Why AI is making ‘low-severity’ vulnerabilities more dangerous
As frontier AI can chain “low-severity” bugs into routes towards critical government systems, defenders must now secure the attack path, not just the individual flaw.
-1788153809426.jpg)
Cybersecurity teams may need to look beyond individual vulnerabilities and understand how attackers could combine them into paths towards critical systems. Image: Canva
Cyber teams may need to rethink what “low severity” means as frontier artificial intelligence (AI) changes how attackers work, as several weaknesses can combine to create a route towards a critical system.
Speaking during the panel at GovInsider’s Cybersecurity Day on August 13, Palo Alto Networks’ director of industry solutions, Japan and Asia Pacific, Siddharth Deshpande, described how attackers are using these models.
He warned that agentic AI can help attackers chain together multiple low-severity vulnerabilities, write successful exploits, and launch complex, autonomous attacks
When low severity becomes high impact
Agentic AI can keep working towards the same objective without the limits of human shift patterns.
AI agent can continue searching for a way into a system around the clock, said Deshpande: “You give the agent a goal… and it can run on a continuous loop 24/7.”
“The more resources and context you give it, the more effective it will be at finding creative solutions to the goal it has been assigned,” he added.
Tan Kim Hwee, principal lecturer and consultant in the AI Strategy & Organisational Transformation Practice at the National University of Singapore’s Institute of Systems Science, described this as a change in the basic “physics” of cyber operations.
“The time is actually machine speed… and the collaboration between agents is now possible,” Tan said.
“That actually makes it very hard to sleep at night,” he added.
The combination of machine speed and coordination allows agents to keep searching for connections between weaknesses.
While a single low-severity flaw may not take an attacker far, several of them chained together could provide a route towards a high-value target.
A path matters more than a single weakness
If vulnerabilities can be combined, then assessing each one individually is no longer enough.
Defenders also need to understand where a weakness could take an attacker and what other systems it connects to.
That route may even cross organisational boundaries.
“We have to make sure that the paths that the attacker might take to get to those systems are well understood from an industry context,” Deshpande said.
“It is the weakest link that will cause harm to the entire ecosystem,” said Senior Lieutenant-Colonel Mok Chuan-Hao, commander of the Singapore Armed Forces’ Cyber Defence Group.
“Even if your system is secure, but an adjacent system is less secure, the enemy using AI will be able to find its way by chaining exploits to get into your target system,” he added.
An organisation may therefore strengthen its own systems and remain exposed through a weaker system connected to them.
Break the path when the system cannot be fixed
Even when defenders understand the route, closing it may not be as simple as applying a patch.
Deshpande pointed to mainframes, supervisory control and data acquisition systems, and older operational technology used by governments, banks and enterprises.
Patching or restarting these systems may require downtime that the services they support cannot tolerate.
“If you, for some reason, cannot actually patch the software… you need to be able to isolate that and put in place a compensating control,” Deshpande said.
This would prevent an attacker from exploiting the weakness through the network, endpoint or other routes, he added.
Virtual patching, isolation and controls at the network, endpoint or proxy level can cut off the attack path while the underlying vulnerability remains unresolved.
Look for the campaign behind the incidents
The same logic applies to detection, as seemingly unconnected security events may be part of the same operation, just as several minor vulnerabilities can form one attack path.
“We need to shift away from looking at incidents as being isolated… to adopt an attitude whereby we focus on discerning campaigns,” Mok said.
Viewing events as part of a campaign helps defenders piece together scattered signals and spot a wider attack taking shape.
AI does not need one critical vulnerability to cause critical harm, as several smaller weaknesses may be enough if an agent has the speed and persistence to connect them.
For governments, the task is not only to patch the worst flaws, but also to understand the paths they could form, break the ones that matter and detect the campaign before it reaches its objective.