Barracuda VP Adam Khan on How Cybercriminals Are Using AI to Launch Attacks
Adam Khan, vice president of global security operations for Barracuda Networks, dives into the degree to which cybercriminals are now using artificial intelligence (AI) technologies to launch cyberattacks.
Transcript
Hey guys, thanks for the throw. We're here with Adam Kahn, who's global vice President for Security Operations for Barracuda Networks, and we're talking about AI threats. I think theoretically, at least we've all understood that the bad guys might be using AI one day to attack us, but I think it's starting to actually happen.
Adam, am I right? What's going on? Hi, Mike.
Thank you for having me. Uh, yeah, it's really interesting what we're seeing, uh, cyber criminals are leveraging l lms, um, to, uh, conduct cyber attacks. So they're using LLMs such as evil, GBT, Wolf, GBT, warm, GBT, dark part, and a few others.
And they're executing this at a much faster rate that we are seeing this in in our, in our intel. And, um, the threats that we're observing across various organizations, Are the threats more lethal or are they more sophisticated? How is that changing?
Great question. So they're being designed by a lot of these, um, AI tools that are, have no boundaries or governance, right? Um, so what their attackers are doing is leveraging these tools to create malicious code or create a brand new malware that we've never seen before.
Uh, even cryptographic malware that embeds in a, in a device and just minds, um, cryptocurrencies, things like that. We've seen an increase of about 219% alone just in 2024, uh, going into 2025. And, uh, this is, uh, being subscribed by thousands of cyber criminals, uh, globally.
Can we as humans on the defender side keep pace with that? Or is this kind of gonna devolve into something that feels like an AI arms race and it'll be our AI versus their ai? I, I, I do believe it's leading to that, you know, effect where, um, a lot of companies are coming out with the, OR have already, um, really good tools, uh, security tools in place that can leverage AI's capabilities, just like how the cyber criminals are to be able to detect these, uh, types of, uh, whether they're, uh, phishing emails that are being constructed by AI or whether there's some AI images that are being embedded within, um, emails or chatbots or different types of bots that are scraping, uh, various websites.
So to be able to filter out for those and defend against AI attacks, um, that is being, um, currently happening across various products, um, that security companies have. So do you think that it will become more stressful for cybersecurity professionals as they kind of deal with all the attacks that are AI fueled? Or might it become less stressful because well now they're fighting back with more AI tools and they're able to swat a lot more of these attacks even though there's more of 'em?
Uh, yeah, it's another great question. So I think it's, uh, I don't know, I think there's, in cybersecurity is definitely, um, uh, being in the field is definitely challenging and exciting at the same time. Um, and, um, it's how we're leveraging as defenders and enabling us to scale a lot faster than we're able to do before.
So for example, you know, we all know about the talent shortage in security, but AI has given us also a really good, um, um, tool in our arsenal to be able to withstand these types of attacks and the scale these attacks are happening. So to, to a certain extent, yes, it's a new way of, uh, of, of thinking and the new way of adopting to a new type of threats that we're seeing. Um, but we, we as defenders also are armed with, with our tool sets to be able to work this.
Do you think also because of AI tools that maybe we're about to discover that there are a lot more attacks than we ever imagined? I mean, that might be a little depressing to think about, but, um, you know, it's kinda like drug interdiction, you know, for every one boat that we intercept, there's 10 others we never saw. Is that kind of where we're on the cusp of?
Yeah, so you, you're seeing that across, especially when it comes to these, uh, chat bots that are scraping a lot of the legitimate websites that are out there. So they're, and these are AI chat bots that we've never seen in the past. They are trying to, um, scrape information from legitimate websites, um, grab, uh, content from those, those sites that are available, and also try trying to basically, um, bring down some of the infrastructure, uh, if that's possible.
So these bots are going out, um, causing DDoS attacks, causing infiltration of the systems and ultimately causing companies to at higher costs because they're, they're in the cloud and as many requests as they're getting on these devices, they're, they're getting hit by the high cost as well. So that's, that is definitely the case. We're seeing new tactics, we're seeing in new types of malware, defensive EVA tactics that, uh, cyber criminals are using, uh, with ai.
Um, so it's, it is definitely a new realm. And, um, you know, the defenders, I feel, uh, or or companies who are doing leveraging AI are, are at the forefront of this. We used to focus a lot in trying to disrupt the economics of the attackers, but it seems as I look at ai, maybe the cost of creating and launching an attack is dropping to zero.
So how do you disrupt an economic model where there's almost no cost to creating and launching the attack? Yeah, I think, uh, from the perspective of, you know, disrupting economics for any cyber crime or criminal organization, it's, it's become, the barrier of entry is so low, you can't, uh, just go after an organization and take them down, and then there'll be another one that gets stood up, right? And we've seen this in the past as well.
I think it's, it is just about understanding that these things are going to happen, right? It's how we respond and how quickly we could respond, and how quickly we could detect and, uh, mitigate these issues, um, rather than, you know, hey, if I'm gonna take down this organization or this, uh, criminal activity that is happening is going to be the end of it all. And it's, I don't think that's the case.
I think it's about, um, having the right tool sets, having the right team in, in, in place to be able to thwart this. So I think that's, that's where we're heading towards How will the defenders get access to ai? And I'm asking the question because am I gonna have to go out and fund the acquisition of an entirely new set of platforms, which is never a popular thing to do, or are these just gonna be added features to my existing platforms over time and we'll just all, you know, get AI as part of a normal upgrade cycle?
Yeah, I think, I think the latter. I think a lot of the security companies are already implementing or have already there, um, AI capabilities, whether you are analyzing an incident, uh, from, from start to finish, um, from like what happened, how did this attack gets executed, uh, what type of, um, malware or hosts were affected, or users were affected, all this information before, as humans were doing and looking at different data points, AI is able to gather all that information and present it to the security teams much faster. So the tools have this capabilities, um, built in, uh, whether it's from the analysis side or threat hunting side or mitigation response side, um, you are just gonna get these updates as, as we go along.
That's, I think that's you, you're right on the mark with, with that assessment. A friend of mine once described the work in cybersecurity as kinda like being in the army, long periods of boredom, punctuated by a few moments of sheer terror. Um, can we reduce the boredom of cybersecurity, which is a lot of the hunting for the proverbial, uh, needle in the haystack and sorting through the data and creating all the reports and that part of the job is maybe less fun.
Yeah, I mean, that's exactly going back to the AI topic. AI is helping us get, you know, through the mono monotonous tasks that, uh, cyber security analysts do. Um, but at the same time, I think the boredom cycle is becoming less and less.
Um, there's more interesting things, interesting attacks and tactics that are being used, um, to, to leverage you. You see this, uh, amazing uptake in like deepfake attacks that are happening as well, which are also leveraging a lot of the AI capabilities. So there's always something new happening in cybersecurity and, and attackers are being at the forefront, uh, and pushing the, a lot of the boundaries and, and, um, security teams, I think in today's day, day and age, compared to like, if you look maybe five or 10 years back, uh, the men, you know, the, the day-to-day routine tasks are kind of getting, uh, you know, outdated and, and not being done anymore where AI is kind of filling those gaps.
Will this ultimately maybe, uh, reduce the chronic skills shortage crisis that we've been dealing with for the past decade or more, or, um, is there still always gonna be a shortage, but maybe it might not be as acute? I, I definitely believe this will, uh, help against that, uh, cyber talent, uh, shortage, definitely. 'cause you know, a lot of the activities that were done by level one or say level two cybersecurity analysts, um, now you could definitely leverage AI to do that from threat intel research, from a analyzing a malware or, you know, uh, kind of describing what is happening in an actual incident from, from the attack, um, tactics type all the way to, you know, what steps that need to be taken when you, or whether you're triaging or how you need to respond to a certain alert.
So those initial level one, level two, uh, items that cybersecurity analysts and others were doing in the past are, can be definitely addressed by, uh, ai. So I think that will help bring the, the cybersecurity talent shortage, um, uh, to a better state. Mm-hmm.
Ultimately, what's your best advice then to your fellow cybersecurity professionals about how to make a case for using AI or bringing AI in the, into an organization? I think a lot of them are a little wary of being perceived as the boy or girl who cries wolf all the time. So how do you kind of get in there and kind of say, folks, we need this and here's what the costs look like, but here's the benefits and have that kind of what we might call an adult conversation?
Yeah, so I think both, uh, you know, organizations and individuals, so from organization's perspective, you know, you, you need to start utilizing security tools that have AI built in, uh, to, to your, to their, to their tech tech stack. Um, 'cause it's imperative to prevent, uh, and detect these, uh, AI attacks that we're seeing. At the same time, security teams need to start leveraging and understanding and learning these tools and understanding how, you know, tools like Bard, which act, uh, dark bard, how it's used and how it goes out to the internet and, and scours information to, uh, actually write malicious code based on the latest news and information that is out there.
And understanding and educating yourself utilizing how to use, uh, ai, what are the right prompts that I need to inject, uh, to be able to detect certain types of attacks. Um, you know, what are the different, um, thresholds that we need to put in to, uh, eliminate the hallucinations that happen with AI as well when we are talking about better efficacies, um, better true positive rates and things like that. So both, uh, on the organization side and, and the security team side, those are the two things I would, um, leverage.
Um, one of the other things I don't think we talk enough about is, um, folks are using AI to create more software than ever. So the overall size of the attack surface is increasing. A lot of the code that's being generated by these AI tools contains more vulnerabilities than ever.
And so, um, do you think cybersecurity people are prepared for this next wave of things that they're supposed to defend, whether, it seems to me exponentially increasing in ways where they're from a security perspective weaker than ever? Yeah, that's a, another great question. I think like you have the, uh, you know, the latest models that are coming out, uh, the recent one that was released, uh, GBT five is super impressive, right?
It could create a whole webpage right, from certain prompts you're giving, and it's designs a really modern UI that, that would take months to develop, right? Um, so I think the, the pace that we're going at is definitely, um, at a exponential scale, but cybersecurity professionals also utilizing that same technology, um, and keeping up and, and with these adversities or these attackers that are leveraging these tactics and techniques to, to, you know, automatically respond to threats within seconds or within, uh, you know, minutes. So the, the dwell time that we used to think about, oh, what, you know, a hundred and, sorry, this is like something around 200 and something days, 277 days before and incident happens, uh, and you actually recognize, uh, attackers in the environment, um, to now within seconds we could analyze it, uh, detect it and mitigate it, um, utilizing AI and automation that's in place.
So we, we, we are definitely keeping up and, um, you know, we're, we're on the right track. All right, well folks, you heard it here. It's true.
AI is one of those proverbial swords that cuts both ways. The only thing you don't wanna be is the one person in the room and doesn't have a sword. Hey, Adam, thanks for being on the show.
That's well put, Mike. Thank you for having me. All right.
And back to you guys in the studio.