TL;DR: Deception honeypots, AI-assisted ransomware, and typosquatting in AI coding pipelines are reshaping how attackers test, extort, and infiltrate environments, according to Sprocket Security’s interview with Armis Labs’ Andrew Grealy, with practical implications for detection and supply chain control. The security model now has to account for machine-speed abuse paths, not just known exploits and human-led intrusions.
NHIMG editorial — based on content published by Sprocket Security: an interview with Andrew Grealy of Armis Labs on deception honeypots, AI-powered ransomware, and supply chain compromise
By the numbers:
- 54% of generated code contains vulnerabilities when produced with AI coding assistants, according to the article’s cited takeaway.
- 1% of people in a large organisation may, a large organisation may be doing something serious, which can translate into thousands of leverage points.
Questions worth separating out
Q: How should security teams defend against AI-driven ransomware entry points?
A: They should combine non-phishable authentication, stronger email authentication, and continuous awareness training focused on realistic lures.
Q: Why do typosquatting attacks work so well in AI coding pipelines?
A: They work because developers and models both optimise for speed and similarity.
Q: What breaks when organisations rely on AI tools without governance in the software supply chain?
A: What breaks is the assumption that generated code and suggested dependencies are safe by default.
Practitioner guidance
- Map deception coverage to likely rehearsal environments Place honeypots and canary services in the places attackers are most likely to test stolen access, including small-business style infrastructure, internal build paths, and externally reachable decoys that resemble real services.
- Treat AI-generated code as untrusted until verified Require dependency pinning, package allowlisting, signature checks, and human review for any package suggested by AI coding assistants before it enters the build chain.
- Harden content stores against extortion mining Limit who can search and export large email, ticketing, and document repositories, and monitor for mass query patterns that indicate automated evidence gathering.
What's in the full article
Sprocket Security's full article covers the operational detail this post intentionally leaves for the source:
- The exact deception-honeypot approach used to surface attacker rehearsal patterns in local infrastructure.
- The interview’s specific examples of AI-driven ransomware extortion and how threat actors mine content for leverage.
- The package-infiltration patterns observed in AI-assisted coding workflows, including typosquatting and wrapper-based command and control.
- The full commentary from Andrew Grealy on how practitioners should think about early warning and continuous hunt activity.
AI-powered supply chain attacks and ransomware: what teams should do?
Explore further
AI-assisted abuse is now a governance problem, not just a tooling problem. The interview shows attackers using AI to scale ransomware, search sensitive content, and exploit dependency trust faster than conventional review cycles can keep up. That creates a governance gap between what security teams believe automation is doing and what it is actually enabling. For identity programmes, the lesson is that machine-speed decision paths need explicit controls, not inherited trust.
A question worth separating out:
Q: How can organisations tell whether deception testing is actually improving detection?
A: They should look for earlier visibility into attacker rehearsal, faster detection of suspicious credential use, and more frequent discovery of new tradecraft before it reaches production. The goal is not more alerts, but better timing and higher-confidence signals that map to real abuse patterns.
👉 Read our full editorial: AI-powered supply chain and ransomware threats are changing cyber risk