When AI hacks, AI fixes (and there I am in the middle, going back and forth( or like a yoyo ?))Over the past few weeks, several websites under my responsibility have been hacked. Then others. Then yet more. Not an isolated incident that you can quickly file away among your bad memories, but a real wave, concentrated over the space of a few weeks, which eventually engulfed my daily life.
And as I found myself dealing with one emergency after another, I came to a realization which, at first, almost made me smile before giving me cause for serious concern: these attacks are undoubtedly increasingly aided by artificial intelligence. And my way of responding to them… is too.
Let’s get one thing straight from the outset, to be honest: I’m not the sort of webmaster who spends hours poring over code to track down a bug line by line. I run an agency, I manage websites, I talk to panicked clients and code isn’t my natural territory. And that’s precisely why this whole ‘AI versus AI’ business concerns me so much: without it, much of what I’ve had to get to grips with recently would have been really hard for me to understand.
The scenario is more or less the same every time, only the details change: a third-party extension that’s poorly maintained or hasn’t been updated in time, a backdoor quietly added to the site’s files, sometimes hidden away where no one would look for it - the files are sometimes outside the site, hidden in a blockchain, or it’s actually template settings that load base-64-encoded code. There’s something about it that borders on genius.
What struck me wasn’t so much the ingenuity of each individual attack – we’ve always seen clever hackers – but rather the pace, the speed, and above all the clean execution. The injected code is crisp, well-structured and automated. In short, it’s the sort of thing that even a highly motivated human would struggle to sustain over time. They call it ‘industrialisation’; as for me, I thought to myself: they’ve hired an AI.
As for me, my routine has changed completely. When faced with a hacked website, I can no longer just ring a developer friend and cross my fingers - there have been too many incidents, too often, too quickly. So I’m doing what many people in my situation are starting to do: I ask an AI to help me understand what’s happened, to translate into plain language what a security report shows me in incomprehensible jargon, and to suggest a fix that I can then have validated, tested and deployed. It’s not me fixing the code - it’s me overseeing the fix, with an AI as my technical co-pilot.
There’s something quite dizzying about it all: one AI that’s probably, somewhere, helping to write the code that broke my websites, and another AI that’s helping me – someone who doesn’t really know how to code – to understand how to fix it. Caught between the two is me, a human, tossed about like a pinball, propelled from one bumper to the next with every new alert, trying to avoid going into tilt. I’m trying to steer my AI, but am I really the one calling the shots?
