Deepfake Demo: Watch Me Become Someone Else
45sThe live deepfake demo is visually shocking and immediately demonstrates the threat, making it highly shareable.
▶ Play Clip"Delivers on the promise of top threats with actionable advice, but includes sponsor plugs and some fluff."
This video discusses the top five cybersecurity threats in 2025, emphasizing the growing role of AI in both attacks and defenses. The host demonstrates deepfakes and provides practical advice for individuals and companies to adopt a 'zero trust' mindset and implement layered security measures.
The host uses AI tools to create deepfakes of his colleague and Taylor Swift, illustrating how realistic and accessible this technology has become.
The video will cover the top five cybersecurity threats in 2025, including AI-powered hacking, and how to protect against them.
Citing Bitdefender's report, 37% of people write down passwords, and 18% reuse passwords across accounts. Emphasizes using password managers, MFA, backups, and updating software.
96% of surveyed security professionals are concerned about AI's impact. AI is used to create perfect phishing emails, personalize attacks, and impersonate people.
Hackers use obfuscation to evade detection; 78% of malicious emails use two or more obfuscation techniques. Chatbot scams are also on the rise.
The solution is to adopt a 'zero trust' mindset: never click links in emails, always verify through a separate channel, and use AI to fight AI.
AI helps malware writers create more sophisticated malware, including polymorphic malware that adapts. Uncensored LLMs like FraudGPT and WormGPT lower the barrier to entry.
Ransomware encrypts data and demands payment. Average ransom demand is $2.73 million. Double and triple extortion are increasing, involving data leaks and DDoS attacks.
Attacks on vendors can impact major companies like Starbucks (via Blue Yonder). Diversifying and decentralizing data and services is key to protection.
IoT devices are often insecure and can be used in botnets. Isolating them on a separate network and changing default credentials are essential steps.
Deepfakes are the scariest threat, with 36% of security pros calling it very significant. They can be created from minimal data and are hard to detect.
Future quantum computers could break current encryption. Using MFA, changing passwords regularly, and adopting quantum-resistant encryption are proactive measures.
The video emphasizes that cybersecurity in 2025 requires a proactive, layered approach, with AI playing a dual role as both a threat and a defense tool. Adopting a 'zero trust' mindset and staying informed are crucial to mitigating risks.
What percentage of consumers have been hit by a security incident?
One in four consumers (25%).
04:07
What is the average ransom demand in 2024?
$2.73 million.
15:39
What is the 'zero trust human' concept?
Don't trust anything; always verify through a separate channel, and use AI to fight AI.
08:03
What are the two uncensored LLMs mentioned that are used for malicious purposes?
FraudGPT and WormGPT.
11:27
What is polymorphic malware?
Malware that adapts and modifies its code at runtime to evade detection.
12:12
What is the recommended backup strategy (3-2-1 rule)?
Three copies of data, two on different storage media, one completely offline.
03:16
What percentage of discovered malicious emails use two or more obfuscation techniques?
78%.
07:13
What is double extortion in ransomware?
Encrypting data and threatening to release it publicly.
16:47
What is the FBI's recommendation for verifying identity in calls?
Use a safe word or phrase known only to family members.
28:36
What is the emerging threat of quantum computers?
They could break current encryption methods, so quantum-resistant encryption is needed.
29:33
Top 5 Threats Introduction
Sets the stage for the video's core content, promising actionable advice.
01:11AI's Impact on Hacking
Highlights the widespread concern (96%) among security professionals about AI.
04:32Zero Trust Human
Introduces a practical mindset shift for individuals to combat AI-driven threats.
08:03Polymorphic Malware
Explains a sophisticated malware evolution that adapts to evade detection.
12:12Deepfakes as Top Threat
Identifies deepfakes as the scariest threat due to difficulty in detection and potential for fraud.
23:37[00:15] Hey Addie, come here. I want to try something. Hold on. Hi Anna.
[00:28] This is a hacker tool. Oh my gosh, this is wild. You know what? That's so weird. She looks like a dude from a trailer park. That's Addie deep faked as you. I don't like that.
[00:43] That's crazy. It's weird. You want to see Taylor Swift? Hey, do you like my songs? Yeah. Sing a song, shake it off, shake it off,
[00:58] shake it off, shake it off. Shake off. Is that Taylor Swift? No, It's almost impossible to not get hacked in 2025 from DeepFakes to AI powered
[01:11] vigilant of us are vulnerable. So let's do something about it. We're going to cover the top five cybersecurity threats you have to watch out emerging threats like AI powered hacking and what we can do about it,
[01:27] and even our companies that we work for because they help us pay the bills. I want us to become zero trust humans when it comes to technology.
[01:39] Let's try and not get hacked. By the way, but they fight cyber crime legit like you've seen the Avengers, right?
[01:51] They even had this super elite covert cybercrime unit within their company called the Draco team. It has some strong slithering vibes, And they partner with the FBI, Interpol Europol to fight. I mean,
[02:07] Now before we get to the scary stuff, the top five first, there are emerging threats, but basic IT security hygiene should already be in place.
[02:22] You know that you know who you are and Bit Defender's Consumer report talking to over 7,000 normies. 37% of you write your passwords down. 18% of you use the same password for three or more accounts and let's be honest,
[02:36] So for basic IT security hygiene passwords, use a password manager. Obviously I'm a big fan of Bitdefender. Pick one. Use it and use a secure unique password for everything you log into.
[02:51] please use multifactor authentication whenever you can. Receive a text message. Use an authenticator app.
[03:03] Authenticator to get an OTP or a one-time passcode. Two forms always. Now let's talk about your data. You have data, pictures, documents, videos, back it up, back it up. Put it somewhere safe. Have a copy of it. Ideally,
[03:16] You'll need three copies of your data, two of those on different types of storage media and one completely offline and locking it up.
[03:28] some kind of system. Next, update your software. Stop ignoring that notification. Do it right now. Your os your applications, You're either getting new features or they're patching a mistake they made and
[03:42] you're about to get hacked. Update as soon as you get it. In most cases, I'm a big fan of bitdefender. but just have something and leave it on.
[03:55] It only takes one moment of leaving yourself wide open to get hacked and your day is ruined. And finally, don't skip this. Stay informed. Stay up to date.
[04:07] you're already doing it. You're watching this video. Good job. But also don't skip the other security IT hygiene things because guess what? One in four consumers have been hit by a security incident. They got hacked.
[04:20] it's not like getting the chicken pox. It can happen a lot. Okay, here we go. but one's pretty bad too. AI powered hacking.
[04:32] Now they just released a pretty scary stat in their cybersecurity assessment report. 2024 out of the 1200 people they surveyed, nearly all of them, 96% are concerned about AI's impact on the threat landscape.
[04:44] people on the front lines. Yeah, Now you probably know this AI is amazing. I use it every day along with many other tech pros to do all kinds of stuff,
[04:57] write code like this and I automate and just do more things faster. Yeah, One of the scariest ways of doing that is with social engineering. Phishing emails where an attacker will try to impersonate someone trustworthy
[05:12] Download malware. The goal is to deceive you, but it's been kind of crappy in the past. mistakes, spelling errors, but you know what? Not anymore. With ai,
[05:29] the phishing emails are perfect because think about it. The same technology you're using to make sure your emails don't sound stupid, phishing emails are still the main way cybercrime is done.
[05:43] It's most common form 3.4 billion emails a day are sent out. Email impersonation accounts for 1.2% of all email traffic globally, Darktrace reported a 135% increase in malicious email campaigns.
[05:58] That didn't sound stupid. That was two years ago. AI has gotten a lot better, They're using AI to find out more about you to make it more targeted. They'll use AI to find out more information about you collecting data on your
[06:13] interest behaviors and preferences using a tool called worm GPT, And then instead of asking you to support a Nigerian prints, personalizing every hacking attempt.
[06:26] They can even impersonate your friends and family and copy their writing style. Like right now, I tried this today just to see what would happen. It's their new AI model from Elon Musk and let's see if it'll do this.
[06:41] That is not how I sound, but you get the idea. Also, grok is kind of unhinged, stay caffeinated and keep it geeky. Sounds just like me. It doesn't does it. off and suddenly they're scamming thousands of people with personalized phishing
[06:58] And it's not just that there's more hackers are using obfuscation techniques, which obfuscation is a fun word to say. Try it right now. Obfuscation, language processors or NLP to send malware or malicious links.
[07:13] They're essentially tricking the NLP that email providers use to detect if a And that's just one of the techniques they found that 78% of discovered malicious emails use two or more obfuscation techniques and listen,
[07:25] that's just phishing emails. There are SMS messages or texts, chat bots, that's a whole can of worms if you're single in 2025, I'm sorry because dating app chatbot scams are prevalent.
[07:37] It's only been a 2080 7% increase in scammers using chatbots. Of course using AI automation on a massive scale and with the advances in ai,
[07:49] They can generate a photo that's very realistic, It's just a person that the AI made up right now. learn about you and then take all your money. So now what's our solution?
[08:03] How do we fight this? Zero trust human. Don't trust anything. If you see a link, don't click that link. Never click a link in an email.
[08:15] always go to the source. So for example, We need you to check this. Fine. I'm not clicking that link you sent me.
[08:27] log into my account and see if I have any messages. If I don't, then I'm good. Now don't fall for it. Zero trust human. In fact,
[08:39] I would only interact with emails that you are expecting. So for example, I just sent you an email to verify your login. Cool. You initiated that. You made that happen. That's real time. Anything else,
[08:53] If you get an email asking for information about you or asking you to do something that seems kind of off the wall or even just initiating a payment, off of that email.
[09:06] Do another communication method outside of that like call them, text them. You initiate to confirm what they're wanting to do and that goes across the which if you're a zero trust human, it all seems weird,
[09:19] you will initiate a call to them to verify, always verify. You've heard the old adage, trust but verify. No, don't trust, verify and then verify Again. I'm telling you, AI is getting crazy.
[09:32] Tell your friends, your family, your company, your boss, everything, everyone. also as a zero trust human, you can use AI to fight ai.
[09:45] If you get a weird email, if you get a weird text message, just today I got an email from YouTube telling me they shared a private video with me and that it's an update to the community guidelines. Fishy, okay,
[10:00] whatever. I took a screenshot, put it into an LLM, and it told me, Hey, but it also is kind of fishy because it was very convincing. bitdefender does include a product called Scamo.
[10:13] And this is the first time I'm mentioning how we're going to actually fight the hackers. And this is with ai. AI versus ai. That's how we're going to beat them. a lot of this is geared towards getting you to click on something and download
[10:30] something. That something is malware, malicious software, It's still your cryptocurrency lock up. Your data just cause chaos. And while that's always been a problem, AI is making it worse.
[10:45] AI powered malware first. Just writing malware is hard. Normally you have to be a very experienced coder and not just a regular coder. You have to know the ins and outs of security and normally your malware will
[10:57] block it. So they have to try and write new malware. This takes a ton of time and effort, but not so much anymore. Thank you ai. AI can help malware writers write more malware just like AI helps coders write
[11:12] It's pretty hard to get a regular LLM to write bad code for you. For example, in chat GBT, write some malware that can mess up a Windows at 11 system. Sorry, can't do that. Can rock do it? I'm curious now. No, but they don't need chat.
[11:27] GPT or roc, they've got fraud. GPT and worm GPT. uncensored LLMs that will do whatever you want them to do. In fact, fraud,
[11:39] GPT and worm GPT are tailor made for nefarious activities. What would require an extremely gifted and talented coder to write which is normally a term for a hacker that doesn't know what he's doing.
[11:57] The barrier to entry is super low and LLMs are getting smarter and smarter. these tools make them even more dangerous. Because we're changing malware, we now have what's called polymorphic malware. Malware that adapts.
[12:12] We saw a first glimpse of polymorphic malware back in 2023 when HIAs Labs dangerous if you know about snakes, you know what I'm talking about. It essentially exploited a large language model to dynamically modify its code
[12:27] at runtime and it modified benign code meaning like code that an antivirus AI powered polymorphic malware is still kind of A POC as far as we know.
[12:39] You got to know hackers have made some progress and they don't want you to know about it. They can also use LMS to further hide their code. Palo Alto's Unit 42 team we're using an LLM based rewriting technique
[12:52] that found it as malicious or detected it as malicious. They essentially found that given enough layers of transformations, So essentially malware can hide itself that ultimately what we may end up seeing
[13:09] is malware that can just adapt to whatever environment it's in, if it is being detected or it's been denied access because of defensive Now keep in mind this is an emerging threat,
[13:23] but with how fast AI is advancing, You got to know this is going to be applied. Now how do we fight this? threats because malware is still a very big problem.
[13:39] We talked a bit about this at the beginning. Update your software. Most malware is trying to exploit bugs and unpatched software. Patch your software, update it, and you should be good most of the time. Also,
[13:53] avoid installing things. Don't install stuff. Reduce your attack surface. Yes, you're going to need applications. Install slack, install Photoshop, who downloaded this random third party voice generation software that no one's
[14:08] ever heard of. Also use advanced antivirus software. You want to use antivirus software that you know is the latest and greatest. and that's even using machine learning and AI techniques to detect the latest
[14:22] but make sure you have something and finally, stay informed. follow Twitter account or X accounts like bleeping computer or simply ask an LLM
[14:35] like chat, GBT or X. Think they have all this stuff free. Now just ask it. Hey, Just ask it and it'll tell you. Now, all these things I've mentioned, meaning you want to have multiple things you're doing to secure yourself
[14:50] multiple layers. It's never going to be just one thing. Now speaking of malware, but you've probably never heard of encryption list ransomware. Because ransomware by Design encrypts,
[15:04] it's malicious software that went executed will take your data, Essentially they put it into a locked room. They are the only ones, you got to pay them some money. Cryptocurrency, what have you once paid?
[15:21] they give you the key to unlock your data. It's been happening for years and it can cripple a company, There were 5,400 victims in 2024. Now that's organizations,
[15:39] the average ransom demand is 2.73 million. Is that right? 2.73 million the average. And what's crazy is these ransoms are often paid. Now,
[15:52] they borrow it with hopefully you not knowing about it, we're going to release this data to the public. information about your patients,
[16:06] Now this type of ransomware is on the rise and it kind of sucks because normally security hygiene things you might do,
[16:18] If it gets locked up, you've got to back up. No big deal. They have your data and they're going to release it. when ransomware is running rampant,
[16:33] they'll actually release free tools decrypt to decrypt against popular I'm just going to take their data and make 'em give me money. They can take it a step further and do double extortion or even triple
[16:47] Double extortion is where they both encrypt your data and threaten to release it. Triple extortion's crazy. The more I say extortion, the weirder it sounds, and then also do a third thing. And this could be, this is like a variable.
[17:01] They might DDoS your company essentially sending a bunch of network packets to Just be unusable or harassing your customers or employees. that ransomware is malware and all the AI power techniques we just talked about
[17:16] How do we protect ourselves first? It's same as malware. you want to have a backup also as an individual. So as part of the antivirus solution they offer take out your back with
[17:32] This is why you'll want advanced antivirus software because it does anti you might have a centralized server in your studio from 45 drives and they have an anti-malware service that will constantly analyze for ransomware.
[17:45] Now this cybersecurity threat, It's called supply chain attacks. In December of 2024, so recently Starbucks got hacked,
[18:00] but they also themselves did not get hacked. Wait, what I told you, This hack disrupted Starbucks operations impacting their payroll and scheduling All the employees had to keep their schedule and all their payroll information
[18:15] Well then how did they get hacked? It's one of their vendors. A key supply chain provider for Starbucks, a company called Blue Yonder, they were hacked and this impacted Starbucks scheduling software. In fact,
[18:30] blue Yonder was a victim of a ransomware attack, a ransomware group. Yeah, which I feel like they could have made a better name. Now here's the thing, and I'm sure they have an amazing cybersecurity team and they're very secure.
[18:45] a company they depend on for a service got hacked. Here's the thing, so many companies depend on other services and this is not an isolated incident. individuals. Now this can come in many forms. For example,
[19:01] you may have a medical provider that has all of your data and they get hacked and suddenly your personal information is out in the wild Do you have a software update that's got malware in it? That has happened.
[19:15] Now I'm scrolling through this article just remembering how many of these supply I think it was dubbed the year of supply chain attacks. what can we expect for emerging attacks?
[19:29] the targets major AI providers. What if open AI got hacked? We know that Apple intelligence was just rolled out very terribly and a lot of That's very new technology ripe for being hacked.
[19:44] They could attack a cloud like Amazon, AWS, Azure, Google Cloud, A lot of companies have their infrastructure there. If these get hacked,
[19:57] How do you protect yourself from this? Well, as an individual, but a lot of security people say, and I agree with them, Now I know this flies in the face of me telling you to always update your
[20:11] read the release notes for every update, maybe put it into AI and say, which even this article says this is better than trying to play.
[20:23] And then this one is what I try to model in my entire life and my business all the time, and it's diversifying, decentralizing your stuff. Don't use just one cloud provider. Don't put all your data on one hard drive,
[20:39] spread your stuff out so you're not dependent on one thing. That's just good. Practice number four is going to hurt. And this is I OT the internet things. You have smart lights, smart oven, smart toilet, it's all amazing.
[20:54] which means they're going to be vulnerable to some sort of attack. The smart devices in your home could become part of a botnet. Essentially. Hackers are able to commandeer your device and combine the power of your device
[21:08] with thousands of other people's devices to perform DDoS attacks on companies. they can affect your stuff with malware, making it unusable. Now, this is a big deal because on average people have about 21 IOT devices in their
[21:22] And this is so easy to miss because often we deploy these little devices in our software that needs to be updated, software that may have vulnerabilities and we just don't think about patching
[21:37] Most of the time we don't think about changing the username and password on an Hackers know these default credentials and using ai,
[21:51] there's 14 houses in Minnesota that I can get accessed on this little camera This happens all the time, and I'm talking in the context of homes.
[22:03] many iot devices that are built and used in a business environment. Now the emerging threats are just amplifying what the current threats are. AI enhanced everything. They can more easily find your devices more easily,
[22:17] and it's never been more important to make sure your iot devices are secure in First thing I would do, isolate your iot devices on their own network. Now, but essentially all it means is we put all your iot devices on their own network
[22:34] So the network where you're on your phone, you don't want your IOT devices talking to the rest of your network. how you do that depends on what kind of router and wifi situation you have.
[22:47] Thankfully we have chat GBT that can help you out or Google a better solution meaning iot that has no access to the internet.
[22:59] You run all of your smart home stuff local and it doesn't need to talk to a You can check out that video right around here somewhere that is a bit more Hey, network, check from the future here.
[23:12] I forgot to mention that Bitdefender does a ton of research on iot because it is vulnerability is identified in LG Web os, thermostats, fire sticks, smart cams,
[23:24] smart locks. That's kind of terrifying. Wait, do I have one of those? So if be curious about what iot stuff is vulnerable or what a vulnerability check out bit defender's research number five is the scariest by far.
[23:37] It's DeepFakes security Pros are scared 36% saying it's a very significant DeepFakes is where things get very scary because it's hard to detect them. Think about this, hackers bad actors. They can steal your face,
[23:50] They can make you say anything. And they can do that same thing to your family, to your friends, And what's even scarier is that it's not that hard to do.
[24:04] It could be as simple as having one picture of someone and just three seconds of audio of their voice and you can become them or create videos of them doing There are apps like Face App, which if I get a chance to play with,
[24:17] And then I saw a movie recently while I say recently, Essentially a sweet old grandma gets a voice fishing call, but it's her grandson's voice and it sounds very real.
[24:31] It incites fear and urgency and it's not just prerecorded videos. I can jump on a phone call a FaceTime call and talk to someone as someone else.
[24:43] Like they've been around for a while, but easy to tell. Not anymore either forced to join that milia and people are falling for this
[24:56] you probably saw this going around. There was a crypto fraud. In fact, were just playing Elon Musk crypto scan videos. And if you weren't intentionally trying to look for a deep fake,
[25:12] One guy lost $690,000 of a savings. Another woman sent $10,000. One out of 10 people say they have received an AI cloned voice message and a stunning 77% of people fell for it. They lost money. Now,
[25:27] I believe created a video of Taylor Swift singing in Japanese. We got David Beckham speaking a bunch of different languages. but not that kind of pot kitchen pots.
[25:43] If your loved ones received a call from you and it sounded like you and you were scared and you were asking for money and you were in trouble,
[25:55] just something very urgent, would they fall for it? Would your mom fall for it? Would you fall for it if your wife called you or your sibling? We're thinking my loved one just called me and they sound like they're in
[26:10] you can probably with in most cases, go yeah, deep fake. Got it. And the tools I've demoed in this video so far are not hard to get.
[26:22] Most of them are free and open source and I was able to get it up and running in where they're able to scrape massive amounts of data about you or your family,
[26:34] and then they can impersonate you with all that information, they know your interest, Just between 2022 and 2023, there's been a, what does that say?
[26:51] It's easy to do on a massive scale and it's getting harder and harder to spot. British engineering giant Arup revealed as $25 million deep fake scam
[27:05] One of their employees in Hong Kong had received a phishing email to send out a he's like, I don't know about that. it was convincing enough for him to send $25 million.
[27:20] This is a nightmare. This could happen to anyone. So what can we do about this? How do we protect ourselves from DeepFakes? Well, there is software out there that can help us detect if a video or a call is a
[27:35] deep fake. There's Sens ai, Intels fake catcher, reality defender. There's a lot out there. But here's the thing, we're doing AI against ai, and as AI improves in quality, deep fakes are going to get better and better.
[27:50] The eyes look weird or the lips don't quite match the words. So the hackers would fix that. They would make the eyes blink more regularly. They would make the lips and the mouth move regularly and they would keep fixing
[28:05] So whatever we're using now to detect if a video is a deep fake that can be and I'm optimistic about this, we stay in line with them. They don't have a massive advance and we're left behind on being able to detect.
[28:21] But you know what could happen? So for that, what do we do for ourselves? First, Someone calls you even if they look like your grandma and they sound like a You call your grandma with your phone and her number.
[28:36] There are other options like the FBI recommends that you have a safe word between you and your family, like monkey poop coffee or something. I don't know. Just a non statistical phrase that no one else would know except you and your
[28:50] family. That's a good idea. However, my family would forget or I might forget. it might be too late for this, but try to limit your digital footprint. Limit what is put out there about you. So for me, I'm done.
[29:04] my voice have been duplicated millions of times. Although I will say this, I've got a beard and beards just do not work well with these AI tools yet. I think hair is one of the hardest things to duplicate,
[29:19] They can't copy what they don't have access to. And this goes for your likeness, Limit that because it's going to get harder and harder to tell who the real you
[29:33] I do have a bonus fear in the future. This is number six, I guess, way more powerful than what we have now and what they'll be able to do.
[29:46] For example, your password right now, if it's long and complex, very hard to decrypt your password to figure out what it's with current if you're on public wifi at Starbucks and you log into Facebook,
[30:01] that connection between you and Facebook is very secure. It's TLS. a hacker could be in the middle and they could capture that traffic, encrypted. But they could just hang onto that.
[30:14] they could decrypt that information and learn about you specifically, Well always use multifactor authentication. Second, change your password on the regular. If they capture your stuff one day,
[30:31] but you change it the next day, it doesn't matter if they have your stuff. Also, we're seeing technologies come out called quantum resistant encryption or essentially cryptography that's secure enough.
[30:44] now. So if you had to make a choice between a provider and they're like, Hey, I think in the future we're all going to be on some type of quantum cryptography
[30:57] And thanks again to Bitdefender for sponsoring this entire video. doing research and making amazing software to help keep you and your loved ones, your friends, your businesses safe. If you want that piece of mind,
[31:12] I'm a big fan of their bitdefender premium security. crypto mining protection, email scam, copilot, password manager, VPN,
[31:24] They are that one-stop shop to give you peace of mind. And when it comes to cybersecurity, you do need to focus on defense in depth. your body from getting sick from viruses, your immune system.
[31:39] They said they want to use the Swiss cheese approach, a slice of cheese has a bunch of holes in it, eventually those holes become covered.
[31:53] And while you may think a cup of coffee and a keen eye is all you need to keep you want to have defenses in place like Bitdefender that have your back when maybe you're having a bad day or there are things you don't know about that come
[32:07] I'll catch you guys next time.
⚡ Saved you 0h 32m reading this? Transcribe any YouTube video for free — no signup needed.