.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Shier compares an organization relying on sophisticated detection without basic prevention to a modern vehicle equipped with driver-assistance sensors and airbags \u2014 but no brakes. Detection and response was a necessary correction to the notion that every intrusion could be prevented, but it becomes dangerous when organizations treat prevention as outdated or assume AI will contain every malicious action after it begins.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s the trap Shier sees organizations falling into \u2014 treating AI as a reason to worry less about prevention. \u201cIt can solve some problems,\u201d he says, \u201cbut it can\u2019t solve all of the problems that are addressed by preventive technologies or by reducing or eliminating risks altogether.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Identity, cloud, and SaaS remain pressure points<\/h2>\n<p class=\"wp-block-paragraph\">AI-enabled attackers do not need to \u201chack in\u201d when they can obtain credentials, session tokens, or authenticated access, and the expansion of cloud services, remote work, and SaaS has given adversaries more identities, permissions, and connections to target.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.crowdstrike.com\/en-us\/about-us\/executive-team\/adam-meyers\/\">Adam Meyers<\/a>, SVP of counter adversary operations at CrowdStrike, says organizations must first learn to \u201cdo cybersecurity well\u201d before expecting advanced technologies to compensate for foundational weaknesses.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOrganizations have quickly moved into remote work, and they\u2019ve moved toward cloud systems,\u201d Meyers tells CSO. \u201cIn a lot of cases, unfortunately, they haven\u2019t kept pace cybersecurity-wise and haven\u2019t done some of the basics correctly with identity in particular, but also cloud.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Meyers points to identity threat detection and response as an increasingly important baseline capability, because criminal actors are seeking passwords, authentication tokens, and ways to bypass multifactor authentication. Asked whether AI could perform the fundamentals for organizations, he was skeptical of treating the technology as a substitute for implementation and accountability.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe fundamentals are the fundamentals,\u201d he says. \u201cI don\u2019t know if you need AI to do the fundamentals. I think you need to pull up your pants and do the fundamentals.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Good practices block entire classes of attacks<\/h2>\n<p class=\"wp-block-paragraph\">The number of vulnerabilities discovered through AI-assisted research is likely to grow. <a href=\"https:\/\/www.linkedin.com\/in\/tonysagercyber\/\">Tony Sager<\/a>, SVP and chief evangelist at the Center for Internet Security, argues that organizations should not interpret that growth as requiring a unique defense for every newly identified flaw, given that vulnerabilities fall into recurring classes that well-chosen security practices can block or constrain at once.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou can\u2019t think of it as, \u2018I have to find and fix every one of them,\u2019 because they\u2019re not all unique. They fall in classes,\u201d Sager tells CSO. \u201cThose good practices \u2014 the basics of identity management, configurations, and all those kinds of things \u2014 block lots of those different classes of attacks.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Frameworks and prioritized security controls translate complex knowledge about attacks, software flaws, and adversary behavior into a set of repeatable organizational practices. Their recommendations may sound elementary, but the simplicity of the behavior does not mean the analysis behind it is simplistic.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou don\u2019t need to read threat reports,\u201d Sager says. \u201cYou just need to engage in the practices that are found in things like the NIST framework and the CIS Critical Security Controls. You get a lot of value out of that, and you should do that because that\u2019s the foundation of good defense.\u201d<\/p>\n<p class=\"wp-block-paragraph\">As AI produces more examples of familiar flaws and gives adversaries the ability to search for them more rapidly, organizations with weak foundational controls will be exposed to more attempts against a larger number of weaknesses.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you haven\u2019t done these basic things, you\u2019re weaker than ever,\u201d Sager says. \u201cThe importance of those fundamental things has only gone up.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Humans must know when the AI is wrong<\/h2>\n<p class=\"wp-block-paragraph\">Cybersecurity fundamentals are not confined to technical controls. Security practitioners must also understand core cybersecurity principles well enough to evaluate AI-generated recommendations and recognize when a model has produced a plausible but incorrect answer.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you as a human being don\u2019t understand the basics of cybersecurity and you\u2019re relying entirely on whatever AI you\u2019re interacting with to tell you, then if the AI goes off \u2014 whether it drifts, gets misaligned, or there\u2019s been poisoning via prompt injection \u2014 you have no ability as the person reading this output to figure out if that\u2019s right or not,\u201d Noma Security\u2019s Kelley says.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/scottbeale\/\">Scott Beale<\/a>, CEO of ISC2, similarly warns that AI\u2019s ability to increase capacity <a href=\"https:\/\/www.csoonline.com\/article\/4198016\/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html\">does not eliminate the need for human judgment<\/a>. An erroneous recommendation about a coffee shop is inconsequential; one affecting an organization\u2019s systems, data, or response to an attack is not.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou need to be able to differentiate what is accurate and what\u2019s not,\u201d Beale tells CSO. \u201cThey also know that when errors are made, it is a human who\u2019s going to be held accountable for whether the right decisions were made.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That accountability, Beale says, is exactly why AI can\u2019t be allowed to lower the floor on human judgment: \u201cHuman judgment and human oversight are absolutely critical, even if you\u2019re partnering with these AI tools.\u201d<\/p>\n<h2 class=\"wp-block-heading\">New AI-specific attacks do not replace traditional threats<\/h2>\n<p class=\"wp-block-paragraph\">Organizations must also distinguish between attacks conducted with AI and attacks directed against the AI systems they use.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/rogeragrimes\/\">Roger Grimes<\/a>, a longtime security researcher and CISO adviser, says AI-enhanced attackers continue to rely heavily on the two dominant initial-access techniques of the broader internet era: social engineering and exploitation of unpatched vulnerabilities. AI can create more convincing phishing campaigns, deepfakes, and customized lures, while also helping identify known and previously undiscovered software flaws.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen AI threats come, as they already are, they\u2019re going to use and abuse those same traditional, classical ways that hackers have always broken in,\u201d Grimes tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">At the same time, organizations are deploying systems vulnerable to prompt injection, model manipulation, data leakage, and other attacks aimed directly at AI. Grimes compares prompt injection to SQL injection: a form of attack made possible by a particular underlying technology. The difference is that AI will be embedded across desktops, devices, and interconnected services, and an attack against one model may reach an organization through an AI supply chain security teams have not fully mapped.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere are attacks from AI against you, whether or not you\u2019re using AI,\u201d Grimes says. \u201cAnd then there are attacks to the AI that you use, because we\u2019re all using AI in some way, and that\u2019s only going to grow over time.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Traditional security fundamentals will mitigate many of the pathways attackers use to reach AI systems, but organizations will also need new controls for models, agents, prompts, and AI data flows. This, Grimes says, is an expansion of the security program, not an excuse to abandon what came before.<\/p>\n<h2 class=\"wp-block-heading\">AI can help do the hard, tedious work<\/h2>\n<p class=\"wp-block-paragraph\">None of the experts argues that CISOs should turn away from AI. Used carefully, it can help security teams analyze telemetry, investigate alerts, discover assets, examine code, and identify vulnerabilities \u2014 scaling work organizations have historically performed poorly because it is tedious and labor-intensive.<\/p>\n<p class=\"wp-block-paragraph\">AWS\u2019s Brandwine says security organizations need ways to experiment with AI without subjecting every idea to a lengthy production review. A new AI-powered detection, for example, can run in parallel with an established system so defenders can compare results without immediately depending on it. That agility becomes essential as developers produce software faster and employees adopt new models and agents, requiring security teams to keep pace without turning governance into an obstacle employees evade.<\/p>\n<p class=\"wp-block-paragraph\">AI may finally make some aspects of security hygiene easier to sustain \u2014 assisting with asset classification, correlating disconnected inventories, prioritizing remediation work, and reducing the manual burden of reviewing logs. But its results will be only as dependable as the systems, data, and human decisions surrounding it.<\/p>\n<p class=\"wp-block-paragraph\">The winning formula is therefore neither \u201cforget AI and return to the basics\u201d nor \u201clet AI solve cybersecurity.\u201d It is to use AI to increase the speed and scale at which organizations perform the fundamentals while preserving the human knowledge, governance, and accountability necessary to determine whether the technology is getting the work right.<\/p>\n<p class=\"wp-block-paragraph\">As Google Cloud\u2019s Betz puts it, the journey is \u201ca firm foundation and a move-faster piece with AI on top.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face\u2019s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox \u2014 the same kind of fundamental [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8964"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8964"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8965"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}