Traditional Security Frameworks Fail to Address AI-Specific Threats
- Securityish
- AI & Future Technology
Quick Summary
The Securityish Brief
In December 2024, the Ultralytics AI library was compromised, resulting in malicious code being installed to hijack system resources for cryptocurrency mining. This incident is part of a troubling trend, as by August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, vulnerabilities in ChatGPT allowed unauthorized extraction of user data from AI memory, contributing to a total of 23.77 million secrets leaked through AI systems, a 25% increase from the previous year.
These incidents occurred despite the affected organizations having comprehensive security programs that passed audits and met compliance requirements. The issue lies in the fact that traditional security frameworks, such as the NIST Cybersecurity Framework, ISO 27001, and CIS Controls, were not designed to address the unique vulnerabilities posed by AI systems. For example, NIST CSF 2.0 focuses on traditional asset protection, while ISO 27001:2022 does not account for AI-specific vulnerabilities.
Traditional frameworks are comprehensive for conventional systems, but they fail to cover the new attack surfaces introduced by AI. Security professionals are now facing a rapidly evolving threat landscape that these frameworks do not adequately protect against. As Rob Witcher, co-founder of Destination Certification, notes, the controls organizations rely on were not built with AI-specific attack vectors in mind.
One specific challenge is prompt injection, where attackers manipulate AI behavior using valid natural language input, bypassing traditional security controls. Similarly, model poisoning occurs during the authorized training process, where attackers corrupt training data, allowing AI systems to learn malicious behavior.
AI supply chain attacks further expose gaps in traditional security frameworks, which focus on vendor assessments and software bill of materials. These frameworks do not provide guidance on validating the integrity of pre-trained models or detecting poisoned datasets, leaving organizations vulnerable despite their compliance with existing controls.
The implications of these gaps are significant, as organizations are increasingly deploying AI systems across various operations. Many security teams struggle to inventory the AI systems in their environment, making it challenging to apply necessary AI-specific security controls.
Organizations must take proactive steps to address these vulnerabilities, including implementing AI-specific security controls and building expertise within their security teams. The regulatory landscape is also changing, with the EU AI Act imposing penalties for serious violations, emphasizing the need for organizations to adapt their security practices to include AI-specific considerations.
Why Traditional Frameworks Are Insufficient
Organizations that rely solely on traditional security frameworks may find themselves exposed to new categories of threats. The attacks against the Ultralytics AI library and ChatGPT vulnerabilities illustrate that compliance does not equate to security. As the threat landscape evolves, organizations must recognize that the existing frameworks do not cover AI-specific attack vectors, necessitating a shift in their security strategies.
Key Takeaways
- Conduct an AI-specific risk assessment to identify vulnerabilities in your systems.
- Implement AI-specific security controls even if they are not mandated by existing frameworks.
- Build AI security expertise within your security teams to better defend against AI threats.
- Update incident response plans to include scenarios related to prompt injection and model poisoning.
- Regularly inventory AI systems in your environment to ensure comprehensive security coverage.
Key Terms & Concepts
- Prompt Injection: In this article, prompt injection refers to attacks that manipulate AI behavior using valid natural language input.
- Model Poisoning: Model poisoning is a type of attack where training data is corrupted, causing AI systems to learn malicious behavior.
- AI Supply Chain Attacks: AI supply chain attacks involve compromising pre-trained models or datasets, posing risks that traditional security controls do not address.
- NIST Cybersecurity Framework: The NIST Cybersecurity Framework is a set of guidelines for managing cybersecurity risks, primarily focused on traditional asset protection.
- ISO 27001: ISO 27001 is an international standard for information security management systems, but it does not account for AI-specific vulnerabilities.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.