Microsoft says US rivals are beginning to use generative AI in offensive cyber operations

Advertisement

Advertise with us

BOSTON (AP) — Microsoft said Wednesday that U.S. adversaries — chiefly Iran and North Korea and to a lesser extent Russia and China — are beginning to use generative artificial intelligence to mount or organize offensive cyber operations.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 14/02/2024 (931 days ago), so information in it may no longer be current.

BOSTON (AP) — Microsoft said Wednesday that U.S. adversaries — chiefly Iran and North Korea and to a lesser extent Russia and China — are beginning to use generative artificial intelligence to mount or organize offensive cyber operations.

The technology giant said it detected and disrupted, in collaboration with business partner OpenAI, threats that used or attempted to exploit AI technology they had developed.

In a blog post, the Redmond, Washington, company said the techniques were “early-stage” and neither “particularly novel or unique” but that it was important to expose them publicly as U.S. rivals leverage large-language models to expand their ability to breach networks and conduct influence operations.

FILE - A logo of Microsoft is displayed during an event at the Chatham House think tank in London, Jan. 15, 2024. Microsoft said Wednesday that U.S. adversaries are beginning to use generative artificial intelligence to mount or organize offensive cyber operations. (AP Photo/Kin Cheung, File)
FILE - A logo of Microsoft is displayed during an event at the Chatham House think tank in London, Jan. 15, 2024. Microsoft said Wednesday that U.S. adversaries are beginning to use generative artificial intelligence to mount or organize offensive cyber operations. (AP Photo/Kin Cheung, File)

Cybersecurity firms have long used machine-learning on defense, principally to detect anomalous behavior in networks. But criminals and offensive hackers use it as well, and the introduction of large-language models led by OpenAI’s ChatGPT upped that game of cat-and-mouse.

Microsoft has invested billions of dollars in OpenAI, and Wednesday’s announcement coincided with its release of a report noting that generative AI is expected to enhance malicious social engineering, leading to more sophisticated deepfakes and voice cloning . A threat to democracy in a year where over 50 countries will conduct elections, magnifying disinformation and already occurring,

Here are some examples Microsoft provided. In each case it said all generative AI accounts and assets of the named groups were disabled:

— The North Korean cyberespionage group known as Kimsuky has used the models to research foreign think tanks that study the country, and to generate content likely to be used in spear-phishing hacking campaigns.

— Iran’s Revolutionary Guard has used large-language models to assist in social engineering, in troubleshooting software errors, and even in studying how intruders might evade detection in a compromised network. That includes generating phishing emails “including one pretending to come from an international development agency and another attempting to lure prominent feminists to an attacker-built website on feminism.” The AI helps accelerate and boost the email production.

— The Russian GRU military intelligence unit known as Fancy Bear has used the models to research satellite and radar technologies that may relate to the war in Ukraine.

— The Chinese cyberespionage group known as Aquatic Panda — which targets a broad range of industries, higher education and governments from France to Malaysia — has interacted with the models “in ways that suggest a limited exploration of how LLMs can augment their technical operations.”

— The Chinese group Maverick Panda, which has targeted U.S. defense contractors among other sectors for more than a decade, had interactions with large-language models suggesting it was evaluating their effectiveness as a source of information “on potentially sensitive topics, high profile individuals, regional geopolitics, US influence, and internal affairs.”

In a separate blog published Wednesday, OpenAI said its current GPT-4 model chatbot offers “only limited, incremental capabilities for malicious cybersecurity tasks beyond what is already achievable with publicly available, non-AI powered tools.”

Cybersecurity researchers expect that to change.

Last April, the director of the U.S. Cybersecurity and Infrastructure Security Agency, Jen Easterly, told Congress that “there are two epoch-defining threats and challenges. One is China, and the other is artificial intelligence.”

Easterly said at the time that the U.S. needs to ensure AI is built with security in mind.

Critics of the public release of ChatGPT in November 2022 — and subsequent releases by competitors including Google and Meta — contend it was irresponsibly hasty, considering security was largely an afterthought in their development.

“Of course bad actors are using large-language models — that decision was made when Pandora’s Box was opened,” said Amit Yoran, CEO of the cybersecurity firm Tenable.

Some cybersecurity professionals complain about Microsoft’s creation and hawking of tools to address vulnerabilities in large-language models when it might more responsibly focus on making them more secure.

“Why not create more secure black-box LLM foundation models instead of selling defensive tools for a problem they are helping to create?” asked Gary McGraw, a computer security veteran and co-founder of the Berryville Institute of Machine Learning.

NYU professor and former AT&T Chief Security Officer Edward Amoroso said that while the use of AI and large-language models may not pose an immediately obvious threat, they “will eventually become one of the most powerful weapons in every nation-state military’s offense.”

Report Error Submit a Tip

More Stories

Foreign workers at Manitoba hotel are owed $138K in unpaid wages and fees, labour board rules

Abiola Odutola 4 minute read Preview

Foreign workers at Manitoba hotel are owed $138K in unpaid wages and fees, labour board rules

Abiola Odutola 4 minute read Sunday, Aug. 30, 2026

BRANDON — The Manitoba Labour Board has ordered the Western Star All Suites Hotel to pay nearly $138,000 in unpaid wages and administrative fees after it dismissed the appeals involving three foreign workers employed by the company.

In a decision dated Aug. 25, the board ordered 6692452 Manitoba Ltd. (doing business as Western Star All Suites Hotel), 1638185 Alberta Ltd. and company director P.X. to pay a total of $137,915.79 to the Employment Standards Branch for wages owed to foreign workers S.J., J.B. and G.R.

The decision was edited to protect the personal information of the employees, who worked at a hotel, reportedly in Melita, at different times and also lived there during their employment.

The board stated the employees were owed wages after hearing evidence about long working hours, irregular payments, inadequate employment records and working conditions.

Read
Sunday, Aug. 30, 2026

Puzzles Palace

1 minute read Monday, Jul. 27, 2026

To solve our puzzles, please subscribe with this special offer: |

Today’s horoscope

Georgia Nicols 4 minute read Preview

Today’s horoscope

Georgia Nicols 4 minute read 2:00 AM CDT

MOON ALERT: Caution! After 5:15 a.m. today, avoid shopping (except food and gas) and important decisions for the rest of the day. The moon is in Taurus.

ARIES (March 21-April 19)

You might have excellent ideas about your work, job and health. Quite likely, they’ll relate to your finances. You might need to know how much money you need ahead of time? Or you might check out the cost of making home improvements.

TAURUS (April 20-May 20)

Read
2:00 AM CDT

Chefs gather in St. Boniface to see whose version of jollof is best

Eva Wasney 4 minute read Preview

Chefs gather in St. Boniface to see whose version of jollof is best

Eva Wasney 4 minute read Yesterday at 5:30 PM CDT

Chef Alex Bockarie is bringing an age-old African culinary battle to Winnipeg.

On Saturday, five local chefs hailing from Senegal, Liberia, Sierra Leone, Ghana and Nigeria will go head-to-head to determine who makes the best jollof — a rice dish simmered in a savoury tomato-based stew.

“Jollof rice originated from Senegal but it has spread throughout West Africa and every country has its own method of cooking it,” Bockarie says. “It’s a long-standing fight; even among the communities here in Winnipeg, everybody’s always saying that Sierra Leone’s (jollof) is the best, Ghana’s is the best, Nigeria’s is the best.

“It’s a friendly competition; friendly, but very serious too.”

Read
Yesterday at 5:30 PM CDT

Dangerous offender status sought for convicted killer

Erik Pindera 5 minute read Preview

Dangerous offender status sought for convicted killer

Erik Pindera 5 minute read Yesterday at 2:00 AM CDT

Crown prosecutors intend to apply to have a convicted killer, who also admitted his guilt in an assault on a stranger at The Forks and a robbery at a local beer vendor, designated as a dangerous offender.

Daniel Christopher Dumas, who is in his mid-30s, pleaded guilty to assault causing bodily harm and robbery in front of provincial court Judge Donovan Dvorak on Monday for the attacks on June 6 and 7, 2025. He will be sentenced at a later date.

Prosecutor Monique Cam said the Crown plans to apply for a dangerous offender designation for Dumas, which, if granted, could result in him being given an indefinite prison sentence.

“The Crown does intend to make an application at a future date … for a remand for assessment to have Mr. Dumas assessed by a court-ordered assessor for the purpose of pursuing a dangerous offender application,” Cam said.

Read
Yesterday at 2:00 AM CDT

Man who killed truck passenger handed new 12-year sentence

Erik Pindera 4 minute read Preview

Man who killed truck passenger handed new 12-year sentence

Erik Pindera 4 minute read 2:00 AM CDT

Manitoba’s highest court has given a man who shot at a passing truck and killed a 20-year-old woman a 12-year prison sentence for manslaughter.

William Ryerson Thomas Comber, now in his mid 20s, was found guilty of second-degree murder by a jury in December 2022 for the killing of Hailey Dugay on Nov. 17, 2018. Comber was later sentenced to life in prison with no chance of parole for 12 years.

Dugay died after the truck she was travelling in was struck by gunfire late at night on a gravel road near Fraserwood, 90 kilometres north of Winnipeg.

The Court of Appeal struck down Comber’s murder conviction earlier this year and ruled he was instead guilty of the lesser offence of manslaughter.

Read
2:00 AM CDT