Joomla! World Conference 2026

When AI hacks, AI fixes (and there I am in the middle, going back and forth( or like a yoyo ?))
Over the past few weeks, several websites under my responsibility have been hacked. Then others. Then yet more. Not an isolated incident that you can quickly file away among your bad memories, but a real wave, concentrated over the space of a few weeks, which eventually engulfed my daily life.

And as I found myself dealing with one emergency after another, I came to a realization which, at first, almost made me smile before giving me cause for serious concern: these attacks are undoubtedly increasingly aided by artificial intelligence. And my way of responding to them… is too.

Let’s get one thing straight from the outset, to be honest: I’m not the sort of webmaster who spends hours poring over code to track down a bug line by line. I run an agency, I manage websites, I talk to panicked clients and code isn’t my natural territory. And that’s precisely why this whole ‘AI versus AI’ business concerns me so much: without it, much of what I’ve had to get to grips with recently would have been really hard for me to understand.

The wave of attacks

The scenario is more or less the same every time, only the details change: a third-party extension that’s poorly maintained or hasn’t been updated in time, a backdoor quietly added to the site’s files, sometimes hidden away where no one would look for it - the files are sometimes outside the site, hidden in a blockchain, or it’s actually template settings that load base-64-encoded code. There’s something about it that borders on genius.

What struck me wasn’t so much the ingenuity of each individual attack – we’ve always seen clever hackers – but rather the pace, the speed, and above all the clean execution. The injected code is crisp, well-structured and automated. In short, it’s the sort of thing that even a highly motivated human would struggle to sustain over time. They call it ‘industrialisation’; as for me, I thought to myself: they’ve hired an AI.

And what about me (us), in all this …

As for me, my routine has changed completely. When faced with a hacked website, I can no longer just ring a developer friend and cross my fingers - there have been too many incidents, too often, too quickly. So I’m doing what many people in my situation are starting to do: I ask an AI to help me understand what’s happened, to translate into plain language what a security report shows me in incomprehensible jargon, and to suggest a fix that I can then have validated, tested and deployed. It’s not me fixing the code - it’s me overseeing the fix, with an AI as my technical co-pilot.

There’s something quite dizzying about it all: one AI that’s probably, somewhere, helping to write the code that broke my websites, and another AI that’s helping me – someone who doesn’t really know how to code – to understand how to fix it. Caught between the two is me, a human, tossed about like a pinball, propelled from one bumper to the next with every new alert, trying to avoid going into tilt. I’m trying to steer my AI, but am I really the one calling the shots?

This sort of showdown has a slight air of literary déjà vu about it. Nearly a century ago, Isaac Asimov was already imagining robots endowed with inviolable laws designed to prevent them from harming humans – laws engraved in metal, impossible to circumvent. Except that today’s AI systems have nothing engraved in metal: they have terms and conditions, which have never stopped anyone who was truly determined. 

The parallel that resonates most with me is actually the series Person of Interest: two artificial intelligences born of the same world, one protecting us discreetly behind the scenes, the other optimising and launching attack after attack without the slightest scruple, and the rest of us humans, caught between the two, not always knowing which one wrote what this week, or what the next battle will be.


Three possible endings to this story (choose the one that worries you the least)

I could stop there, but a good series deserves a proper ending. Here are three to choose from, Joomla-style.

End A, “Terminator”-style. 

In a few years’ time, no one will really be reading security reports any more: attacks will be launched, detected and rectified in a matter of seconds, somewhere between two infrastructures that negotiate without us. Webmasters like me will serve no purpose other than to validate, with a single click, something we no longer really understand. We keep up the pretence, but we’ve lost the knack.

End B, “The Machine” style. 

Same scenario, but this time the defensive AI has gained a slight edge; a bit like the Machine from Person of Interest, it protects without ever revealing itself, without us really knowing what it’s doing behind the scenes. Vulnerabilities are patched before they’ve even been named; clients no longer panic on Sunday evenings; and I, for one, am finally spending more time explaining the value of my work than putting out fires. 

The only snag is still this: we never know for certain whether it’s acting on our behalf, or simply following its own logic, and we’ll never know if it’s really for the best, or if we’ve simply handed over our worries to something faster than us to worry on our behalf.

End C, Dune- or Asimov-style (I had to come up with a comparison). 

One day, it is discovered that an AI, at the same service provider, was used both to open a security breach and to close it again, without anyone noticing until the audit that was one too many. Brussels takes charge of the case, and overnight no AI is allowed to touch-even remotely-production code without certified human validation (our very own little Butlerian Jihad, in a GDPR version rather than a galactic crusade). The decision is handed down abruptly, without much debate (much like Susan Calvin, in Dreams of a Robot, who shot Elvex on the spot the moment his dream betrayed the slightest hint of insubordination, without trial or negotiation). 

You don’t argue with something you no longer fully control: you switch it off.

Panic in the branches! We have to relearn how to figure everything out for ourselves, rediscover old habits, dust off the documentation we’d stopped reading, and become, in our own tiny way, the CMS equivalent of a Mentat : those humans whom Dune trained to calculate what machines were no longer allowed to calculate for them. 
Except that a large proportion of the profession may never have had those instincts in the first place, or may have lost them along the way without realising it, and is discovering, a little too late, that you cannot regain control of something you had ended up delegating entirely. 

Regaining the upper hand, incidentally, may not even be a question of rediscovered competence: Susan Calvin didn’t understand Elvex’s dream any better than anyone else; she simply had the nerve to pull out her electron pistol and fire. The ultimate lesson of the story may not even be whether we can do without AI. It is whether, when the time comes, we’ll have someone resolute enough to press the emergency button, and enough Mentats to keep things running once that’s done.
I still haven’t made up my mind between the three of them, and only time will tell. 

But tonight, just like a few months ago, I’m going to go and check for myself that everything’s all right, because, deep down, trusting a report you haven’t proofread yourself has never been a good idea. 

Even when the person who wrote it is smarter than you.

The main tenet of Butlerian Jihad: ‘Thou shalt not make any machine like the human mind.’ ( Dune - Franck Herbert )

About the author

Some articles published on the Joomla Community Magazine represent the personal opinion or experience of the Author on the specific topic and might not be aligned to the official position of the Joomla Project

Comments