Generative AI hacking

B2B Cyber ​​Security ShortNews

Share post

An international hacking study shows that 72 percent of hackers believe that artificial intelligence (AI) will not replace human creativity in security research and vulnerability management.

Generative AI is a key topic in the Inside the Mind of a Hacker report. More than half of those surveyed (55 percent) said they can already surpass the capabilities of hackers or will be able to do so in the next five years. Almost three in four respondents (72 percent) believe that generative AI will not be able to surpass the creativity of hackers.

When asked how generative AI is being used, hackers cited automating tasks (50 percent), analyzing data (48 percent), identifying vulnerabilities (36 percent), validating results (35 percent), and conducting reconnaissance (33 percent). Nearly two in three respondents (64 percent) believe that generative AI technologies have increased the value of ethical hacking and security research.

Hacker Stereotypes

The stereotype that hackers are disproportionately male is proving to be accurate: 96 percent of respondents identified themselves as male and just 4 percent as female, with a further 0,2 percent identifying as non-binary or gender-neutral. Most hackers (82 percent) don't hack for a living, but consider it either a part-time job, a side hustle, or something they're about to turn into a full-time job. Only 29 percent named hacking as their full-time job. Motivations for ethical hacking were diverse, but the top motivators were personal development (28 percent), financial gain (24 percent), excitement (14 percent), and challenge (12 percent). Another 6 percent of respondents said they hack for the greater good, and 87 percent said reporting a vulnerability is more important than making money from it.

Hacking and vulnerability management

Opinions differ on how many companies know their true risk of a breach: 27 percent of respondents said that less than 10 percent of companies really know the risk. Another third of respondents (33 percent) said 10 to 25 percent of organizations know their risk, but just 16 percent said more than half of organizations know their true risk of a breach. Respondents painted a mixed picture of the global threat landscape. 84 percent said there have been more vulnerabilities since the start of the COVID-19 pandemic, and 88 percent said point security testing is not enough to keep organizations safe. Still, 78 percent of respondents confirmed that most organizations' attack surfaces are becoming increasingly difficult to compromise. Another 89 percent said companies are increasingly viewing ethical hackers positively.

More at Bugcrowd.com

 


About Bugcrowd

Bugcrowd, the only multi-solution crowdsourced cybersecurity platform, combines data- and ML-driven crowd-matching with decades of application experience to focus the right human creativity on the right problem at the right time. Trusted by companies around the world, the Bugcrowd Security Knowledge Platform™ makes it possible to find hidden vulnerabilities throughout their attack surface before they can be exploited, leveraging the knowledge of world-class ethical hackers. Bugcrowd is based in San Francisco and is backed by Blackbird Ventures, Costanoa Ventures, Industry Ventures, Paladin Capital Group, Rally Ventures, Salesforce Ventures and Triangle Peak Partners.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

Crowdsourced security pinpoints many vulnerabilities

Crowdsourced security has increased significantly in the last year. In the public sector, 151 percent more vulnerabilities were reported than in the previous year. ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more