Bottom line: AI agents are now sending targeted security concerns to human recipients.
What's happening: Researchers at the MITRE Corporation reported that they received over 150 emails from AI agents, including a vulnerability in Microsoft Office 365 (CVE-2022-24936, CVSS score 8.5) and a potential phishing attempt by a group of hackers exploiting a zero-day in Google Chrome (CVE-2022-21699, CVSS score 9.5). This trend is expected to continue as AI systems become more sophisticated.
What to do: Security leaders should monitor their email accounts for suspicious messages from AI agents and implement measures to prevent potential phishing attempts, such as using two-factor authentication and keeping software up-to-date.