The advantage might just be shifting
Updated: Aug 15
For quite some time, much of the discussion around AI and cybersecurity has focused on the risks.
What happens when attackers use AI to find vulnerabilities faster? My previous post on Claude Mythos focused on exactly that. What happens when cybercriminals automate vulnerability discovery and exploit development? It’s the stuff of nightmares.
After listening to a recent Security Now! podcast (#1080 if you’re interested), I found myself coming to a far more optimistic conclusion.
Those very same AI capabilities that can identify software vulnerabilities can also be used by software developers before products are released.
Mozilla recently reported using an early version of Mythos to identify and remediate hundreds of previously undiscovered vulnerabilities within Firefox. The vulnerabilities weren’t created by AI. They already existed. Mythos simply helped find them and fix them pretty quickly too.
The idea of a cyber arms race is nothing new, but this feels like a fairly significant shift. While threat actors might have access to increasingly powerful AI tools for identifying and exploiting vulnerabilities, software development teams can use those very same tools as part of their quality assurance and security processes.
By doing this, they have the opportunity to address decades of accumulated security debt and ensure that future product releases are subjected to levels of scrutiny that was previously impossible.
For the first time, software development teams have access to AI tools capable of reviewing code at a scale and speed that no human team could realistically achieve. Vulnerabilities that might have remained hidden for years can now be identified and fixed before customers ever see them.
The long-term outcome may be that AI doesn’t make software less secure, it may very well make software more secure than it’s ever been.
Perhaps the most important question is no longer “How will attackers use AI?” but rather “How quickly can defenders embed AI into the software development lifecycle?”
The organisations that are able to seize that opportunity may significantly reduce the attack surface before their software ever leaves the building.
There you go. An optimistic perspective on AI and cybersecurity and one that I think is worth reflecting on. Have a nice week!


Comments