The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AI is helping attackers do familiar cyber work faster and at greater volume; the available evidence does not show that it has broadly created a new class of attacks. Google’s review of government-backed actors using Gemini found assistance with tasks across the attack lifecycle, but no indication that the activity it examined involved novel capabilities. That distinction matters: more efficient research, coding, and reconnaissance can raise the pressure on defenders even when the underlying methods are familiar.
What have threat actors been observed doing with AI?
Google Threat Intelligence Group’s January 29, 2025 report examined government-backed actors’ interactions with Gemini. It describes generative AI being used mainly for productivity and learning, rather than as evidence of a fundamentally new attack method. Google says its analysis involved analyst review and LLM-assisted analysis, and its findings should be read within that scope—not as a census of all threat actors, models, or cyber operations.
The report describes AI assistance with work at several stages, including:
- Researching targets and infrastructure, and conducting reconnaissance.
- Researching vulnerabilities and developing payloads.
- Writing scripts and other code.
- Seeking help with evasion.
These examples show assistance with parts of an operation, not autonomous end-to-end compromise. Google’s summary is that “Rather than enabling disruptive change, generative AI allows threat actors to move faster and at higher volume.” That is the report’s characterization of the observed activity, not a measured result that applies equally to every actor.
#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Does AI make attackers more capable, or just faster?
It can help with both productivity and learning, but the evidence here supports a careful distinction. Google describes skilled actors using AI as a framework to make work more efficient, while less skilled actors may use it to learn and develop tools faster. This is the report’s assessment of possible benefits across skill levels, not a universal or quantified effect.
In either case, lowering the effort needed for routine tasks can matter. Faster target research, code drafting, or troubleshooting may let an actor spend less time on individual tasks or repeat them at greater volume. The reviewed sources do not establish a general figure for how much AI shortens an attack timeline or raises an attack’s chance of success.
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
What is observed, and what is still a projection?
It is important not to confuse AI-assisted work with an AI system independently carrying out an intrusion. Google reports observed assistance in Gemini interactions. Microsoft’s Digital Defense Report 2025 discusses a further possibility: AI agents could automate reconnaissance, vulnerability scanning, and exploitation at scale, potentially across an entire attack lifecycle. That is a projection of capability, not proof that autonomous, end-to-end attacks are already routine.
| Claim | What the cited report supports | How to interpret it |
|---|---|---|
| AI assists with attack-stage tasks | Google GTIG describes government-backed actors using Gemini for research, reconnaissance, vulnerability research, payload development, scripting, and evasion support. | Observed assistance within the report’s scope; not evidence of autonomous compromise. |
| AI agents could automate more of an attack | Microsoft’s 2025 report describes automation of reconnaissance, vulnerability scanning, and exploitation at scale as a potential. | A projected capability, not an established account of universal or routine end-to-end automation. |
| AI also has defensive uses | Microsoft describes using AI to analyze threat intelligence, identify protection gaps, and automate responses. | Defensive capabilities that still require governance and validation; the report does not establish that defenders always gain more than attackers. |
How does AI change the defender’s problem?
AI is a tool and a risk at the same time. Microsoft puts it this way in its Digital Defense Report 2025: “Both adversaries and defenders are using AI to make their operations more effective and efficient, rendering the technology a cybersecurity risk and tool at once.” Organizations can apply AI to threat analysis, gap identification, and response automation, while attackers can use it to accelerate familiar work. Microsoft also identifies insecure AI workloads as targets and synthetic media as a means of fraud.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Generated text, images, audio, and video can also appear in influence operations. Those activities are not automatically cyber intrusions: Microsoft’s 2024 report discusses nation-state influence operations alongside cyber risks, and the two should not be conflated.
Why do ordinary security controls still matter?
AI does not remove the need to secure the paths attackers can use to reach valuable systems. Microsoft’s 2024 Digital Defense Report describes attack-path analysis as combining asset inventories, vulnerability data, and external attack surfaces to map possible chains to critical assets. The report’s June 2024 infographic presents these figures from Microsoft Security Exposure Management’s 2024 analysis:
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
| Finding | Microsoft’s reported figure |
|---|---|
| Organizations exposed to at least one attack path | 90% |
| Attack paths leading to a sensitive user account | 61% |
| Organizations with attack paths exposing critical assets | 80% |
| Attack paths including lateral movement based on non-interactive remote code execution | 40% |
| Attack paths containing three steps or fewer | 10% |
| Organizations exposed to more than 1,000 attack paths | 3% |
These are figures from Microsoft’s analysis, not universal rates for all organizations. Their practical implication is that an attacker may not need a novel technique if an existing chain of weaknesses already reaches a sensitive account or critical asset.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11What should organizations do about AI-enabled threats?
Prioritize controls that reduce the opportunity for familiar attack methods to succeed, then govern any AI used in defense so it does not create new blind spots.
- Map routes to critical assets. Use current asset inventories, vulnerability information, and external attack-surface data to identify likely attack paths and prioritize the ones that reach sensitive accounts or critical systems.
- Fix the weaknesses on those paths. Address technical debt, outdated controls, and vulnerabilities that enable access or movement between systems. Review shadow IT so untracked services do not leave gaps in the inventory or defenses.
- Review data-security policies. Make sure policies and safeguards account for how organizational data is handled, including in AI workloads, and assess whether those workloads are securely configured.
- Use defensive AI with oversight. AI can support threat-intelligence analysis, protection-gap identification, and response automation, but organizations should validate outputs and govern how automated actions are approved and applied.
The evidence points to a constraint-removal effect, not a wholesale reinvention of cyberattacks: AI can help people perform familiar tasks more quickly, at greater volume, or with less experience. That makes attack-path reduction and sound security hygiene more—not less—important.
Quick Recap
Sources
- Google Threat Intelligence Group, “Adversarial Misuse of Generative AI”, January 29, 2025.
- Microsoft, Digital Defense Report 2025.
- Microsoft, Digital Defense Report 2024.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

