AI-Driven Threats
Unlock the complete study guide + 1,040 practice questions across 16 full exams.
Bundled into the existing CompTIA SecAI+ premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- What AI changed for the attacker, and what it did not
- Automated phishing: reconnaissance, pretext and lure
- Synthetic voice and video in social engineering
- Polymorphic malware and LLM-assisted development
- Vulnerability research and the shrinking exploitation window
- Where the capability comes from: jailbreaks and tools as a service
- When the model runs the chain: agents and run-time calls
- What actually changes in your controls
- Exam patterns: telling the tool side from the target side
What each of the three jobs actually changes for a defender
| Property | Content and language work | Code and vulnerability work | Orchestration of the chain |
|---|---|---|---|
| What the model does for the attacker | Synthesises open-source research into targets and pretexts, writes the lure, generates the voice or the face | Reads code for flaws, drafts exploit code, produces malware and infrastructure variants | Chains reconnaissance, exploitation and collection through tool calls while an operator supervises |
| Assessed uplift | Largest and most evenly spread; significant uplift for less-skilled actors from a low base | Real but gated on expertise, resource and quality data; assessed as the most significant development still to come | Skilled actors experimenting with automating parts of the chain; fully automated end-to-end attacks assessed unlikely to 2027 |
| Who it reaches | Anyone with access to a general-purpose model | Actors who already had the skill, plus buyers of tooling sold as a service | Well-resourced actors with agent frameworks and tool integrations |
| How ATT&CK names it | Query Public AI Services (T1682), Generate Content (T1683) with written and audio-visual sub-techniques | Obtain Capabilities: Artificial Intelligence (T1588.007), Polymorphic Code (T1027.014) | No single technique; documented through campaign reporting that spans the ordinary techniques end to end |
| The defence that stopped working | Teaching users to recognise poor language and generic greetings | Signature-only detection, and a patch window measured in weeks | Containment that starts with a human reading the first alert |
| What replaces it | Out-of-band verification of the request before any irreversible action | Exploitability-driven patching plus behaviour-based detection | Pre-authorised automatic containment for reversible actions, with irreversible ones still gated |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
References
- LAMEHUG (S9035) Whitepaper
- CompTIA SecAI+ (CY0-001) certification page
- Query Public AI Services (T1682) Whitepaper
- Generate Content (T1683) Whitepaper
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 Whitepaper
- Obtain Capabilities: Artificial Intelligence (T1588.007) Whitepaper
- Impact of AI on cyber threat from now to 2027 Whitepaper
- CSRC Glossary: phishing Whitepaper
- CSRC Glossary: social engineering Whitepaper
- Phishing (T1566) Whitepaper
- Generate Content: Written Content (T1683.001) Whitepaper
- The near-term impact of AI on the cyber threat Whitepaper
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) Whitepaper
- Generate Content: Audio-Visual Content (T1683.002) Whitepaper
- Social Engineering (T1684) Whitepaper
- Polymorphic Code (T1027.014) Whitepaper
- CSRC Glossary: zero-day attack Whitepaper
- Anthropic AI-orchestrated Campaign (C0062) Whitepaper
- Phishing attacks: defending your organisation Whitepaper