Skip to main content
Emerging ThreatsMalware & Ransomware

Unfettered AI Fuels New Wave of Cybercrime

Cluttered computer workstation with code on laptop screen in dimly lit room.

“6,644 models published openly on Hugging Face with labels such as ‘uncensored,’ ‘heretic,’ and ‘unfiltered,’” and more than 22 million downloads of those models in a 30-day period — a specific metric from ThreatDown’s research that underpins a simple claim: guardrail-free AI is not a theoretical danger, it is a present and broadly available toolkit for misuse.

ThreatDown’s tally: 6,644 “uncensored” models and 22 million downloads

Researchers at ThreatDown reported that labels like “uncensored,” “heretic,” and “unfiltered” appear on 6,644 openly published models on Hugging Face, and that those models were downloaded over 22 million times in a single 30-day window. The report uses that volume to argue the problem is mainstream rather than confined to niche or dark-web spaces — a claim the security leaders quoted in the research repeatedly echoed.

Malicious AI services: renting and repackaging frontier models

The report’s second major finding is that many malicious actors are not building models from scratch. Instead, ThreatDown identified “a network of malicious AI services” that take legitimate frontier models hosted on mainstream cloud infrastructure and then package, resell, or wrap those models for harmful purposes. In short, the supply chain now includes resellers and wrappers that make powerful but poorly controlled capabilities easier for attackers to access.

AI-native attacks versus traditional weaknesses

Security leaders emphasize that the new threat landscape combines two patterns. Randolph Barr, CISO at Cequence Security, notes that “approximately two-thirds of current AI-related incidents still originate from traditional weaknesses,” while “the remaining third are uniquely ‘AI-native’.” He lists those AI-native techniques as model and data poisoning, prompt injection, and autonomous agents that can chain API calls and act with minimal human oversight. Barr warns that AI systems’ dynamic, self-learning, and interconnected nature produces an attack surface that can grow faster than most security programs can respond to.

Defenders’ prescriptions: behavioral detection, automated containment, and deception

Responses from named security practitioners in the report converge on three themes: contextual behavioral detection, faster automated response, and offensive deception as part of defense.

  • Dr. Margaret Cunningham, Vice President of Security & AI Strategy at Darktrace, urges defenders to “assume breach, assume unapproved access,” and to accept that guardrails are imperfect. She warns jailbreak techniques — “context flooding, metaphor, literary framing, and iterative workarounds” — already evade many controls. Cunningham emphasizes that advanced defense “is still mostly human,” that vulnerability management lagged before AI accelerated discovery, and that defenders must “build defenses around the reality of their own environment” using behavioral detection, anomaly-based analytics, and autonomous containment.
  • Ram Varadarajan, CEO at Acalvio, describes attackers using “multi-agent swarms” that coordinate reconnaissance, credential harvesting, and data exfiltration, producing “exponential coordination” where “hundreds of specialized AI agents will operate simultaneously.” He prescribes a shift to “preemptive, AI-driven strategies” and advocates AI-driven deception — forcing attackers to “fight on the defender’s terms” and making adversaries expend compute against decoys.
  • Diana Kelley, CISO at Noma Security, frames the problem as governance: security teams must govern AI systems and agents that “make recommendations and decisions, and in some cases take action on behalf of the business.” She warns that without a “strong control plane for AI systems and agents, including clear guardrails on access and actions, along with identity, access control, data governance, and runtime monitoring,” AI will amplify existing weaknesses.
  • Shane Barney, CISO at Keeper Security, underscores operational urgency: advanced models “scan systems, networks and code to identify vulnerabilities at a speed and scale no human analyst can match,” creating a bottleneck of bugs human maintainers cannot triage. He advises organizations to assume public vulnerabilities will be weaponized “within hours rather than weeks,” implement automated update paths for internet-facing systems, prioritize dependency security patches immediately, and maintain robust logging and multi-factor authentication to limit lateral movement.

What this means for technologists, enterprise leaders, and end users

  • Technologists and security teams: treat behavioral baselines and anomaly detection as primary controls, accelerate automation for containment, and prioritize vulnerability triage and automated patching — because defenders “must operate on a much shorter clock,” per Shane Barney.
  • Enterprise leaders and procurement: expect third-party AI services to include wrappers or resales of frontier models; insist on clear control planes, runtime monitoring, and identity/access controls so AI agents cannot act unchecked, as Diana Kelley recommends.
  • End users and administrators: recognize that faster automated attacks will exploit unpatched systems and excessive permissions; follow immediate mitigation steps like robust logging and multi-factor authentication to reduce blast radius if compromise occurs.

ThreatDown’s numbers and the security leaders’ responses converge on a stark operational reality: powerful models without meaningful guardrails are widely accessible, malicious services can repackage legitimate models for abuse, and attackers are already combining traditional weaknesses with AI-native techniques. The remedy the quoted practitioners offer is not a single silver bullet but a stack of changes — behavioral detection tuned to specific environments, faster automated containment, and active deception — that accepts the premise Dr. Cunningham stated plainly: guardrails can reduce opportunistic misuse, but they are not a complete defense.

Original story: https://www.securitymagazine.com/articles/102458-ai-without-guardrails-is-driving-a-new-era-of-cybercrime