{"id":649668,"date":"2025-12-23T04:31:14","date_gmt":"2025-12-23T04:31:14","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/649668\/"},"modified":"2025-12-23T04:31:14","modified_gmt":"2025-12-23T04:31:14","slug":"the-wannacry-of-ai-will-happen-the-register","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/649668\/","title":{"rendered":"&#8216;The WannaCry of AI will happen&#8217; \u2022 The Register"},"content":{"rendered":"<p>Interview &#8220;In my past life, it would take us 360 days to develop an amazing zero day,&#8221; Zafran Security CEO Sanaz Yashar said.<\/p>\n<p>She&#8217;s talking about the 15 years she spent working as a spy &#8211; she prefers &#8220;hacking architect&#8221; &#8211; inside the Israel Defense Forces&#8217; elite cyber group, Unit 8200.\u00a0<\/p>\n<p>&#8220;Now, the volume and speed is changing so much that for the first time ever, we have a negative time-to-exploit, meaning it takes less than a day to see vulnerabilities being exploited, being weaponized before they were patched,&#8221; Yashar told The Register. &#8220;That is not something you used to see.&#8221;<\/p>\n<p>The reason: AI. This technology isn&#8217;t helping criminals develop novel or more sophisticated attack chains entirely without humans in the loop, she said. &#8220;But AI is helping the threat actors do more, and faster,&#8221; according to Yashar &#8211; and the more and faster is what worries her.<\/p>\n<p>As a teen, Yashar&#8217;s family moved from Tehran to Israel, and the Israeli military intelligence corps recruited her while she was working as a research assistant at Tel Aviv University.\u00a0<\/p>\n<p>In 2022, Yashar co-founded Zafran, which uses AI to help companies map and manage their cyber-threat exposure. But before heading up her own security startup, she led threat intelligence at Cybereason and worked as a manager at Google&#8217;s incident response and threat intel biz, Mandiant.<\/p>\n<blockquote class=\"pullquote\">\n<p>AI is helping the threat actors do more, and faster<\/p>\n<\/blockquote>\n<p>She&#8217;s citing <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7376823949587906561\/\">Mandiant&#8217;s recent analysis<\/a> that found the average time-to-exploit (TTE) in 2024 hit -1. This is how Google and Mandiant define the average number of days it takes attackers to exploit a bug before or after the vendor issues a patch, and this is the first time ever the security analysts have seen a negative TTE.\u00a0Crims are getting to exploit bugs a day before they&#8217;re patched now.<\/p>\n<p>&#8220;And we saw 78 percent of the vulnerabilities being weaponized by LLMs and AI,&#8221; Yashar said.<\/p>\n<p>In addition to attackers using AI to improve the speed and efficiency of breaches, organizations&#8217; increasing use of this same technology &#8211; in some cases, just stuffing AI into every product and process &#8211; expands the attack surface.\u00a0<\/p>\n<p>This includes attackers misusing corporate AI systems through things like <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/10\/28\/ai_browsers_prompt_injection\/\" rel=\"noopener\">prompt injection<\/a> and tricking AI agents into <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/11\/14\/ai_guardrails_prompt_injections_echogram_tokens\/\" rel=\"noopener\">bypassing safety guardrails<\/a> to <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/11\/13\/chinese_spies_claude_attacks\/\" rel=\"noopener\">develop exploit chains<\/a>, or <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/09\/26\/salesforce_agentforce_forceleak_attack\/\" rel=\"noopener\">access data<\/a> they&#8217;re not supposed to.\u00a0<\/p>\n<p>Plus, there&#8217;s also software vulnerabilities within the AI systems and frameworks themselves, and Yashar worries about the &#8220;collateral damage&#8221; caused from exploiting these bugs, especially if they fall into the hands of &#8220;junior&#8221; hackers: the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/10\/13\/scattered_lapsus_hunters_hiatus\/\" rel=\"noopener\">Scattered Spider<\/a>, <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/11\/21\/shinyhunters_salesforce_gainsight_breach\/\" rel=\"noopener\">ShinyHunters-type<\/a> <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/08\/12\/scattered_spidershinyhunterslapsus_cybercrime_collab\/\" rel=\"noopener\">cybercrime collectives<\/a> or governments just beginning to develop or buy a cyber-weapons arsenal or experimenting with agentic AI.<\/p>\n<p>&#8220;Sometimes the ones that don&#8217;t understand what they are doing are more dangerous than Russia, Iran, Israel, US, China &#8211; they understand what can happen if something goes wrong,&#8221; she explained. &#8220;Even if they do bad things, there is a decision they understand.&#8221;<\/p>\n<p>&#8220;The new threat actors are going to utilize these vulnerabilities, not understanding that they can shut down half of the world,&#8221; Yashar said. &#8220;And the collateral damage is going to be something that we cannot expect and we cannot deal with. I do think the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2017\/05\/13\/wannacrypt_ransomware_worm\/\" rel=\"noopener\">WannaCry<\/a> of AI has not yet happened. It&#8217;s going to happen. I don&#8217;t know where it&#8217;s going to come from, but it&#8217;s going to happen. The question is, how are you going to mitigate &#8211; because you cannot remediate it &#8211; so how you&#8217;re going to mitigate your own risk?&#8221;<\/p>\n<p>WannaCry, which took place in May 2017, was one of the largest worldwide ransomware attacks, hitting hundreds of thousands of computers and causing untold damage that&#8217;s estimated to be in the hundreds of millions or billions.<\/p>\n<p>The answer, according to Yashar, is also AI. Not coincidentally, Zafran has developed a threat-exposure management platform that uses AI to find and remediate exploitable vulnerabilities and perform proactive threat hunting.<\/p>\n<p>&#8220;The way we do security is going to completely change,&#8221; she said. &#8220;Companies that just show you insight wouldn&#8217;t be enough. They have to get the job done. And to get the job done, you need to use agents, even with human intel.&#8221;<\/p>\n<p>AI agents will investigate and triage threats, and develop an action plan for an organization to mitigate them. &#8220;The AI is going to build those packages according to your risk appetite, and there&#8217;s going to be a human to make sure that you want to do this action according to your risk appetite,&#8221; Yashar said.<\/p>\n<p>Humans, she adds, will remain in the loop for the foreseeable future because &#8220;human behaviour changes slower than technology,&#8221; and when it comes to completely turning over the reins to AI agents, we&#8217;re not there yet. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Interview &#8220;In my past life, it would take us 360 days to develop an amazing zero day,&#8221; Zafran&hellip;\n","protected":false},"author":2,"featured_media":649669,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3163],"tags":[323,1942,53,16,15],"class_list":{"0":"post-649668","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-technology","11":"tag-uk","12":"tag-united-kingdom"},"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/649668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=649668"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/649668\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/649669"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=649668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=649668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=649668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}