There's a peculiar tint to the modern digital landscape: everything is somehow both the same as it's always been, and yet entirely different. We still use Google, but we get a handy AI summary up top. We still get phished, but it's being done to us by AI. On this latter [[link]] point, (PDF warning) points out that AI is now actually 4.5x more successful at getting users to click malicious links than standard attempts (via ).
More specifically, "AI-automated phishing emails achieved 54% click-through rates compared to 12% for standard attempts" because "AI enables more targeted phishing and better phishing lures." The bulk of the data from the report is collected from Microsoft's fiscal year 2025, from July 1, 2024 to June 30, 2025.
In addition, "AI automation has the potential to increase phishing profitability by up to 50 times by scaling highly targeted attacks to thousands of targets at minimal cost. This massive return on investment will incentivise cyber threat actors who aren’t yet using AI to add it to their toolbox in the future."
These phishing stats just point towards a more general—and, of course, expected—trend towards AI being used for nefarious purposes, not just for phishing:
"We’re witnessing adversaries deploy generative AI for a variety of activities, including scaling social engineering, automating lateral movement, engaging in vulnerability discovery, and even real-time evasion of security controls. Autonomous malware and AI-powered agents are now capable of adapting their tactics on the fly, challenging defenders to move beyond static detection and embrace behavior-based, anticipatory defense."
It can be easy to jump on the anti-AI bandwagon upon hearing things like this—and I'm no stranger to such sentiment—but I'm conscious that I'm hearing about this on the same day I'm hearing that . Pros and cons, as always.
Plus, there's [[link]] the fact that AI is used to help defend from cyber attacks these days. I suppose that's just what happens in an arms race, though; the neorealist in me sees such tit-for-tat escalations as inevitable to maintain equilibrium between different states and powers.
The good news is that it doesn't [[link]] seem there's much different, in principle, that we should be doing—just ramping up more of the same. For instance, Microsoft says that "no matter how much the cyber threat landscape changes, multifactor authentication (MFA) still blocks over 99% of unauthorized access attempts, making it the single most important security measure an organization can implement."
Of course, MFA might do little to prevent you from falling for a phishing attack. On that front, though, Microsoft's recommendations are again more and better implementations of the same defences we're used to: Inbox filters, restrictions on external communications, limiting remote access tools, educating users, and keeping an eye out for common patterns of attack behaviours.

1. Best gaming laptop:
2. Best gaming PC:
3. Best handheld gaming PC:
4. Best mini PC:
5. Best VR headset:
👉👈
LuckyLad385
I enjoy the daily missions and rewards system. It gives me extra motivation to play regularly and allows me to earn more coins and bonus items, which enhances the overall gaming experience.