HomeSecurityTraditional security frameworks leave organizations exposed to AI attacks

Traditional security frameworks leave organizations exposed to AI attacks

In December 2024, the popular Ultralytics AI was compromised, installing malicious code that hoarded system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, ChatGPT vulnerabilities allowed unauthorized extraction of user data from AI memory.

See also: Evasive Panda: AitM attacks and DNS poisoning to distribute malware

AI attacks

The result: 23.77 million secrets leaked through AI systems in 2024 alone, a 25% increase from the previous year.

What these incidents have in common is that the organizations that were breached had comprehensive security programs. They passed audits. They met compliance requirements. Their security frameworks simply weren't designed for AI attacks.

Traditional security frameworks have served organizations well for decades. But AI systems operate fundamentally differently than the applications these frameworks were designed to protect. Attacks against them don’t fit into existing control categories. Security teams have followed the frameworks, but the frameworks simply don’t cover this area.

The major security frameworks that organizations rely on, such as the NIST Cybersecurity Framework, ISO 27001 , and CIS Control, were developed when the threat landscape was completely different. NIST CSF 2.0, released in 2024, focuses primarily on traditional asset protection. ISO 27001:2022 addresses information security as a whole, but does not consider AI-related vulnerabilities.

See also: The dark side of algorithms: When AI becomes the target of cyberattacks

Traditional security frameworks leave organizations exposed to AI attacks

CIS Controls v8 covers endpoint security and access controls in depth—however, neither of these frameworks provides specific guidance for AI attacks.

They're not bad frameworks. They're complete for traditional systems. The problem is that AI introduces attack surfaces that don't correspond to existing control families.

“Security professionals are facing a threat landscape that has evolved faster than the frameworks designed to protect against it,” notes Rob Witcher, co-founder of cybersecurity training company Destination Certification. “The controls that organizations rely on were not designed with AI-specific attack vectors in mind.”

See also: Google releases Gemini AI for Chrome on iPhone and iPad

Traditional security frameworks leave organizations exposed to AI attacks

This gap has led to increased demand for specialized AI security certification preparation that addresses these emerging threats specifically.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS