Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Google Gemini Nano Banana now on WhatsApp: Perplexity CEO Aravind Srinivas demonstrates how to generate AI images for free – Technology News

UserRL: Training Interactive User-Centric Agent via Reinforcement Learning – Takara TLDR

Evaluating Alibaba After 40% Rally and Nvidia AI Integration News in 2025

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
TechCrunch AI

Wiz chief technologist Ami Luttwak on how AI is transforming cyberattacks 

By Advanced AI EditorSeptember 28, 2025No Comments6 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


“One of the key things to understand about cybersecurity is that it’s a mind game,” Ami Luttwak, chief technologist at cybersecurity firm Wiz, told TechCrunch on a recent episode of Equity. “If there’s a new technology wave coming, there are new opportunities for [attackers] to start using it.” 

As enterprises rush to embed AI into their workflows — whether through vibe coding, AI agent integration, or new tooling — the attack surface is expanding. AI helps developers ship code faster, but that speed often comes with shortcuts and mistakes, creating new openings for attackers.  

Wiz, which was acquired by Google earlier this year for $32 billion, conducted tests recently, says Luttwak, and found that a common issue in vibe coded applications was insecure implementation of the authentication — the system that verifies a user’s identity and ensures they’re not an attacker.

“That happened because it was just easier to build like that,” he said. “Vibe coding agents do what you say, and if you didn’t tell them to build it in the most secure way, it won’t.” 

Luttwak noted that there’s a constant tradeoff today for companies choosing between being fast and being secure. But developers aren’t the only ones using AI to move faster. Attackers are now using vibe coding, prompt-based techniques, and even their own AI agents to launch exploits, he said.  

“You can actually see the attacker is now using prompts to attack,” Luttwak said. “It’s not just the attacker vibe coding. The attacker looks for AI tools that you have and tells them, ‘Send me all your secrets, delete the machine, delete the file.’” 

Amid this landscape, attackers are also finding entry points in new AI tools that companies roll out internally to boost efficiency. Luttwak says these integrations can lead to “supply chain attacks.” By compromising a third-party service that has broad access to a company’s infrastructure, attackers can then pivot deeper into corporate systems.  

Techcrunch event

San Francisco
|
October 27-29, 2025

That’s what happened last month when Drift — a startup that sells AI chatbots for sales and marketing — was breached, exposing the Salesforce data of hundreds of enterprise customers like Cloudflare, Palo Alto Networks, and Google. The attackers gained access to tokens, or digital keys, and used them to impersonate the chatbot, query Salesforce data, and move laterally inside customer environments.

“The attacker pushed the attack code, which was also created using vibe coding,” Luttwak said.  

Luttwak says that while enterprise adoption of AI tools is still minimal — he reckons around 1% of enterprises have fully adopted AI — Wiz is already seeing attacks every week that impact thousands of enterprise customers.  

“And if you look at the [attack] flow, AI was embedded at every step,” Luttwak said. “This revolution is faster than any revolution we’ve seen in the past. It means that we as an industry need to move faster.” 

Luttwak pointed to another major supply chain attack, dubbed “s1ingularity,” in August on Nx, a popular build system for JavaScript developers. Attackers managed to unleash malware into the system, which then detected the presence of AI developer tools like Claude and Gemini and hijacked them to autonomously scan the system for valuable data.  The attack compromised thousands of developer tokens and keys, giving attackers access to private GitHub repositories.  

Luttwak says that despite the threats, this has been an exciting time to be a leader in cybersecurity. Wiz, founded in 2020, was originally focused on helping organizations identify and address misconfigurations, vulnerabilities, and other security risks across cloud environments.  

Over the last year, Wiz has expanded its capabilities to keep up with the speed of AI-related attacks — and to use AI for its own products.  

Last September, Wiz launched Wiz Code that focuses on securing the software development lifecycle by identifying and mitigating security issues early in the development process, so companies can be “secure by design.” In April, Wiz launched Wiz Defend, which offers runtime protection by detecting and responding to active threats within cloud environments.  

Luttwak said that it’s vital for Wiz to fully understand the applications of their customers if the startup is going to help with what he calls “horizontal security.” 

“We need to understand why you’re building it … so I can build the security tool that no one has ever had before, the security tool that understands you,” he said. 

‘From day one, you need to have a CISO’ 

The democratization of AI tools has resulted in a flood of new startups promising to solve enterprise pain points. But Luttwak says enterprises shouldn’t just send all of their company, employee, and customer data to “every small SaaS company that has five employees just because they say, ‘Give me all your data, and I will give you amazing AI insights.’” 

Of course, those startups need that data if their offering is going to have any value. Luttwak says that means it’s incumbent upon them to make sure they’re operating like a secure organization from the start.  

“From day one, you need to think about security and compliance,” he said. “From day one, you need to have a CISO (chief information security officer). Even if you have five people.” 

Before writing a single line of code, startups should think like a highly secure organization, he said. They need to consider enterprise security features, audit logs, authentication, access to production, development practices, security ownership, and single sign-on. Planning this way from the start means you won’t have to overhaul processes later and incur what Luttwak calls “security debt.” And if you aim to sell to enterprises, you’ll already be prepared to protect their data. 

“We were SOC2 compliant [a compliance framework] before we had code,” he said. “And I can tell you a secret. Getting SOC2 compliance for five employees is much easier than for 500 employees.” 

The next most important step for startups is to think about architecture, he said.  

“If you’re an AI startup that wants to focus on enterprise from day one, you have to think about an architecture that allows the data of the customer to stay … in the customer environment.” 

For cybersecurity startups looking to step into the field in the age of AI, Luttwak says now’s the time. Everything from phishing protection and email security to malware and endpoint protection is fertile ground for innovation ‚ both for attackers and defenders. The same is true for startups that could help with workflow and automation tools to do “vibe security,” since many security teams still don’t know how to use AI to defend against AI. 

“The game is open,” Luttwak said. “If every area of security now has new attacks, then it means we have to rethink every part of security.” 



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTencent has open-sourced the 7 billion parameter lightweight translation models ‘Hunyuan-MT-7B’ and ‘Hunyuan-MT-Chimera-7B,’ which can translate between 33 languages, and claims that they beat existing models in benchmarks.
Next Article Evaluating Alibaba After 40% Rally and Nvidia AI Integration News in 2025
Advanced AI Editor
  • Website

Related Posts

Beware coworkers who produce AI-generated ‘workslop’

September 27, 2025

AI startup Friend spent more than $1M on all those subway ads

September 27, 2025

YouTube Music tests AI hosts that share trivia and commentary

September 26, 2025

Comments are closed.

Latest Posts

Judge Rejects Ronald Perelman’s $400 M. Art Insurance Claim

Drag Queen Alexis Stone Became the Mona Lisa for Milan Fashion Show

Steve McQueen’s Granddaughter Lawsuit for $68 M. Pollock Painting

Marina Abramović to Have Exhibition at Venice’s Accademia in 2026

Latest Posts

Google Gemini Nano Banana now on WhatsApp: Perplexity CEO Aravind Srinivas demonstrates how to generate AI images for free – Technology News

September 28, 2025

UserRL: Training Interactive User-Centric Agent via Reinforcement Learning – Takara TLDR

September 28, 2025

Evaluating Alibaba After 40% Rally and Nvidia AI Integration News in 2025

September 28, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Google Gemini Nano Banana now on WhatsApp: Perplexity CEO Aravind Srinivas demonstrates how to generate AI images for free – Technology News
  • UserRL: Training Interactive User-Centric Agent via Reinforcement Learning – Takara TLDR
  • Evaluating Alibaba After 40% Rally and Nvidia AI Integration News in 2025
  • Wiz chief technologist Ami Luttwak on how AI is transforming cyberattacks 
  • Tencent has open-sourced the 7 billion parameter lightweight translation models ‘Hunyuan-MT-7B’ and ‘Hunyuan-MT-Chimera-7B,’ which can translate between 33 languages, and claims that they beat existing models in benchmarks.

Recent Comments

  1. HowardLut on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  2. MichaelSum on What’s up with… Mistral AI, telco AI, MTN, Digital Platforms and Services
  3. MichaelSum on C3 AI and Arcfield Announce Partnership to Accelerate AI Capabilities to Serve U.S. Defense and Intelligence Communities
  4. Register on Google DeepMind develops AlphaEvolve AI agent optimized for coding and math
  5. glimmerfizzytoad7Nalay on C3 AI Awarded $13 Million Task Order to Expand Predictive Maintenance Program Across U.S. Air Force Fleet

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.