Police in South Korea launched a major probe after hackers, possibly using an AI attack tool, broke into seven lenders and exposed data on 66,000 people.
1.4.A.6Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.Learning objective: Explain how adversaries use AI-powered tools to augment cyberattacks.
1.5.B.4AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.Learning objective: Explain how AI-powered tools are enabling faster and more accurate threat detection and response.
2.1.C.6In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.Learning objective: Describe the phases of a cyberattack.
AP Networking alignment
4.1.A.3When confidentiality is compromised, systems are vulnerable to having sensitive data exposed or stolen. A breach of confidentiality can be identified by: • unauthorized access • network traffic showing exfiltration of…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.
4.5.B.4Security controls to limit the impact of unauthorized access include: • enforcing strong password policies and account lockout settings • applying the principle of least privilege • implementing segmentation to restrict access…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a managed network.
4.5.C.3IDS and IPS logs and alerts can be reviewed for indicators of security threats that suggest potential unauthorized access or malicious activity. These can include: • repeated failed login attempts • access attempts outside of…Learning objective: Identify indicators in intrusion detection system (IDS) or intrusion prevention system (IPS) logs that may suggest potential threats or network issues.