
AI-Powered Malware: Existential Threat or Overhyped Buzz?
AI dominates headlines and newsfeeds these days, and AI-related cybersecurity headlines are no exception.


You’ve got to love SEC filings in which mega-rich, super-huge companies admit they’ve suffered a “cybersecurity incident.”
To you and me, a cybersecurity “incident” probably involves inadvertently clicking a dubious link, reaching a phishing site, but bailing out in time and then quickly double-checking that no harm was ultimately done.
Or it’s where you accidentally messaged friend X directly, when you really meant to moan about X behind their back to mutual friend Y, thus dropping all three of you into a cyber-awkward social standoff.
If our entire home network were trashed and then blasted offline by cyberattackers, we probably wouldn’t consider that an “incident,” but would reach for words such as crisis, disaster, wipe-out, and many other phrases not suitable for repeating on a family-friendly website.
But for Boston Scientific, a $20-billion-a year healthcare giant in the US, their latest reportable “incident” involves an attack against “certain of its information technology systems that has resulted in a global disruption to the Company’s operations.”
As Irish cybersecurity luminary Brian Honan reported yesterday, “This explains why staff in the Irish operations have been told to work from home.”
Boston Scientific continues:
The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.
Given the level of operational disruption, this feels like a ransomware attack where critical files across the network were deliberately scrambled to stop users doing their jobs, followed by an extortion note demanding money for decryption keys to recover the ruined files and get business back on track.
Or it might have been a straight-out data breach, followed by a blackmail demand “promising” to “delete” the stolen information in return for a cryptocurrency payment, leading the company to take its own systems down in the hope of stopping the criminals from continuing their attack (for example, by scrambling files for additional leverage, or simply out of spite if the company refused to pay).
We don’t know exactly what happened yet, and apparently Boston Scientific doesn’t know either, so let’s give them the benefit of the doubt for now.
The amusing bit is the concluding sentence of the SEC report, which says, “[T]he Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company.”
Global disruption? Customer interactions halted? Staff sent home? No way to know how long it will take to fix?
Sure sounds like an impact, if you ask me.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

AI dominates headlines and newsfeeds these days, and AI-related cybersecurity headlines are no exception.

The escalating complexity of business IT environments, coupled with an increase in security threats, means companies can no longer ignore taking their security posture seriously. Unfortunately, the worldwide cybersecurity labor shortage continues to grow, adding to the challenge of having an in-house department that can protect and respond to cyber threats. Furthermore, security needs have become increasingly specialized, requiring expert hands on deck for your company to be fully protected. The complex nature of an organization’s distributed environment today means […]

It is the 20th anniversary of CISA’s cybersecurity awareness month and for the beginning of the second decade of this tradition. While this year’s themes are geared towards personal security, there are ways to implement them within an organization for more cyber resilience so there’s still something to learn here. Here are the key themes for the year: These themes are important to be aware of, but on the organizational level, there’s a lot more that can be done to […]

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






