Views Bangladesh Logo

Cyber attacks increasing under the guise of AI agents, Kaspersky warns

 VB  Desk

VB Desk

Kaspersky, the global cybersecurity firm, has warned that the rapid development of AI agents and the tendency to prioritise work speed and productivity are creating new types of cybersecurity risks. Cybercriminals are spreading harmful versions of these tools by exploiting users’ trust in legitimate AI tools.

According to data from Kaspersky’s Global Research and Analysis Team (GReAT), 92 thousand harmful attacks conducted under the guise of AI services have been detected in 2026. In these attacks, along with fake versions of ChatGPT, Claude and Gemini, more than 15 thousand malware samples under the guise of agentic AI software have also been detected.

Security researcher of Kaspersky’s GReAT Sojun Ryu said that AI technology has developed rapidly over the past few years. Initially AI was used for tasks such as content creation, summarisation and drafting, but gradually it has become directly involved in various stages of work. Now AI agents can plan themselves, use various tools, make API calls and complete tasks automatically.

He said that the role of humans is still important in verifying every stage of AI-dependent work. However, under the pressure of increasing productivity that verification is being neglected many times. As a result, when speed becomes more important than verification, cyber risks can also increase.

Ryu also warned about the growing risk of supply chain attacks on open source software alongside AI. In his view, cybercriminals can create opportunities to enter an organisation’s technology infrastructure by attacking trusted software components.

He said that open source is important for AI systems as well as for developers. And cybercriminals also know this. As a result, incidents of attacks on open source ecosystems such as NPM and PyPI are increasing. He informed that at least 10 major attack campaigns have been detected since the middle of last year.

Ryu further said that a survey conducted by Kaspersky last year found that 31 percent of enterprise organisations have been victims of supply chain attacks. This shows how important open source software has become in enterprise software development.

To tackle this risk Kaspersky has advised a secure development environment, strong Integrated Development Environment (IDE), permission control for AI agents, controlled system for software access and regular monitoring. Researchers of the organisation have also detected more than 250 thousand potential misconfigurations in CI/CD environments.

Ryu said that along with securing the software after it is created, the environment for creating the software also needs to be brought under security. If security can be ensured from the initial stage of the development process, organisations will be able to work while maintaining both security and speed.

Leave A Comment

Avatar

Trending Views