Loading...
Loading...
Last September, a Chinese state-sponsored hacking group used an AI model to run a cyber espionage campaign against roughly thirty targets across the globe, including chemical manufacturers. The operation took place at machine speed and confirmed what many researchers had been saying for years: that large language models would reshape the cybersecurity landscape.
Less than one year later, Anthropic released Mythos, a frontier AI model able to autonomously discover exploits in nearly any system or network. OpenAI’s latest model has similar capabilities, and the open-source models are only a few months behind. What previously took a nation-state to do will soon be achievable with a few hundred dollars of tokens.
For the past twenty years, attacking industrial systems required years of specialized training, custom tooling, and a nation-state budget. That model is now dead. Today, it takes a laptop and an internet connection. Welcome to “the Infinite Front.” American firms should take note.
The Chinese have been preparing for this day for a long time. Volt Typhoon, a Beijing-linked group, has maintained persistent access to a broad swath of American critical infrastructure for years. The Department of Homeland Security openly talks about how this group is likely pre-positioning to disrupt industrial systems in the event of a conflict over Taiwan.1
At an electric and water utility in Littleton, Massachusetts, Volt Typhoon sat inside the operational technology network for roughly three hundred days while they exfiltrated geographic information system (GIS) data and spatial layouts necessary to conduct targeted cyber attacks; the utility only found out about the breach when the FBI called to notify them.2
Volt Typhoon and similar Chinese-backed hacking groups are already using AI tools to radically accelerate the breadth and speed with which they operate. And the security through obscurity that industrial systems and networks have enjoyed for the past forty years is coming to an end.
In response to this new threat environment, there are three priorities American industrial firms must adopt now, not next quarter. The first is to maximize compliance. Frameworks such as Cybersecurity Maturity Model Certification (CMMC), if taken seriously and not as a box-checking exercise, can serve as a roadmap to a minimally viable security program.
The second is to instrument the factory floor. Firewalls are important, but most activity happens on endpoints. While monitoring industrial networks is important, it is just as important to watch the actual computers performing critical tasks, from engineering workstations to industrial controllers. Most attacker activity happens on these endpoints, and monitoring them can be done passively without touching production.
The third is to remember that security is, at the end of the day, a human task. Basic security training works. Whether it is anti-phishing training or the regular reminder to make sure every person in the office has a correct and working badge, firms need to train their people to be the first line of defense.
1 “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure [Alert Code: AA24-038A],” Cybersecurity and Infrastructure Security Agency, February 7, 2024.
2 For more details on this incident, see: Jonathan Grieg, “Volt Typhoon Hackers were in Massachusetts Utility’s Systems for 10 Months,” Record, March 12, 2025.
点击"双栏对照"切换左右对照视图
去年九月,一个由中国政府支持的黑客组织利用人工智能模型,对全球约三十个目标发起了一场网络间谍行动,涉及对象包括多家化学品制造商。这场行动以机器速度展开,证实了研究人员多年来的论断:大型语言模型将重塑网络安全格局。
不到一年后,Anthropic发布了前沿AI模型Mythos,它能够自主发现几乎任何系统或网络中的漏洞。OpenAI的最新模型也具备类似能力,而开源模型仅落后数月。过去需要国家级力量才能完成的任务,很快只需花费几百美元购买代币即可实现。
过去二十年,攻击工业系统需要数年的专业培训、定制工具以及国家级预算——这种模式如今已宣告终结。现在,一台笔记本电脑和网络连接就足以做到。欢迎来到"无限前线"——美国企业当警醒。
… 点击上方按钮查看完整翻译