Why we keep replaying the classics

Timely updates, strong unique passwords and multifactor authentication remain our most effective, everyday cyber defences, even when facing up to emerging AI-driven threats.

A photo of an old retro computer with a game of snake on screen

AI is changing almost every aspect of our lives, but did you know it’s also affecting the way cyber attacks could be carried out?

Researchers at the University of Toronto recently demonstrated a proof-of-concept AI-powered computer worm that could identify weaknesses, adapt its approach, and spread across a test network. It did this without human guidance, and over seven days it compromised nearly three-quarters of the network it was targeting.

The worm wasn't relying on any futuristic AI magic either, instead It was taking advantage of familiar problems that people and organisations have been dealing with for years: outdated software, weak passwords and misconfigurations on the back end.

A computer worm is a type of malicious software that spreads from one device to another by exploiting specific security weaknesses. This new AI-driven wriggly menace was able to adapt itself and look for different weaknesses as it moved through the test network.

The thought of a self-evolving worm might sound terrifying, but the research highlights once again why we in the Cybersecurity team keep repeating the same key messages.

The basics still work

  • One of the most effective things you can do is keep your software updated. Attackers love searching for any outdated software or devices that may have security weaknesses they can take advantage of. The longer you delay an update, the more time it gives cyber criminals to find a way to exploit it.
  • Strong, unique passwords are just as important. Reusing passwords means that if one account is compromised, others may be at risk too. Keep it complex, keep it unique, and where available, enable multifactor authentication (MFA) for an additional layer of protection.

While there’s plenty cybersecurity teams can do behind the scenes to keep things safe and locked down, software updates, strong passwords and MFA remain some of the simplest and most effective ways we can all do our part.

As AI continues to evolve and new threats emerge, it's easy to assume we need completely new solutions. But research like this is a reminder that good cybersecurity habits are still some of our strongest defences. As Professor Nicolas Papernot from the University of Toronto puts it:

"We can all do our part by removing as many digital vulnerabilities as possible. To start, no more delaying software updates, no more reusing easy passwords, and we need to use multifactor authentication as much as possible."