Get the latest tech news

Cisco: Fine-tuned LLMs are now threat multipliers—22x more likely to go rogue


Cisco warns LLMs fine-tuned for business are now being weaponized. Guardrails aren't failing. They're being engineered around.

Source: Cisco State of AI Security 2025, p. 9.Unlike mainstream models with built-in safety features, these LLMs are pre-configured for offensive operations and offer APIs, updates, and dashboards that are indistinguishable from commercial SaaS products. That’s the takeaway from Cisco’s joint research with Google, ETH Zurich and Nvidia, which shows how easily adversaries can inject malicious data into the world’s most widely used open-source training sets. CISOs and security leaders need real-time visibility across the entire IT estate, stronger adversarial testing, and a more streamlined tech stack to keep up – and a new recognition that LLMs and models are an attack surface that becomes more vulnerable with greater fine-tuning.

Get the Android app

Or read this on Venture Beat

Read more on:

Photo of Cisco

Cisco

Photo of threat

threat

Photo of rogue

rogue

Related news:

News photo

Cisco warns of CSLU backdoor admin account used in attacks

News photo

The threat of US–centric social media

News photo

Cisco IOS XR vulnerability lets attackers crash BGP on routers