Kaspersky GreAT Expert Warns Blind AI Trust Outpaces Verification
Kaspersky warns that the rapid development of AI agents is creating new cybersecurity risks as productivity increasingly takes priority over verification. Attackers are exploiting users’ trust in legitimate AI tools by distributing malicious versions. In 2026, Kaspersky GReAT researchers identified 92,000 malicious attacks disguised as AI services, including fake ChatGPT, Claude and Gemini applications, as well as more than 15,000 malware samples disguised as agentic AI software.
“AI has advanced at a tremendous pace over the past few years. In its early stages, AI took the form of tools that could generate, summarise, and draft content. The next phase brought copilots, embedding AI directly into workflows to assist, suggest and guide users as they worked. Fast forward to now, we have entered the era of AI agents, which can plan, use tools, call APIs, and act autonomously. While humans remain present to verify each stage of an AI-driven development, we see more and more incidents where verification is often overlooked to maximise productivity, and when speed outpaces verification, that speed can also amplify risks,” warns Sojun Ryu, security researcher at Kaspersky's GReAT (Global Research and Analysis Team).
Ryu also highlighted the growing threat of open-source software supply-chain attacks, noting that attackers can exploit trusted components to gain access to enterprise environments. The March 2026 compromise of Axios demonstrated how quickly a compromised package can spread malicious code across the software supply chain.
“The truth is that developers need open source. AI needs open source. And attackers understand this very well, which is why software supply chain attacks targeting open-source packages remain one of the most significant threats. Across multiple open-source ecosystems—especially npm and PyPI—major compromises spread in rapid succession. Since the middle of last year, we have seen at least ten large-scale attack campaigns, and the pace continues to rise. From attacks on highly popular packages such as Axios to self-propagating worms such as Shai-Hulud, these campaigns are beginning to shake the foundations of the open-source ecosystem,” adds Ryu
“According to our survey last year, 31% of enterprise businesses had been impacted by a supply chain attack. This reflects how deeply open-source software is embedded in enterprise development environments. We should expect open-source ecosystems to remain a major target for attackers because it’s their door to crack into the intelligence inside the enterprises,” he adds.
Kaspersky recommends trusted development zones, hardened IDEs and agent permissions, controlled software entry points, and continuous visibility. Its researchers also identified over 250,000 potential CI/CD misconfigurations.
“As a security researcher, I strongly believe that we should shift security not only toward earlier stages of software development, but also from protecting deployed systems to securing the environments where software is created. Because when trust is verified before execution, organisations move faster, not slower. Most importantly, security fails when we prioritise speed, money, and delivery over protection and visibility,” he adds.