Researchers say they were able to trick cybersecurity firm Cylance's AI-based antivirus engine into thinking programs like WannaCry and other malware are benign
By taking strings from an online gaming program and appending them to malicious files, researchers were able …
Context & Ripple Effects
Cylance built its brand on machine-learning detection — a $1B valuation and $130M+ fiscal-2018 revenue, up over 90% year-over-year — but its credibility record already had a blemish in the allegations that it used bogus malware to close sales deals. The new research strikes at the product claim itself: appending strings from an online gaming program to files makes the engine classify WannaCry and other malware as benign.
The finding lands just months after researchers showed malware planting fake cancerous nodes in CT scans to fool radiologists — together marking 2019 as the year adversarial-input attacks moved from academic demos into both consumer security and medical imaging.
First-order effects
- Cylance customers running the engine as a primary or sole detection layer face a documented evasion path for well-known threats like WannaCry, forcing the vendor to retrain or harden its models and publish guidance.
Second-order effects
- Rivals selling AI-based detection now face buyer skepticism about black-box classifiers, pushing procurement toward vendors who submit to independent adversarial testing — a dynamic Cylance already knows from its testing-controversy history.
Third-order effects
- If appended-benign-data evasions become a routine attacker technique, ML-only antivirus gives way to layered detection stacks, and 'AI-powered' becomes a claim buyers pressure-test rather than accept — the same trust gap now surfacing around vendor AI-security claims more broadly.
The trend: Machine-learning security products are entering an adversarial arms race in which crafted inputs, not zero-days alone, become a standard way to defeat them.