Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Security Implementation Gap topic
No spam. Unsubscribe anytime.
FBI and Microsoft urge security-by-default as AI becomes 'tradecraft' for attackers
Summary
On the FBI podcast guests described Operation Winter SHIELD and Microsoft Threat Intelligence's finding that AI is becoming standard tradecraft for threat actors; both FBI and Microsoft urged implementing basic controls, vetting incident‑response partners and engaging developers to reduce the security implementation gap.
Get email alerts on the Security Implementation Gap topic
No spam. Unsubscribe anytime.
Brett Leatherman and guests on the FBI Cyber Division podcast said defenders should prioritize implementation of basic security controls and adopt "secure‑by‑default" settings as threat actors increasingly use artificial intelligence to scale attacks.
Maeve Healy, who manages the FBI’s Global Partnership Program and helped roll out Operation Winter SHIELD, said the campaign focuses on reducing the attack surface of home and small‑business routers, improving device lifecycle management and sharing clear recommendations for non‑technical users and small organizations. Healy noted the program is distributed through FBI field offices and forward‑deployed cyber assistant legal attachés (ALATs) to reach international and domestic partners.
Brett Leatherman summarized Microsoft Threat Intelligence’s March 6 blog "AI is Tradecraft," saying Microsoft observed attackers using generative AI to write phishing lures, translate content for global campaigns, summarize stolen data and assist in malware development. "For most actors, AI is functioning as a force multiplier," Leatherman said on the podcast.
Sherrod DeGrippo, Microsoft’s deputy chief information security officer, told the host that Microsoft’s telemetry (about 1.5 billion endpoints) shows defenders and law enforcement share overlapping priorities: tracking threat actors, prioritizing mitigation and sequencing disruption actions with industry partners. DeGrippo said the security problem is rarely a knowledge gap and is more often an execution and follow‑through problem: "We all know what to do; we just need to get on with it."
DeGrippo urged organizations to exercise incident‑response tabletops that include executives—C-suite, legal counsel and finance—so decision‑makers are familiar with the playbook before an incident. She advised creating an "AI bill of materials" listing models and agents in an environment, setting pre‑decided responses (patch, turn off, reconfigure) and engaging software developers in threat briefings to reduce vulnerabilities introduced by code and deployment practices.
Both guests stressed that AI amplifies speed and scale but does not fundamentally change common entry points: weak credentials, unpatched devices and misconfigured systems. The podcast recommended applying Winter SHIELD controls—basic hygiene, patching and device retirement planning—and engaging law enforcement early when incidents occur.
The episode closed with a reminder to consult the FBI Winter SHIELD resources at fbi.gov/wintershield and Sherrod DeGrippo’s Microsoft blog "The Security Implementation Gap: Why Microsoft Is Supporting Operation Winter Shield" for practical guidance.

