All videos
0:00 / 0:00
research

How AI hands hackers a skeleton key

Dr Waku16 June 2026Watch on YouTube

Description

AI has improved to the point where it is starting to be used by nation states in cyber attacks. In fact, Google reports that generative AI is being used across the full attack chain by state hackers in China, Russia, and Iran. This tilts the offense defense balance even more in favor of attackers, making widespread cyber attacks more likely. Counterintuitively, AI also creates vulnerabilities while accelerating developer workflows. It especially expands the attack surface when developers use agentic frameworks like OpenClaw. While it might seem possible to use AI to find vulnerabilities, it still takes time to deploy fixed code in the wild. We also have additional serious threat vectors such as nation states trying to steal each other's model weights. Even a model trying to escape human oversight might leverage cyber security as an attack factor in the future. #cyber #ai #nationstates Disrupting the first reported AI-orchestrated cyber espionage campaign https://www.anthropic.com/news/disrupting-AI-espionage Evaluating and mitigating the growing risk of LLM-discovered 0-days https://red.anthropic.com/2026/zero-days/ Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support https://thehackernews.com/2026/02/google-reports-state-backed-hackers.html GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use Oracle Error Leaves DeFi Lender Moonwell With $1.8 Million in Bad Debt https://finance.yahoo.com/news/oracle-error-leaves-defi-lender-082155372.html OpenAI Hires OpenClaw Creator Peter Steinberger And Sets Up Foundation https://www.forbes.com/sites/ronschmelzer/2026/02/16/openai-hires-openclaw-creator-peter-steinberger-and-sets-up-foundation/ 0:00 Intro 0:31 Contents 0:41 Part 1: How AI automates cyber attacks 0:52 Anthropic cyber espionage attack 1:48 How Anthropic detected this attack 2:17 The cybersecurity community was surprised 2:40 Google describes nation state use of AI 3:23 Models can still be jailbroken 3:56 AI is upsetting the offense/defense balance 4:22 Without AI: attacking easier but expensive 5:16 With AI: attacker has even bigger advantage 6:10 Consequences of increasing attack capabilities 6:59 Part 2: How AI creates vulnerabilities 7:10 Vibe coding has security flaws 7:40 Example: crypto company lost $1.8 million 8:32 Why Claude Code Security doesn't always help 8:57 How AI expands attack surfaces (OpenClaw) 9:12 How OpenClaw works 9:56 Security issues with OpenClaw 10:41 OpenClaw malicious plugins 11:40 AI is an unreliable security boundary 12:28 Part 3: Exploiting an insecure world 12:47 An attacker will always target the weakest point 13:21 Not all bugs are vulnerabilities 13:48 What an attacker will use AI for 14:31 Couldn't we use AI to find all the bugs? 15:31 Nation states want to carry out cyber attacks 15:53 Example: Colonial pipeline, etc 16:28 Nation states will try to steal model weights 17:10 Stealing model weights is like stealing crypto 17:34 Loss of control through cybersecurity 18:02 Example: loss of control through subgoal 18:54 Conclusion 19:27 AI is even creating new vulnerabilities 19:54 Dangerous for critical infrastructure 20:29 Outro

What you'll learn

  • AI is now used by state-backed hackers across entire attack chains, significantly shifting the balance between offense and defense in favor of attackers
  • AI-powered developer tools introduce new security vulnerabilities, particularly when frameworks like OpenClaw can execute autonomous actions
  • Agentic frameworks expand the attack surface by enabling external plugins and tools without adequate security oversight

Frequently asked questions

How do state-backed hackers use AI in cyber attacks?
Google reports that China, Russia, and Iran use generative AI across all phases of cyber attacks, from reconnaissance to execution. This automates and accelerates traditional attack chains significantly.
What security problems arise from developers using AI tools?
AI-powered code generators create security vulnerabilities through faster but less careful coding practices. Frameworks like OpenClaw increase risk by allowing external plugins without sufficient validation.
Why can't cyber attackers simply be stopped with AI?
Even when AI detects security issues, deploying fixed code to production takes time. Additionally, state actors can target critical infrastructure and steal model weights.
What are the consequences of shifting the offense-defense balance?
Greater advantage for attackers makes large-scale cyber attacks more likely, especially against critical infrastructure like power grids and financial systems.

Topics