Breaking
April 18, 2025

Why defensive AI alone is not enough: the crucial role of a strong security culture | usagoldmines.com

Before the rise of AI-driven cyber threats, phishing attempts were often easy to spot. Poor grammar, overly manipulative language, and unsolicited requests were telltale signs of malicious attacks.

With the implementation of offensive AI used by threat actors, these phishing attempts have become harder to identify. While Secure Email Gateways (SEGs) have also implemented defensive AI to combat these threats, these emails are still reaching users’ inboxes.

The AI email security gap

AI and Machine Learning (ML) models in SEGs are primarily trained on historical data, enabling them to recognize phishing patterns. While this retrospective approach is effective for identifying known threats, it struggles to keep pace with rapidly evolving attack techniques. Offensive AI enables threat actors to generate highly professional, industry-specific phishing emails using minimal effort or time investment. These attacks can mimic the jargon and technical terms of targeted sectors, making malicious emails appear legitimate, and allowing them to bypass SEGs.

Despite embracing AI capabilities with open arms, SEGs are still struggling to keep up with these sophisticated phishing attempts. While AI can efficiently identify repetitive patterns and filter out bulk threats, it remains reactive. This gap between offensive and defensive AI leaves organizations vulnerable to novel phishing techniques.

How attackers bypass SEGs

Cybercriminals continuously develop new methods to circumvent SEGs, often manipulating legitimate services or introducing novel techniques that AI models have yet to encounter. Some of the most effective tactics include:

QR codes: Embedding malicious links within QR codes can be challenging for AI systems to analyze automatically. This attack method requires the employee to scan a code on their phone, removing the physical protection on their enterprise systems. The most recent innovative QR code technique involves rotating and embedding one QR code within another so a SEG scanning a QR code will get a different result than a victim who is instructed to scan the code sideways.

Malicious attachments: Disguising harmful links within seemingly benign attachments, such as PDFs or Microsoft Office documents, allows attackers to exploit the trust associated with common business communication.

URL obfuscation or redirection: Threat actors use legitimate services to mask malicious links, redirecting victims to phishing sites.

SEG-encoded links: Since SEGs rewrite incoming email URLs to scan for threats, attackers can embed pre-encoded URLs from other SEGs, tricking security filters into marking them as safe.

Malicious HTML files: Attackers attach malicious HTML files that, when opened, direct users to phishing sites or prompt credential entry.

These various techniques highlight the adaptive nature of phishing threats and techniques employed by threat actors that are used to bypass email security defenses.

The necessity for a strong security culture

As phishing attacks evolve, introducing novel threats that AI tools may not yet recognize, human ingenuity becomes a vital component of a comprehensive, layered defense strategy. This makes the cultivation of a strong security culture within organizations essential. While AI excels at routine pattern recognition and data filtering, human intuition and vigilance remain indispensable for identifying and responding to complex or ambiguous threats.

Building a robust security culture starts with communicating the significance of email security and positioning employees as the first line of defense. Creating a non-punitive environment where staff feel empowered to report suspicious activity is key to enhancing overall security.

This can be achieved by implementing user-friendly reporting tools, enabling quick identification and response to live threats, and offering interactive training sessions tailored to the unique risks faced by the organization. These initiatives ensure employees are equipped with the knowledge to spot and report phishing attempts effectively.

Recognizing and rewarding proactive security behaviors not only boosts engagement but also reinforces the value of individual contributions to organizational safety. By integrating these elements of a strong security culture, organizations can leverage human ingenuity alongside AI-driven defenses to create a formidable, multi-layered approach to threat protection.

Combining the power of AI efficiency and human ingenuity

While defensive AI can offer significant advantages, it is not infallible. The most effective defense against sophisticated phishing attacks combines AI-driven capabilities with human insight. AI excels at managing repetitive tasks and flagging potential issues, but human analysis is crucial for interpreting context, assessing nuances, and making informed decisions in ambiguous situations.

As phishing strategies continue to evolve, organizations must recognize that AI alone is not enough. By investing in a strong security culture that empowers employees to serve as vigilant defenders and complementing this with the power of advanced AI tools, organizations can establish a resilient, multi-layered defense against cyber threats.

We’ve featured the best encryption software.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

We just saw the end of the desktop scanner | usagoldmines.com

What is the release date and launch time for The Last of Us season 2 episode 2? tom.power@futurenet....

AI in the workplace: why upskilling, not fear, is the key to AI collaboration | usagoldmines.com

Star Wars Celebration is in full swing, and Lucasfilm just dropped more details on its Beyond Victor...

You don't have to pay for Google Gemini to comment on what you're looking at on your phone anymore e...

Resist, eggheads! Universities are not as weak as they have chosen to be. Ars Staff | usagoldmines.c...

There’s a secret reason the Space Force is delaying the next Atlas V launch Stephen Clark | usagoldm...

This Is the Best Free Weather App for Windows Justin Pot | usagoldmines.com

You can't hide from ChatGPT – new viral AI challenge can geo-locate you from almost any photo – we t...

Meta is set to train its AI models with Europeans' public data, and you can stop it doing so chiara....

Company apologizes after AI support agent invents policy that causes user uproar Benj Edwards | usag...

A Guide to Freezing Practically Any Food Allie Chanthorn Reinmann | usagoldmines.com

Don't Fall for This New Gmail Phishing Scheme Emily Long | usagoldmines.com

Verizon Updates Ultimate 5G Plan With More Data and New Features Juli Clover | usagoldmines.com

At monopoly trial, Zuckerberg redefined social media as texting with friends Ashley Belanger | usago...

Prominent nutrition researcher resigns from NIH over scientific censorship Beth Mole | usagoldmines....

When to Bring a Problem to HR (and When Not To) Jeff Somers | usagoldmines.com

Instagram Announces 'Blend' Shared Reel Feeds Juli Clover | usagoldmines.com

Trump’s FCC chair threatens Comcast, demands changes to NBC news coverage Jon Brodkin | usagoldmines...

HP agrees to $4M settlement over claims of “falsely advertising” PCs, keyboards Scharon Harding | us...

What Strava Buying Runna Will Mean for Both Running Apps Beth Skwarecki | usagoldmines.com

How Apple CEO Tim Cook Convinced Trump to Exempt Apple From Tariffs Juli Clover | usagoldmines.com

Walmart's online store is down – here's the latest on the shopping giant's site problems jacob.krol@...

US Interior secretary orders offshore wind project shut down John Timmer | usagoldmines.com

Tested! These are the best USB-C cables for charging and data transfers | usagoldmines.com

Best live TV streaming service: YouTube TV vs Sling TV vs Hulu + Live TV and the rest | usagoldmine...

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

I want to upgrade my laptop to Windows 11. Microsoft won’t let me | usagoldmines.com

Android 16 Beta 4 Available for Pixel Devices Kellen | usagoldmines.com

My Favorite Amazon Deal of the Day: The Google TV Streamer 4K Daniel Oropeza | usagoldmines.com

Grok Can Now Remember Your Past Conversations Jake Peterson | usagoldmines.com

Gemini 2.5 Flash comes to the Gemini app, gives developers control over “thinking” Ryan Whitwam | us...

I switched to Instagram’s X rival, Threads, for a month… and I kind of like it? | usagoldmines.com

Watch: Google Hosts TED Talk and Demos Android XR Glasses Tim | usagoldmines.com

How to Tell If Your Running Shoes Fit Correctly Meredith Dietz | usagoldmines.com

Beats Highlights New USB-C Cables in Latest 'Pill People' Ad Juli Clover | usagoldmines.com

I fed NotebookLM a 218-page research paper on string theory and the podcast results were mind-blowin...

Tiny startup could challenge Wasabi, iDrive, and BackBlaze with sovereign EU cloud storage solution ...

Chris Krebs, who debunked 2020 election lies, vows full-time fight against Trump Jon Brodkin | usago...

Skepticism greets claims of a possible biosignature on a distant world John Timmer | usagoldmines.co...

Synology could bring “certified drive” requirements to more NAS devices Kevin Purdy | usagoldmines.c...

Google Offers Students in US Free Access to Gemini Advanced, 2TB Storage Kellen | usagoldmines.com

Gemini Live Is Now Available to All Android Users for Free Jake Peterson | usagoldmines.com

10 Simple Home Maintenance Steps That Will Make Your Life Easier in the Future Jeff Somers | usagold...

Open Your Favorite Chat Right From Your iPhone Lock Screen Tim Hardwick | usagoldmines.com

DoJ Wins Another Victory: Google's Ad Tech Empire Violates Antitrust Laws Juli Clover | usagoldmines...

Insta360 teaser suggests it could launch world's best 360 camera soon – here are 5 things I want to ...

What Strava buying Runna means for users of both fitness apps – according to their CEOs matt.evans@f...

Google is gifting a year of Gemini Advanced to every college student in the US Ryan Whitwam | usagol...

Patreon challenges Twitch with its own 24/7 live streaming feature | usagoldmines.com

Buying a laptop? Wait! I beg you to consider a mini PC instead | usagoldmines.com

The bewildering world of USB-C charging, explained | usagoldmines.com

US DOJ finds Google guilty of advertising monopoly | usagoldmines.com

I can’t wait to butt-stomp demons on a motorcycle in ‘Ninja Gaiden: Ragebound’ | usagoldmines.com

Infamous site 4chan taken down by a hacker from rival community | usagoldmines.com

Verizon Quietly Updates Unlimited Ultimate With 200GB Hotspot, More Travel Data Kellen | usagoldmine...

DEAL: Google TV Streamer Down to Just $79 ($20 Off) Tim | usagoldmines.com

'Pakistan' Is a Cookbook for the Fearless Flavor Seeker Allie Chanthorn Reinmann | usagoldmines.com

The 50 Best '90s Movies You Can Stream Right Now Ross Johnson | usagoldmines.com

Netflix reveals July 2025 launch and first trailer for The Sandman's second and final season, and it...

New Marvel trailer for The Fantastic Four: First Steps reveals first looks at Reed Richards using hi...

Latest Instagram feature asks if you’re ready to reveal your innermost Reel personality to your best...

Google blocked over 5 billion ads in 2024 as AI-powered scams skyrocketed | usagoldmines.com

Nintendo quietly removes mentions of VRR support from its US and Canada Switch 2 websites | usagold...

Apple has removed yet another popular VPN app from its Russian App Store chiara.castro@futurenet.com...

Sony releases new trailer for 28 Years Later Jennifer Ouellette | usagoldmines.com

Google loses ad tech monopoly trial, faces additional breakups Ashley Belanger | usagoldmines.com

Best laptops: Our experts pick the top 12 models | usagoldmines.com

Synology NAS boxes are cutting features for non-Synology hard drives | usagoldmines.com

What the heck is a capture card, and do I need one to stream my gameplay? | usagoldmines.com

Windows 11 is installing on business PCs even when admins block it | usagoldmines.com

Microsoft confirms plan to kill its legacy PDF reader in Edge soon | usagoldmines.com

This 1440p 240Hz OLED gaming monitor is a solid score for $550 | usagoldmines.com

Galaxy S24 Lineup’s One UI 7 Update Has Resumed Tim | usagoldmines.com

Beats Cables Now Available at Apple Stores Joe Rossignol | usagoldmines.com

This small, affordable 4K dash cam has a unique ‘enhance’ trick for license plates and signs | usag...

This independent testing lab confirms Saily users save nearly 30% of mobile data while traveling udi...

Watch out, your work mobile apps could be a huge security risk - here's what to look out for | usag...

Samsung says a next-gen TV with RGB backlight is still coming this year – but the size will rule it ...

What do you actually do in Mario Kart World’s vast open world? Kyle Orland | usagoldmines.com

This 1440p home security cam with magnetic mount is only $25 right now | usagoldmines.com

What's New on Hulu in May 2025 Emily Long | usagoldmines.com

OWC Takes $100 Off Popular 14-Port Thunderbolt Dock During Its Spring Sale Mitchel Broussard | usago...

European diplomats targeted by Russian phishing campaign promising fancy wine tasting | usagoldmine...

NYT Connections hints and answers for Friday, April 18 (game #677) | usagoldmines.com

NYT Strands hints and answers for Friday, April 18 (game #411) | usagoldmines.com

Quordle hints and answers for Friday, April 18 (game #1180) | usagoldmines.com

Apple fixes dangerous iOS zero days after threats against targeted individuals | usagoldmines.com

Why AI won’t eliminate software engineering jobs | usagoldmines.com

Samsung Galaxy Buds FE 2 earbuds specs spotted, revealing bigger battery and even Wi-Fi support beck...

Thankfully Mario Kart World will have some open-world challenges in Free Roam mode | usagoldmines.c...

Rely on cybersecurity fundamentals, not LLMs, in the face of emerging threats | usagoldmines.com

Climate change will make rice toxic, say researchers Inside Climate News | usagoldmines.com

Diablo vs. Darkest Dungeon: RPG devs on balancing punishment and power Alan Bradley | usagoldmines.c...

Tesla makes its cars lie about their mileage, lawsuit claims Jonathan M. Gitlin | usagoldmines.com

This Ryzen 7 mini PC packs 24GB RAM and triple 4K ports for $479 | usagoldmines.com

Linkind Smart Solar Spotlight SL5C review: Light up your landscape | usagoldmines.com

Get Samsung’s super-fast 240Hz IPS monitor for its lowest ever price | usagoldmines.com

What Are Heart Rate Zones, and How Can You Find Yours? Beth Skwarecki | usagoldmines.com

These Samsung Galaxy Earbuds Are at Their Lowest Price Ever Right Now Pradershika Sharma | usagoldmi...

Leave a Reply