/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers say they were able to trick cybersecurity firm Cylance's AI-based antivirus engine into thinking programs like WannaCry and other malware are benign

By taking strings from an online gaming program and appending them to malicious files, researchers were able …

VICE Kim Zetter

Context & Ripple Effects

Cylance built its brand on machine-learning detection — a $1B valuation and $130M+ fiscal-2018 revenue, up over 90% year-over-year — but its credibility record already had a blemish in the allegations that it used bogus malware to close sales deals. The new research strikes at the product claim itself: appending strings from an online gaming program to files makes the engine classify WannaCry and other malware as benign.

The finding lands just months after researchers showed malware planting fake cancerous nodes in CT scans to fool radiologists — together marking 2019 as the year adversarial-input attacks moved from academic demos into both consumer security and medical imaging.

First-order effects

  • Cylance customers running the engine as a primary or sole detection layer face a documented evasion path for well-known threats like WannaCry, forcing the vendor to retrain or harden its models and publish guidance.

Second-order effects

  • Rivals selling AI-based detection now face buyer skepticism about black-box classifiers, pushing procurement toward vendors who submit to independent adversarial testing — a dynamic Cylance already knows from its testing-controversy history.

Third-order effects

  • If appended-benign-data evasions become a routine attacker technique, ML-only antivirus gives way to layered detection stacks, and 'AI-powered' becomes a claim buyers pressure-test rather than accept — the same trust gap now surfacing around vendor AI-security claims more broadly.

The trend: Machine-learning security products are entering an adversarial arms race in which crafted inputs, not zero-days alone, become a standard way to defeat them.