AI Cyberattacks. The Industry Gives Warning. WinMagic Gives the Fix.
As more than 150 technology, cybersecurity, and financial organizations warn of accelerating AI-enabled attacks, WinMagic CEO
The letter lists what has left systems exposed and ask for industry collaboration and higher security standards. Most of that list, including patching, tightening the permissions, fixing the misconfiguration, is hard work, but none of it addresses the foundational weakness: weak authentication. Those items matter, but we want to focus on the hardest one, and the one we believe we can fix. The industry has worked hard here too, from passwords to MFA and from MFA to passkeys, and attackers still get in: Proofpoint reported in
We see the shortcomings causing weak authentication as follows: the industry uses cryptography everywhere, the best technology for digital security, but it uses it in pieces, not end-to-end. As an example, authentication gives a verdict; it does not protect the data exchange that follows. Even though all data is encrypted, by the standard TLS protocol, for instance, the switch from the verdict to the data is a gap, and it is the weak link attackers, AI or not, exploit.
AI makes an attacker better at two things: producing deception a person will believe and finding the flaw in complicated machinery. We have seen increasingly sophisticated AI-based attacks recently. It can more successfully lure users into setting up the attack that is hardest to defend against: Adversary-in-the-Middle (AitM), where the attacker relays between the user and the real service, and both ends see a login that succeeded.
Yet a properly designed, cryptographically atomic operation, where the authentication produces the encryption key that protects the data, addresses the issue, and the AitM attack fails even if the lure succeeds.
WinMagic has the fix. We do need a bit of funding, tooling and coordination, and some fixes will need the applications' support. Let's start with the login, which is where these attacks aim.
Our login asks the user to notice nothing, and it is not assembled from separate pieces. It rests on cryptography: on a key that exists inside one endpoint's hardware and never leaves it. The "Live Key" represents the user, the device and local security policy all being met, and it disappears when those conditions stop holding. This login verifies user, device and conditions with no user action, and against cryptography, AI has no advantage.
"AI is very good at deceiving people and at finding flaws in complicated systems. It is not good at breaking cryptography," said
The mechanism is not new, and it is not ours. That atomic operation is mutual TLS, where both ends prove themselves, not just the server, and it has secured machine-to-machine authentication for decades. It never reached the ordinary login because it asked people to carry cards and handle certificates. What was missing was a client key that could stand for a person. We use the endpoint to apply that same machine-to-machine cryptography to users and get both stronger security and no user action.
The session token is another example of flawed applied cryptography: it is supposed to be difficult to copy. That is not cryptography, and we know it is not working well enough. Service providers and partners, we need you here. We can close the login; we cannot close what happens after it: the session between the user and the service, which the authentication server is no longer part of. What we need is for applications to speak mTLS with the endpoint and our Live Key. Parts of this are already public: the LIT project on GitHub carries a reference implementation of the Live Key and mTLS-based authentication on Windows (github.com/WinMagic/LIT), and we will provide further source code, under agreement, to partners who build with us. Then login and session collapse into one mTLS session, with no user action and no login prompt left for AI to attack. We are doing this in the open.
We published this in 2024, before AI made it urgent, see https://winmagic.com/en/blog/winmagic-discovered-a-flaw-in-tls-and-fido/ and "https://winmagic.com/en/blog/did-your-login-pass-or-fail/". Since then we have taken it where it belongs: a formal proposal to the W3C WebAppSec group in
If you want to examine what we have built, or build the session side with us, write to [email protected].
About WinMagic
WinMagic's mission is to secure the digital world through high standards and strong ethics. For nearly three decades, the organization has led innovation in encryption and endpoint security. Today, WinMagic is advancing a new paradigm for online access — anchoring the endpoint as the foundation of trust. By letting endpoints speak for users, WinMagic turns cumbersome logins into seamless, automated exchanges. What was once user-to-machine communication now becomes a machine-to-machine relationship, governed by policy and anchored in cryptography. This evolution eliminates friction, reduces risk, and lays the groundwork for the Secure Internet — where security is continuous, effortless, and requires no user action. Learn more at https://winmagic.com.
References
OpenAI. (2026). A Call for Collective Action on Cyber Defense. OpenAI.
openai.com/collective-cyberdefense/
WinMagic Discovered a Flaw in TLS and FIDO. WinMagic. winmagic.com/en/winmagic-discovered-a-flaw-in-tls-and-fido/
Nguyen-Huu, T. (2025). Did Your Login Pass or Fail? Understanding Risks. WinMagic. winmagic.com/en/did-your-login-pass-or-fail/
Nguyen-Huu, T. (2026, March 2). Formal Proposal: A Deterministic (No-Token) Alternative to DBSC. W3C public-webappsec archive. lists.w3.org/Archives/Public/public-webappsec/2026Mar/0000.html
Gardiner, M. (2024, December 30). Why MFA Is Good but Not Good Enough. Proofpoint. proofpoint.com/us/blog/identity-threat-defense/why-mfa-good-not-good-enough-need-defense-depth-combat-mfa-bypass
Media coverage of WinMagic and the Secure Internet. WinMagic Newsroom. winmagic.com/en/winmagic-newsroom/articles/
Live Identity in Transaction (LIT): Reference implementation of the Live Key and mTLS-based authentication on Windows by Winmagic. https://github.com/WinMagic/LIT
Media Inquiries
Karla Jo Helms
JOTO PR™
727-777-4629
jotopr.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/ai-cyberattacks-the-industry-gives-warning-winmagic-gives-the-fix-302867693.html
SOURCE WinMagic
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- USDT0 Goes Live on Stellar, Connecting Unified Dollar Liquidity to the World's Most Accessible Network
- Chatsworth Products (CPI) Joins Digital Realty Innovation Lab in London to Advance AI Infrastructure Validation
- Atlanta Metropolitan State College Generates Nearly $75 Million in Economic Impact
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share