Connect with us

Technology

When AI Becomes a Cyber Weapon: How Artificial Intelligence Is Changing Cyberattacks

AI is becoming part of the cyberattack toolkit, with threat actors using generative AI to improve phishing, analyse stolen documents, develop code and automate parts of cyber operations. A recent Kimsuky-linked campaign highlights this shift, while the UK is developing AI-specific cybersecurity standards to address the growing threat.

Vaishnavi V S

Published

on

AI-powered cyberattack and cybersecurity concept showing a digital shield protecting against cyber threats
AI is changing cyberattacks by enabling faster phishing, data analysis and other offensive cyber capabilities. Representational image. Image credit: AhmedAlMaslamani/Pixabay

Artificial intelligence is becoming part of the cyberattack toolkit, but its most immediate impact may be less dramatic than the idea of fully autonomous hackers suggests. Instead, AI is helping attackers improve existing techniques — from reconnaissance and phishing to analysing stolen information and exploiting software vulnerabilities — while cybersecurity agencies warn that these capabilities could become more powerful as AI systems advance. A recent case involving the North Korean-linked cyber group Kimsuky illustrates the shift.

From Phishing Lures to AI Infrastructure

In August, South Korean cybersecurity company Genians reported finding evidence that Kimsuky had assembled infrastructure for running and managing AI models locally.

According to Genians, the infrastructure included tools such as Ollama, GPT4All and Msty, as well as retrieval-augmented generation (RAG) technology, AI-agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool. The significance is not that Kimsuky had developed its own large language model. Rather, the reported infrastructure suggests an attempt to bring existing AI capabilities into a cyber-operation workflow.

Genians said local AI systems could allow operators to analyse documents without sending sensitive information to external AI services. It also assessed that the tools could support malware development, analysis of stolen material, attack automation and more convincing phishing campaigns.

The company said it also identified finance- and cryptocurrency-themed documents that appeared to have been generated with AI and designed to resemble legitimate investment reports and workplace documents. Reuters reported that Genians’ evidence could not be independently confirmed. The claims should therefore be understood as a cybersecurity firm’s assessment rather than independently established evidence of Kimsuky’s capabilities.

Still, the reported activity fits a wider trend identified by cybersecurity authorities.

AI Strengthening Existing Cyber Capabilities

The UK’s National Cyber Security Centre (NCSC) has repeatedly warned that AI is already affecting the cyber threat landscape.

Its 2025 assessment of the impact of AI on cyber threats through 2027 says AI is likely to make elements of cyber intrusion more effective and efficient. The agency expects AI-enabled tools to improve threat actors’ ability to exploit known vulnerabilities and warns that the period between vulnerability disclosure and exploitation could become even shorter.

The important point is that AI does not need to independently carry out an entire cyberattack to be useful to an attacker. A cyberattacker can use AI to perform individual tasks more quickly: understand technical information, research a target, process large quantities of text, generate or modify code, or produce convincing communications.

This can reduce the amount of human time needed for different stages of an operation. The NCSC’s assessment is therefore more measured than the idea of an imminent era of completely autonomous hacking. It describes AI primarily as a technology that can enhance existing cyber capabilities, while acknowledging that the technology is developing rapidly and that technical surprises are possible.

Phishing: One of the Clearest Risks

Social engineering is particularly suited to generative AI. Phishing traditionally depends on persuading a victim to trust a message, link or document. Poor grammar, awkward phrasing or obvious inconsistencies can expose fraudulent communications.

Generative AI can reduce some of those weaknesses by producing coherent text and adapting content to a particular context. The risk is not simply better-written emails. AI can help attackers work with information about potential targets and produce different versions of messages at much greater scale.

This is why cybersecurity agencies have focused on AI-enabled social engineering alongside other forms of cyberattacks. But there is an important distinction between AI-assisted phishing and autonomous phishing operations. The evidence available today supports the former much more strongly than the latter.

Stolen Data Could Become More Useful

The Kimsuky case also highlights another potential application: analysing information after it has been stolen. Large language models are designed to work with large volumes of text. When combined with retrieval systems, they can make it easier to search and retrieve relevant information from a collection of documents.

RAG, or retrieval-augmented generation, is not itself a cyberattack technology. It is a general AI architecture that allows a model to retrieve information from an external knowledge base and use it when generating an answer. Its presence in Kimsuky’s reported infrastructure is therefore significant because of how the technology was allegedly being incorporated into the broader operation, rather than because RAG itself is malicious.

The same principle applies to the other tools identified by Genians. Ollama, GPT4All, Msty and Cursor are legitimate AI or software-development tools. Their appearance in a suspected cyber-operation does not make the tools themselves malicious. The concern is how legitimate AI capabilities can be repurposed.

Masked figure facing computer screens, illustrating the growing use of AI tools in cyberattacks such as phishing, stolen-data analysis and cyberattack automation.
The reported Kimsuky activity highlights how AI tools are being incorporated into cyberattack operations, from analysing stolen material to developing more convincing phishing campaigns. Representational image. Image credit: Tima Miroshnichenko/Pexels

Cyberattacks: Why Local AI Matters

The reported use of locally operated AI models introduces another dimension. When an AI system runs locally, information can be processed on infrastructure controlled by the operator rather than necessarily being sent to an external AI service.

For legitimate users, local processing can provide privacy, control and offline functionality. For a cyberattack, the same characteristic could make it possible to process sensitive or stolen material without relying on an external AI provider.

That does not make local AI inherently unsafe. It illustrates a broader cybersecurity principle: capabilities designed for privacy and control can have both legitimate and malicious uses.

The UK AI security: Distinct Cyber Issue

Governments are now responding not only to the use of AI by attackers but also to vulnerabilities within AI systems themselves. The UK published its Code of Practice for the Cyber Security of AI in January 2025. The voluntary framework applies to AI systems, including generative AI, and sets out security principles across the AI lifecycle. The UK’s approach has subsequently moved towards international standardisation.

The European Telecommunications Standards Institute (ETSI) developed EN 304 223, a standard for the cybersecurity of AI. The UK government says the standard draws from the UK’s AI Cyber Security Code of Practice. In July 2026, the UK Department for Science, Innovation and Technology also published a mapping of global AI security standards, regulations and guidance against ETSI EN 304 223.

This reflects an important change in policy thinking: AI security is increasingly being treated as part of cybersecurity rather than as a separate question of AI ethics or safety. The UK is also strengthening wider cyber resilience

AI-specific policy sits alongside broader UK cybersecurity measures. The Cyber Security and Resilience (Network and Information Systems) Bill is currently progressing through Parliament. Its stated purpose is to strengthen the security and resilience of network and information systems used in connection with essential activities. As of August 13, 2026, the Bill is in the House of Lords, with committee stage scheduled to begin on September 1.

The legislation is broader than AI. But that is important because AI-enabled attacks ultimately target the same networks, organisations and digital infrastructure that conventional cyber threats target.

The NCSC has also stressed that cyber resilience cannot be treated solely as an IT concern. In June 2026, it warned that the rapid pace of frontier AI development means assumptions about cyberattack can become outdated within months rather than years.

The Bigger Risk is Convergence

The Kimsuky case points towards a more important question than whether hackers will use AI. They already are. The question is how deeply AI will become integrated into the different stages of a cyber operation. Today, the strongest evidence points towards augmentation: AI helping humans perform existing tasks more quickly or at greater scale. Tomorrow’s risk could lie in the increasing connection between those individual capabilities — reconnaissance, information retrieval, social engineering, coding and vulnerability exploitation.

That does not mean AI will suddenly produce completely autonomous cybercriminals. Current evidence does not justify that conclusion. But it does suggest that cybersecurity is entering a period in which the traditional boundary between a human attacker and a software tool is becoming less clear.

For defenders, that makes speed important. If AI allows cyberattackers to analyse information, identify vulnerabilities or tailor social-engineering attempts faster, defensive systems will need to detect and respond at comparable speed. The UK’s emerging policy framework reflects this shift: secure the AI systems themselves, strengthen the resilience of the infrastructure around them, and prepare for AI to become part of both offensive and defensive cybersecurity.

The Kimsuky case, if Genians’ findings are borne out by further evidence, could be an early example of that transition, not because AI has replaced the hacker, but because the hacker is beginning to use AI as part of the machinery of the cyberattack.

Vaishnavi VS is an Editorial Associate at EdPublica. She holds a Master's degree in Mass Communication from Pondicherry University, India. She writes on education, science, environment, innovation, and public policy.

Society

Digital Detox: Why Taking a Break From Screens Matters

A digital detox can help children and adults reduce screen dependence, reconnect with nature and relationships, and create space for reflection and creativity.

Anoop Krishnan H

Published

on

digital detox
Image credit: Darina Belonogova/Pexels

A digital holiday can offer a practical pause from screens and constant connectivity. From children to working professionals, taking regular time offline can help rebuild attention, creativity, relationships and a healthier balance with technology. A digital detox can help children and adults reduce screen dependence, reconnect with nature and relationships, and create space for reflection and creativity.

Imagine a day without digital devices. Those of us who grew up in the 1990s remember the shift firsthand — from writing letters with ink pens to typing messages on social media and making video calls. Artificial intelligence and rapid technological change now touch nearly every part of daily life, and an internet-first era has drawn humanity into a globally connected network. We ask AI chatbots for advice on everything from recipes to relationships. Yet the love of books and literature hasn’t disappeared — it has simply changed form. Audiobook platforms have grown fast, gaining listeners who once preferred print. At the same time, attention spans are shrinking as short-form video reshapes how we consume information. In an era built around likes, shares and instant search results, there is a real case for finding a better balance between online and offline living.

Children under 16 in particular need more exposure to offline living, and less dependence on screens. Time away from devices helps children build social skills, sharpen critical thinking, and learn to approach problems from multiple angles — all of which support holistic personal development.

Of course, context matters. During the Covid-19 pandemic, online education became the only option once lockdowns were imposed, and digital learning kept formal education running when nothing else could. But in a post-pandemic world, governments are increasingly reconsidering how much unsupervised screen time is appropriate for children. China’s “minor mode” framework restricts screen time by age; the United Kingdom has moved to ban social media for under-16s from 2027; and New Zealand has introduced legislation to do the same. In India, Karnataka announced in its 2026 state budget that it would ban social media use for under-16s, and Goa’s government has said it is studying a similar move. The details of enforcement remain unsettled in most of these cases, but the direction of the debate is clear: policymakers across the world are actively discussing how to limit children’s social media access. A middle path — rather than an outright ban — is worth considering.

Digital Detox Awareness

Schools are well placed to lead here. A monthly digital detox awareness session, run by trained resource persons and built around hands-on, creative activities, could help draw out children’s imagination while gently reducing screen dependence. Students could keep a diary of their experience — what they noticed, what they missed, what surprised them — during each digital detox day. Over time, schools could even form “digital holiday clubs” to mark one day a month as a shared offline day. Practised consistently through school life, this could help a generation grow into adults with more clarity of thought and purpose — provided they use that offline time for something creative and productive, rather than simply waiting it out.

In practice, a life entirely without the internet isn’t realistic for most of us. But digital minimalism is achievable, and a single digital holiday once a month is a reasonable place to start. Switching off completely for one day can open space for new ideas and reconnect us with the natural world.

That day can also be a chance for self-reflection — a deliberate pause to look inward. It can be used to build a skill: writing, cooking, dancing, whatever draws you. It’s an opportunity for offline meetups with friends and family, for cycling a short distance, for reading a book purely because you chose it, not because an algorithm suggested it. A digital holiday can help you rediscover what actually matters to you and reset your priorities. It also strengthens real relationships — the kind built through presence, not notifications — and leaves room for practices like yoga and meditation that support genuine mental peace.

Digital Detox Is Harder for Working Professionals

For working professionals, this is harder. Most of us are running behind deadlines, structuring our days around work and family obligations already. Stepping outside that loop, even for a day, takes real intention. But the practice of digital detox is worth the friction — it teaches delayed gratification and reintroduces us to the quieter pleasures of offline living.

None of this is a case against technology. Instant messaging and the broader digital revolution have made services faster and more accessible than ever, and that’s worth acknowledging. But speed and convenience come with a cost if we let them: information overload, and an over-reliance on AI chatbots for decisions that deserve real human judgement. Blindly following AI-generated advice isn’t something to encourage. The internet is a necessity now — but that makes the case for balance stronger, not weaker.

Reconnect with nature. Spend real time with the people who matter to you. And once in a while, take the leap: switch off for a day, and notice the difference it makes.

Continue Reading

Technology

What is AGI? AI’s Next Era: When Machines Start Taking on the Work

As AI systems move from answering prompts to handling complex, multi-step tasks, the boundary between today’s AI agents and the broader idea of artificial general intelligence is becoming harder to ignore. This article examines what AGI means, how autonomous AI is changing knowledge work, and what the shift could mean for India.

Published

on

A programmer works at a desk with multiple screens displaying computer code.
A programmer works with code across multiple screens, reflecting the growing role of AI in software development and autonomous coding. Representational image. Image credit: Mikhail Nilov/Pexels

The next phase of artificial intelligence is taking shape inside the companies building it. AI agents are being trained to handle hours-long assignments, while researchers are using AI to write code, investigate technical problems and help develop the next generation of AI systems. AGI generally refers to an AI system capable of learning, reasoning and applying knowledge across a broad range of tasks, rather than being limited to a narrow set of functions.

There is no universally accepted definition or test for AGI, so there is still no agreed threshold for declaring that a system has reached it. But many jobs gradually moving into automation, pushing thousands into uncertainty might help us understand the whole story.

OpenAI says more than 70% of sampled Codex users in May 2026 asked the coding agent to handle tasks estimated to take more than an hour. About a quarter made at least one request estimated at more than eight hours. Anthropic reported in August that Claude was leading 26% of the AI research and development work covered by its internal measurement system, compared with less than 1% in February. Both figures come from the companies themselves and are not measures of the wider economy.

For most people, AI is still something they consult. Ask a question, get an answer. Give it a document, get a summary. Ask for code, get code. That model is changing. The newer systems can take an assignment, break it into steps, use software and other tools, check their progress and continue working with less human intervention.

What happens when AI can handle much more of the work itself? That question sits at the heart of the debate over artificial general intelligence, or AGI.

From Prompts to Assignments

A programmer can ask AI to write a function. An agent can be given a larger job: inspect an existing project, build a feature, run tests, find problems and make corrections. The AI is handling a sequence of tasks rather than producing one answer. That distinction could eventually change how many kinds of knowledge work are organised.

AGI: Two people count stacks of cash at a table with digital code and data displayed in the background.
People handle cash at a counting table as digital code and data appear on a projected screen, illustrating the changing relationship between technology, automation and work. Representational image. Image credit: Tima Miroshnichenko/Pexels

AI is Helping Build AI

Frontier AI companies are already making the change clear. OpenAI says it has developed an “automated research intern” capable of performing defined research tasks under human direction. The company says it is working towards an automated AI researcher by March 2028.

Anthropic’s August figures point in the same direction. The company says Claude is increasingly being used in its own AI research and development, although it remains dependent on human researchers and is not fully autonomous in the measured work. AI is helping researchers build better AI.

So, When does AGI Arrive?

Researchers disagree about the capabilities AGI should demonstrate, and no accepted test exists. Google DeepMind CEO Demis Hassabis said in May that he expected AGI could arrive within roughly four years, possibly sooner. If an AI can research a subject, analyse data, write software, use several digital tools and complete a complex assignment, how much of that work still needs to be done by a person? Work will change before we have an answer.

A researcher could delegate a literature review and data analysis. A programmer could hand over an entire software feature. Some tasks may disappear from jobs. Others may become faster. New work will emerge around supervising, testing and governing AI systems.

India is Preparing for the Shift

India is investing heavily in the infrastructure needed for the next phase of AI. The IndiaAI Mission has an approved outlay of ₹10,371.92 crore over five years. The government said in August 2026 that more than 45,000 GPUs had been onboarded through its shared computing programme and 237 projects had accessed subsidised capacity. Twenty indigenous foundation-model proposals had also been selected from 506 applications.

AI systems need to work across Indian languages and very different economic and institutional settings. OpenAI announced an India initiative with Tata Group in February covering areas including AI infrastructure and local capability. Google DeepMind has partnered with Indian institutions on applications in science, education, agriculture and energy.

It becomes harder when an AI system spends hours researching, writing code, analysing information and making decisions before presenting a result. The human role will increasingly involve setting the objective, judging evidence and deciding when a system should be trusted. AGI remains undefined, and nobody can put a reliable date on its arrival. But the shift towards more autonomous AI is already visible.

Continue Reading

Technology

India’s AI Moment Rests on More Than Code

India has assembled many of the building blocks of an AI economy: capital, talent, research and startups. But its next phase will depend as much on chips, electricity, skills and policy as on software, exposing the gap between rapid growth and the systems needed to sustain it.

Published

on

featured 4

India’s AI ambitions are now reflected in global rankings, investment flows and Bengaluru’s emergence as a lead ing innovation hub. Yet the numbers reveal only part of the story. Much of the hardware is imported, demand for skilled workers continues to outpace supply, and the infrastructure pow ering AI faces growing pressure. The country’s next challenge is no longer adopting AI, but building the industrial and social foundations that can sus tain its growth.

j2 1

The Hardware Production Gap

The IndiaAI Mission has deployed over 38,000 GPUs and TPUs across domestic data centres. Registered startups and researchers can access this compute at ₹115–150 per GPU hour, roughly 42% cheaper than com mercial cloud rates. The governmentplans to scale this to 100,000 GPUs by December 2026. Not one of these chips is made in India. Every GPU in that stack is sourced from the same export controls that cut China off from this hardware exist as legal authority that could, under different political conditions, apply to India too.

A US India trade framework announced in February this year includes language protecting India’s chip access, but it depends on ongoing political align ment. Budget 2026–27 allocated ₹8,000 crore to the semiconductor and display manufacturing ecosystem programme, the largest single-year outlay since the mission launched, with a separate ₹1,000 crore for India Semiconductor Mission 2.0. The Tata PSMC fabrication plant at Dholera is targeting trial production by late 2026. But these plants are not building AI grade chips.

India’s Sovereign AI

At the IndiaAI Impact Summit 2026, three models were introduced: Sarvam AI, BharatGen, Gnani.ai. BharatGen has assembled over 15,000 hours of annotated voice data across 22 Indian languages. Sarvam’s Vision model, a 3-billion-parameter doc ument intelligence system, scored 84.3% on a standard OCR benchmark, outperforming Google Gemini 3 Pro (80.2%) and OpenAI’s GPT 5.2 (69.8%). Bhashini-v2, launched in early 2026, offers AI-powered translation across all 22 scheduled Indian languages and serves 140 million users on the MyGov platform. India is constructing the language of sovereignty. Indigenous models, na tional compute, and mission branding. But the engine underneath runs on hardware it cannot make and may not always be allowed to import.

The Jobless Economic Growth

India’s IT sector has long been the engine of middle-class stability, con tributing about 7.3% to GDP, employing over 5.8 million people directly, and creating the white-collar jobs that drove spending across housing, edu cation, and retail. That engine is under pressure from the same technology India is racing to lead. Particularly for mid-level coding, BPO, and testing roles that form the bulk of jobs in India. TCS announced 12,000 layoffs in 2025; Infosys and Wipro followed. Across the sector, jobs have been cut in what companies call strategic realignment.

j3 1

NITI Aayog’s October 2025 report projected that in a worst-case sce nario headcount could fall to 6 million by 2031. In April 2026, global equity re search firm Bernstein wrote an open letter to Prime Minister Modi warning that India’s 10 to 15 million IT services, GCC, and BPO workforce faces direct exposure to AI-driven automation. Sonal Varma, chief economist for India and Asia ex-Japan at Nomura, said: “Entry-level routine jobs are being displaced, and mid-level jobs are transforming. India needs to create about 8 million jobs annually.’’

Skill Set for the Emerging Sector

AI DevOps engineers, data centre operators, ethical AI auditors are the major emerging roles. But they require skill sets entirely different from the mass-hiring model that built the IT sector. An IIM-Ahmedabad study found that 68% of white-collar work ers fear automation within five years; 55% have adopted AI tools, but only 48% have received any training. India produces over 1.5 million engineering graduates annually but ranks 18th globally in skills alignment and 73rd in human capital in terms of AI. Graduate volume is not the same as workforce depth.

In that way adoption without re skilling becomes exposure to disrup tion dressed up as progress. NASSCOM projects that the broader AI push could generate 750,000 jobs and add $500 billion in economic value by 2030. Whether they reach the workers being displaced depends on whether India can close the gap between how many people it trains and how well it trains them. It is a gap that every major index in 2026 has documented and none has resolved.

The Climate Bill

There is a cost to India’s AI ambitions that doesn’t appear in invest ment announcements is the physical climate risk accumulating around the infrastructure meant to run it all. A report by climate risk consul tancy assessed 2,595 planned data centres worldwide, examining risks of direct physical damage from climate hazards, operational disruption from extreme heat.

For India, the country ranks 11th globally in physical climate risk to planned data centre infrastruc ture. The more concerning finding is where that risk concentrates. Tamil Nadu, Telangana, and Karnataka, three of India’s major data centre corridors are among the top 30 regions globally for projected operational disruption from extreme heat. South Asia as a whole has one of the highest pro portions of high-risk planned facil ities globally, with risk projected to increase sharply toward the end of the century.

j4 1

Data centres require large-scale cooling to keep servers running. Rising ambient temperatures increase cooling costs, strain electricity grids, and raise the probability of outag es. Countries including India, Brazil, Mexico, Indonesia, and Spain already record some of the highest projected operational disruption risks from heat globally, with more than 75% of anal ysed facilities classified as high risk. Productivity losses become ten times higher with indirect risks like power outages, water shortages, infrastructure failures.

India’s data centre ecosystem is concentrated in heat-exposed regions with al ready-strained urban infrastructure. Future vulnerability can be reduced by adequate planning during site selection, engineering standards, and resilience investment. Microsoft has committed $17.5 billion to Indian data centre expansion. Google is building a hub in Andhra Pradesh with a $15 billion commitment. Amazon has pledged $48 billion through 2030. At this stage, planning choices that are made now determine the risk profile for the next three decades. India has no mandatory national standard governing data centre siting or construction for climate resilience. This gap is no longer a future problem.

Where the Momentum Meets Reality

The 190% growth in Bengaluru’s ecosystem, the indigenous models outperforming global benchmarks, the public compute infrastructure being built at scale are all substantiated achievements. The QS Index gives In dia a perfect score of 100 on economic capacity and ranks it fifth globally in the “Future of Work” category. “The IndiaAI Mission represents substan tive, measurable progress, not merely a policy optics exercise.”

But the gaps are structural. The top ten Indian cities account for nearly half of all AI users while representing less than 10% of the population. The choices being made about who controls the technology, who gets the jobs, who bears the risks will deter mine whether this moment becomes something real or just another set of promises that get quietly shelved. What happens in policy rooms and planning offices will have to answer it.

Continue Reading

Trending