•   sales@dolos.africa
  • +27 21 683 3899
DolosDolosDolosDolos
  • Home
  • Solutions
    • Endpoint Security
      • Endpoint Protection
      • Endpoint Detection & Response
      • Add-on Modules
      • DNS Protection
    • Advanced Endpoint Security
      • Advanced EDR & EPDR
      • Threat Hunting Platform
      • Add-on Modules
      • MDR
    • XDR – Unified Security
    • Network Security
    • Multi-Factor Authentication
    • Secure Wi-Fi
    • Document Security
    • RMM Solutions
    • Cyber Assessment
  • Partners
  • News
    • Blog
    • Press Office
  • Support
  • About Us
  • Contact

AI: Vital Tool or Rising Threat?

    Home Advanced Endpoint Security AI: Vital Tool or Rising Threat?

    AI: Vital Tool or Rising Threat?

    By Andrea Kemsley | Advanced Endpoint Security | Comments are Closed | 13 November, 2024 | 0

    In a world as technologically dependent as the one we live in, individuals and companies are more vulnerable than ever to multiple threats, ranging from ransomware and malware attacks to data theft and other forms of cybercrime. This reality underscores the growing importance of artificial intelligence in cybersecurity as a key technology to prevent, detect, and respond to potential security breaches that could result in sensitive information disclosure and economic damage, leading to loss of trust from partners and customers. However, if we look at the specific impact of AI in cybersecurity, there are positives and negatives.

    That said, not everyone in the industry is aware of this situation. According to a recent survey, only 46% of security professionals surveyed believe they understand both the positive and negative impacts of this technology on cybersecurity.

    Considering the growing impact AI is having on cybersecurity, it is crucial to understand the magnitude of the situation and understand how to use AI-powered solutions to your advantage, as well as protect yourself from potential attacks that exploit this self-same technology.

    New use cases for AI in cyber attacks 

    Not surprisingly, cybercriminals have spotted the opportunity AI delivers to make their attacks more effective. This is precisely why many cybersecurity professionals have been studying and warning about potential misuses of AI for some time now.

    A prime example is Morris II. This malicious worm does not incorporate artificial intelligence in its inner workings, instead its propagation method exploits vulnerabilities in generative AI systems. In other words, although this worm is not AI-driven, its effectiveness is directly dependent on systems that are. This malware was developed by a group of researchers at Cornell Tech, a research centre at Cornell University, New York, with the purpose of alerting us to threats lurking in generative AI systems, while highlighting the need to strengthen security measures in these environments through implementing measures to control the use of this type of technology.

    Cybersecurity experts also warn about the high probability of hackers managing to circumvent the protection of tools such as ChatGPT, then using them to produce malicious content and develop new forms of attack, which flags up the damage that could be inflicted by misuse of AI-powered tools.

    Language models such as ChatGPT can be used maliciously if users manage to bypass security restrictions. The controls implemented in these systems are designed to prevent generating responses that could facilitate illicit activities, such as the creation of malware or the dissemination of harmful information. However, cybercriminals can attempt to circumvent these restrictions by manipulating language, using indirect descriptions or less obvious terms to achieve their goals.

    For instance, instead of directly requesting code for ransomware, a user could take advantage of the tool’s blind spots to describe specific functionality that is part of a malicious programme without explicitly mentioning that it is malware. This could lead to the generation of code fragments that, although not constituting full malware, could be used as the basis for developing a malicious tool.

    This process could result in the creation of polymorphic malware, which constantly changes its form to evade traditional security solutions, making it more difficult to detect and mitigate. Polymorphic malware is particularly dangerous because it uses code variability to escape detection signatures, making it a difficult threat to control.

    Ultimately, misuse of tools powered by generative AI can lead to the automated creation of new and increasingly evasive malware. We need to strengthen security measures in these environments now to prepare companies for this increasingly real threat.

    Using AI to enhance cybersecurity  

    The good news is that AI can also be applied to improve cybersecurity solutions and positively impact the protection of company systems, even against the most evasive attacks.

    If your managed service provider offers an advanced EDR solution, which bases its main endpoint threat detection and response functionalities on artificial intelligence, it can strengthen protection capabilities in the following ways:

    • Advanced threat detection:

    Thanks to machine learning characteristic of AI, solutions are able to analyse large volumes of data and detect potential threats in real time, and thus recognise advanced threats that traditional security solutions might miss. This delivers greater detection efficiency, reducing the chances of successful attacks through early identification.

    • Analysis and prediction: 

    These technologies help to obtain analysis that provides a deep understanding of the techniques, tactics, and procedures (TTPs) used by cybercriminals. AI can correlate past events with suspicious behaviour to facilitate the identification of vulnerabilities and strengthen protection under a prevention-based system.

    • Automated incident response:

    AI-based EDR solutions can automate incident response, minimising reaction time and, with it, the consequences and propagation of the attack. When a threat is detected, predefined actions can be executed, such as isolating the affected device, blocking malicious processes, and generating detailed alerts for computers, improving the effectiveness of protection efforts.

    Given this situation, it is essential that cybersecurity teams are updated to understand how to combat new types of attacks based on artificial intelligence and thus put half-prevention and control against possible attacks.

    However, it is equally important to know how to use it to their advantage to strengthen the protection of devices against increasingly sophisticated threats and thus reduce the attack surface. By understanding the potential of AI in both offensive and defensive cyber strategies, companies can prepare for the pervasive role of AI in cybersecurity. For more information on the latest solutions that WatchGuard Technologies offers against AI-driven attacks, please contact the Dolos team.

    Contact us
    Advanced Endpoint Detection & Response
    WatchGuard Technologies

    Related Post

    • Beyond the Breach: What A Ransomware Gang Taught the Cybersecurity Industry

      By Andrea Kemsley | Comments are Closed

      What is ransomware? In 2025, ransomware is no longer just malicious software that encrypts your machines. It has morphed into something more dangerous: extortion built on stolen data. Attackers don’t stop at locking files; theyRead more

    • The Reseller Shift to Managed Services: Where to Start and Why It Matters

      By Andrea Kemsley | Comments are Closed

      Resellers are feeling the pressure: escalating cybersecurity demands, tighter customer budgets, and increasingly commoditised product sales. Managed services provide a path forward to offer recurring revenue, stronger customer retention, and a more scalable business model.Read more

    • Navigating Living-off-the-Land Attacks: Understanding Threat and Defence Strategies

      By Andrea Kemsley | Comments are Closed

      In cybersecurity, “Living-off-the-land” (LotL) attacks have become increasingly difficult to detect. These attacks exploit legitimate system tools like PowerShell, WMI, or Office macros instead of relying on external malware, allowing attackers to move stealthily withinRead more

    • Modern SOC Series V: how modern SOCs help organisations manage cyber risk

      By Andrea Kemsley | Comments are Closed

      Cyber adversaries constantly leverage sophisticated, malicious applications and legitimate tools to infiltrate organisations and evade existing security controls. To counter such attacks, security teams need to transition from security management to proactive security operations, efficientlyRead more

    • Modern SOC Series IV: the various deployment models of a modern SOC operation

      By Andrea Kemsley | Comments are Closed

      Constructing a modern SOC A modern SOC (Security Operations Centre) can be built internally, although many organisations lack the in-house resources to accomplish this and struggle to find suitable staff members due to the deepRead more

    Recent Posts

    • 17 March, 2026
      Comments Off on In Full Bloom: What Cybersecurity Maturity Looks Like

      In Full Bloom: What Cybersecurity Maturity Looks Like

    • 5 February, 2026
      Comments Off on Modern Security, Simplified: Introducing WatchGuard’s All in One Zero Trust Bundle

      Modern Security, Simplified: Introducing WatchGuard’s All in One Zero Trust Bundle

    • 6 January, 2026
      Comments Off on Weeding Out Cyber Threats: How to Detect and Stop Common Attacks

      Weeding Out Cyber Threats: How to Detect and Stop Common Attacks

    • 5 December, 2025
      Comments Off on Is a single layer of defence enough in the hybrid era?

      Is a single layer of defence enough in the hybrid era?

    Categories

    • Add-on Modules
    • Advanced Endpoint Security
    • Channel Partner Program
    • DNS Protection
    • Endpoint Detection & Response
    • Endpoint Protection
    • Multi-Factor Authentication
    • Network Security
    • Secure Wi-Fi
    • Unified Security

    Tags

    Adaptive Defense Adaptive Defense 360 AuthPoint Cybersecurity Culture DNSWatchGo Endpoint Security Panda Security Patch Management Premium Threat Hunting Service Threat Hunting Platform WatchGuard WatchGuard AuthPoint WatchGuard Cloud WatchGuard EPDR WatchGuard Firebox T Series WatchGuard MDR WatchGuardONE WatchGuard Technologies WatchGuard ThreatSync WatchGuard Total MDR WatchGuard Zero Trust Bundle
    • Dax Data Logo
    •   Unit 1 Melomed Office Park
      Punters Way
      Kenilworth
      Cape Town
      7708
    •   +27 21 683 3899
    •   sales@dolos.africa

    Useful Links

    • Solutions
    • Contact
    • Partners
    • Support

    News

    • In Full Bloom: What Cybersecurity Maturity Looks Like

      Imagine your organisation’s cybersecurity as a garden. Achieving maturity is not a

      17 March, 2026
    • Modern Security, Simplified: Introducing WatchGuard’s All in One Zero Trust Bundle

      Hybrid work, cloud applications and constant connectivity have completely reshaped how people

      5 February, 2026
    Copyright © 2025 Dolos. All Rights Reserved.  |  Privacy Policy
    • Home
    • Solutions
      • Endpoint Security
        • Endpoint Protection
        • Endpoint Detection & Response
        • Add-on Modules
        • DNS Protection
      • Advanced Endpoint Security
        • Advanced EDR & EPDR
        • Threat Hunting Platform
        • Add-on Modules
        • MDR
      • XDR – Unified Security
      • Network Security
      • Multi-Factor Authentication
      • Secure Wi-Fi
      • Document Security
      • RMM Solutions
      • Cyber Assessment
    • Partners
    • News
      • Blog
      • Press Office
    • Support
    • About Us
    • Contact
    Dolos
    Contact us for more information