Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI models to generate exploit code and scan networks, according to Taiwanese cybersecurity firm TeamT5.
The sharp increase in attack frequency correlates directly with hackers' use of AI tools including DeepSeek, ChatGPT, and Anthropic's Claude Code. These models enable threat actors to automate code generation and network reconnaissance at scale, dramatically expanding their offensive capabilities.
TeamT5's findings align with recent research from the UK, which demonstrates that open-source AI models are rapidly closing the gap in cyber capabilities. The convergence of accessible AI technology and organized state-backed hacking infrastructure creates a significantly more dangerous threat landscape.
The use of AI in cyberattacks streamlines multiple phases of the kill chain. Hackers leverage language models to write functional exploit code without extensive manual development, accelerate vulnerability scanning across target networks, and potentially craft more convincing social engineering campaigns.
DeepSeek, a Chinese AI model that gained prominence for its cost-effective performance, has emerged as a preferred tool among threat actors. However, Western models like ChatGPT and Claude are equally valuable to attackers, suggesting that the problem transcends any single AI platform.
The doubling of attack volume raises immediate concerns for organizations across critical infrastructure, government, and private sectors. State-backed groups typically target high-value entities for espionage, intellectual property theft, and strategic advantage.
This development underscores a critical security challenge: the democratization of AI technology simultaneously empowers defenders and attackers. While organizations can leverage AI for threat detection and incident response, adversaries gain equivalent or superior offensive capabilities with fewer resource constraints.
Security experts warn that traditional defense models built around slower attack cycles may prove insufficient. Organizations must accelerate threat detection capabilities and assume higher baseline attack volumes from sophisticated state actors.
The findings also highlight the dual-use nature of AI development. As models become more capable at code generation and technical analysis, their offensive applications multiply alongside legitimate security research uses.
Top Chinese military strategists have published analyses detailing artificial intelligence's role in accelerating command decision-making. The writings offer insight into Beijing's military modernization efforts.
AliExpress deployed an outdated browser fingerprinting technique using ultrasonic frequencies to identify and track users. Security researchers discovered the e-commerce platform embedding inaudible sounds in web pages to create unique device signatures.
An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.
Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.