キラスクリプトキディーズの攻撃
本文の状態
日本語全文を表示中
詳細モードで約18分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The Verge AI
DARPA主催のAIサイバーチャレンジで、主要なセキュリティチームが人工的な欠陥を注入した5400万行のコードからバグを検出するAIツールの実力を示した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
昨年の8月、業界を代表するいくつかのサイバーセキュリティチームがラスベガスに集結し、DARPA の人工知能サイバーチャレンジ(AIxCC)において、自社の AI バグ発見システムの強さを披露しました。これらのツールは、DARPA が人工的な欠陥を注入した実際のソフトウェアコード 5400 万行をスキャンしました。チームは十分な能力を持っており、人工的に仕込まれたバグのほとんどを特定しましたが、彼らの自動化されたツールはそれだけにとどまりませんでした — DARPA が意図して挿入しなかったバグも、12 件以上発見したのです。
今月、Anthropic が Claude Mythos と呼ばれる新しい AI モデルを通じてセキュリティ上の地震を引き起こす前であっても、自動化システムはコードの欠陥を発見する能力をますます高めていました。そして、AI がこれらの欠陥を検出できるだけでなく、それらを悪用するためにも使用可能となり、ハッキングスキルが世界中の誰もが手にできるようになるという懸念が高まっています。
「Mythos かどうかにかかわらず、これは避けられないのです」
これは空しい脅しではありません。何十年もの間、スクリプトキディ(無技能なハッカー)と呼ばれるこの種のハッカーは、インターネットから引き抜いたスクリプトや、エクスプロイトツールキットからコピーしたスクリプトを実行して大混乱を引き起こしてきました。彼らはこれらのスクリプトを完全に理解しておらず、自ら作成するための技術的な知識も持っていませんでした。それでもなお、ウェブサイトの改ざんやウイルスの拡散を行うことができていたのです。
現在起きていることは、技術的背景を持たない人々が AI を活用して、単純なスクリプトでは不可能だった方法で能力を強化できるという、重大なエスカレーションを表しています。これははるかに広範な影響をもたらす可能性が高いです。
「津波が押し寄せています。それが見えます。私たち全員が見ています」と語ったのは、セキュリティ企業 Trail of Bits の CEO 兼共同創設者である Dan Guido です。同社は今回のチャレンジで準優勝を果たしました。「あなたは横になって死を迎えるのか、それとも何か行動を起こすのか?」
画像:Joseph Rogers / The Verge
Project Glasswing を超えても、Anthropic は犯罪者による自社のソフトウェアの悪用を防ぐために努力を続けています。Mythos の発表から一週間後、同社は Claude Opus 4.7 をリリースしました。これは初めて、悪意のあるサイバーセキュリティ関連のリクエストをブロックするためのセーフガードが組み込まれたモデルです(防御目的でこのモデルを使用したいセキュリティ専門家は、同社の Cyber Verification Program に申請することができます)。
Anthropic の Mythos 発表は業界全体に衝撃を与えましたが、AI のサイバーセキュリティにおける能力に関する警告の兆候はそれ以前からありました。2025 年 6 月には、自律型攻撃セキュリティプラットフォーム XBOW が、バグ報奨金プラットフォームである HackerOne のリーダーボードで人間のエラーを凌駕し、トップに輝きました。これは AI モデルがバグを発見する能力において大きな飛躍があったことを示しています。
AIxCC が開催される頃には、「すでに 10 から 20 の異なるバグ発見システムが存在しており、私たちがパッチを適用できる数よりも桁違いに多くのバグを見つけられるようになっていた」と Guido は語っています。「これは実際、新しい問題ではありません。」
「2026 年はすべてのセキュリティ債務の返済期限となる年だ…2026 年は成否を分ける年である」
AI はパターンマッチングに優れており、既知のバグの変種やまだ発見されていないバグの変種を見つけることが、人々にとってますます容易になっています。また、エクスプロイト(攻撃コード)の作成も簡単になりつつあります。
「AI ツールを使用すれば、ごく限られた人間の指導、あるいは場合によっては全く人間の指導なしで、広く使用されているソフトウェアにおけるゼロデイ脆弱性を見出すことができます」と語るのは、Theori のシニアセキュリティリサーチャーである Tim Becker 氏です。同氏はまた、今回のコンペティションのファイナリストにも名を連ねています。
この懸念は業界全体に明確に感じられており、モデルの改善やその能力に対する理解の深化が、驚くほど速いスピードで進んでいます。
オープンウェイトモデル(学習済みのパラメータ、すなわち「重み」が一般公開されているモデル)もリスクをもたらします。実際、Becker 氏によると、高度な脅威アクターは、エクスプロイトが Anthropic や OpenAI のサーバー上で露出するのを防ぐため、自分たちでデプロイメントを実行する可能性の方がはるかに高いと述べています。なぜなら、Anthropic は データ abuse を監視するためにデータを保持する可能性がある からです。そして業界は、次に何が起きるかに向けて備えを始めています。他のモデル作成者が Anthropic のように慎重であるとは限らず、強力な新ツールをそのまま一般公開する可能性さえあります。
「神話かどうかにかかわらず、これは訪れるのです」と Guido は語ります。
Mythos はエクスプロイト作成において一段階上のレベルを意味しますが、現在のモデルも同様に能力を持っています。セキュリティ研究者たちはすでに、広く利用可能なモデルを用いて、実世界で悪用される前にベンダーに脆弱性を報告しています。つまり、抑圧的な政権に対するエクスプロイトを作成したり、自らの目的で機密データを窃取したりといった悪意のあるアクターがこれらを利用するリスクも存在します。
業界の専門家は、AI セキュリティ機能の進展により、より多くのエクスプロイトが発生すると予測しています。悪意のあるアクターは、AI に以前誰も手をつける価値を見出さなかったような、稀なソフトウェア内のバグを見つけるよう指示できる可能性があります。
「新しい 100 万行規模のコードベースに潜り込み、バグを発見するためのハードルは、かつてよりもはるかに低くなっています。」
「今や、努力は安価になったので、食物連鎖のより下位にあることを行えるようになりました。ある一社だけが持つソフトウェアに対する脆弱性攻撃コードを書くこともできますし、その一社が唯一採用している特定の構成を持つソフトウェアに対する攻撃コードも書くことができます。そして、それを即座に行うことも可能です。例えば、ある病院への侵入の最中に、目的とするものへの道に壁が立ちはだかった場合でも、LLM をその壁に向けて『ここに欠陥を見つけろ』と指示するだけで、成功するまで延々と試行錯誤を繰り返してくれます。そして、かつて誰も見たことのない弱点に対する脆弱性や構成を見つけて攻撃コードを実行し、ユーザー…つまりハッカー…あるいはスクリプトキディの側がほとんど努力することなくこれを実現します」と Guido は語りました。
彼は、これがスクリプトキディを強化すると述べています。なぜなら、彼らはランダムな UNIX ユーティリティの弱点を記憶するという制約から解放され、使用するツールの事前学習に依存して行動できるようになるからです。彼らは機械の速度で脆弱性を標的とした攻撃コードを反復実行することが可能になり、これは人間、ましてやスクリプトキディには到底できないことです。
これが攻撃者の能力を具体的にどの程度向上させているかを正確に判断するのは困難ですが、明らかに相関関係があるようです。セキュリティ研究者たちは、発見されているバグの規模を理解する手助けをしてくれます。
Becker が AI を用いた自動バグ発見に取り組む前に、彼は脆弱性調査に従事し、ゼロデイを発見してメンテナに報告していました。彼はかつて、新しいコードベースで高インパクトの脆弱性を発見するのに数週間から数ヶ月を要していたが、現在は数時間で済むようになったと述べています。
「AI バグ発見ツールにコードを投入するだけで、数時間後には候補となる多数の脆弱性を含むレポートが届きます。そのほとんどが有効であり、実際の問題であることが確認されます」と彼は言いました。「新しい百万行規模のコードベースに飛び込み、バグを見つけるためのハードルは、かつてよりもずっと低くなっています。」
自動化ツールの各リリースは、テキストから画像を生成するツールや、エクスプロイト開発・配信システムである Metasploit などのオープンソースツールにおいて、それがどのように悪用されるかという懸念を引き起こしてきました。このパニックはさらに 1995 年まで遡り、当時「セキュリティ管理者ネットワーク分析ツール(Security Administrator Tool for Analyzing Networks)」の略称として名付けられた無料ソフトウェア脆弱性スキャナである SATAN がリリースされた際にも発生しました。
「LLM をその壁に向けて『ここに欠陥を見つけろ』と指示するだけで、成功するまで延々と処理を続行できます。」
多くの場合、自動化ツールは、予防措置の導入や攻撃者による採用率の低さ、その他の要因により、予想または予測されたほどの混乱を引き起こすことはありません。
Security Superintelligence Labs の CTO かつ共同創設者である Joshua Saxe は、ブログ記事 wrote in a blog post で、脆弱性攻撃(エクスプロイト)そのものがサイバー攻撃を引き起こすわけではなく、AI を活用した脆弱性情報調査ツールの採用は漸進的であると述べています。
「何らかの新しい敵対的なツールが利用可能になると、すぐに犯罪者がそれらを利用するようになるという暗黙のメンタルモデルが存在しているようです。これは、人間が実際に何をしようとしているかについて、思考したり実証的な調査を行ったりする必要すらなく成立してしまうようなメンタルモデルです」と、彼は The Verge に語りました。
Saxe は、攻撃者側の様々な層が、既存のワークフローや組織文化の中でこれらのツールを採用する際に摩擦が生じる可能性があると指摘しています。「ここには人間と組織に関する要素がすべて含まれています」と彼は述べました。
「特定の攻撃者層がこれらの新しいツールに飛びつくこともあるでしょうし、採用曲線が非常に緩やかになる可能性もあります。一部の者はフィッシングや既に持っているエクスプロイトを使って依然としてネットワークへの侵入を続け、他の者はこれらのツールを用いて新たなエクスプロイトの開発を開始するかもしれません」
画像:Joseph Rogers / The Verge
採用の速度を予測することは不可能ですが、企業には到来する脆弱性情報報告の激増に備えるための対策がいくつかあります。
Luta Security の創設者兼 CEO であるケイティ・ムッソウリスは、セキュリティチーム向けのコンサートポスターとフェスティバル生存ガイドを掲載したブログ記事で「Vulnapalooza」という用語を考案し、これは企業が自社の脆弱な点を強化すべき時であると説明しました。企業に対するアドバイスは、標準的なベストプラクティスと変わりません:セグメンテーション(区画化)、アイデンティティ・アクセス管理の推進、メモリ安全コードの使用、フィッシング耐性認証の実装、および最新ソフトウェアの導入です。
クラウドセキュリティアライアンスは、「Mythos 対応」セキュリティ計画の策定に関する迅速な戦略ブリーフィングを発表しました。これにはこれらの概念の詳細が多数含まれています。同レポートでは、脆弱性の修正だけでなく、優先すべき脆弱性を特定する必要性も強調されています。しかし、機械速度の脅威に対応する必要性は新たな課題であり、バグ報告数はすでに急増しており、より多くのインシデントに備え、それらをより迅速に緩和・封じ込める必要性が生じています。
Moussouris氏は、サイバーセキュリティの役割にある多くの人がAIの効率化によって解雇されていると述べていますが、その効率性こそが、より多くの人間が関与し続ける必要がある理由だと指摘しています。企業は、新たな攻撃への襲来に対処するために、人間の脅威ハンター、脅威インテリジェンス担当官、インシデント対応チームを必要とするでしょう。また、どのパッチを優先して実装するかを決定する人材も必要となります。
「それらのタスクをすべて自動化するためのAIによる防御の同等物はまだ存在しませんし、私たちは人員を増員して多くの人材を採用する必要が出てくると思います」と彼女は述べています。さらに組織は、無限のパッチ適用のサイクルに陥らないために、ネットワーク用の安全なソフトウェアと安全なアーキテクチャ(architecture)を構築する必要があります。「まず第一に、より安全なソフトウェアを構築しなければなりません。インシデント対応だけでレジリエンス(resilience)を築くことはできないのです」。
人材採用の準備ができていない組織であっても、少なくともベンダーオンボーディングプロセスを合理化して、必要に応じて人員やサービスを迅速に導入できるようにすべきです。「攻撃を受けていてパッチ展開のペースについていけなくなっている時に、4ヶ月もの調達プロセスに縛られてしまうのは避けたいものです」とMoussouris氏は言います。
多くの人が脆弱性(vulnerability)を懸念する中、Moussouris氏は、いわゆる「バグ Apocalypse(vulnpocalypse)」は実際には「パッチ Apocalypse(patchpocalypse)」として現れると信じています。
「モデルはすでに数千の脆弱性を特定しており、この調整努力から来るパッチの津波が、最初の大きな痛みポイントになるでしょう」と彼女は述べています。
システムのパッチ適用が遅れている組織は、思いがけない衝撃を受ける可能性があります。脆弱性を AI によって発見されたサービスに対する攻撃や、モデル自身が作成したエクスプロイトを利用した攻撃に対して、対応が遅れることは大きなリスクとなります。
「脆弱性が公表されてからエクスプロイトコードが利用可能になるまでの時間が、ほぼゼロまで短縮されています。これは、リスク評価において人々が考慮しなければならない重大な変化であり、対策に要する時間や、この問題に対処するために投入すべきリソースの量にも影響を及ぼします」と彼女は説明しました。
AI を活用して、少なくとも修復または緩和プロセスを加速させる機会があります。ベッカー氏によると、Theori は商業ツール「Xint」を開発中で、オープンソースコードベース上で運用しています。コミュニティの強化プロジェクトとして、またツールの能力を実証するため、高深刻度の発見事項については手動でメンテナに詳細なレポートと修復提案を送付し、自費で報告を行っています。現在の Xint のバージョンは、同じコードベースをスキャンした際、Mythos が検出したすべてのバグを検出できることが確認されています [1]。さらに、Anthropic の発表に含まれていなかった 12 の追加のゼロデイ脆弱性も発見しました。
[1]: https://go.xint.io/xint-mythos-appsec-findings-report
しかし、これらのバグを緩和することは、それらを見つけるほど迅速にはなりません。なぜなら、パッチが見つかった問題に対する最善の解決策であるか、あるいは将来的にコードの保守性や理解しやすさを損なうものではないかを判断するには、コードベースに極めて精通したエンジニアが必要だからです。場合によっては、パッチは問題を解決する手段ではあるものの、最良の方法ではないこともあります。そのため、解決策を完成させるまでには人的な時間と労力が必要です。
報告されるバグの急増は、特に オープンソースのメンテナ にとってパッチ対応の長い待ち行列を生み出す可能性があります。彼らはこの負荷に追いつくことができないかもしれません。
攻撃者のツールキットにおいてすべてのバグが有用なわけではありませんが、どのバグを優先して修正すべきかを判断するために山積みのバグを整理することは、実際に修正することと同じくらい難しい場合があります。
「優先順位付けの多くは文脈に基づいて行われる必要があります」とムスーリス氏は述べています。例えば、外部からアクセスするのが困難な内部で動作している非常に深刻なバグよりも、企業の境界線上に露出しているそれほど重要ではないバグの方が優先度が高い可能性があります。
バグの優先順位付けに加えて、組織は機能制限を伴い、場合によってはダウンタイムを引き起こす可能性のあるパッチをいつ適用し、いつ待つべきかを決定する必要があります。セキュリティ対策が整っている数が少ないほど、パッチ適用にはより多くの時間が必要になります。
パッチを単に公開するだけでは、攻撃者がバグ修正の逆解析を行いやすくなり、まだ更新されていないデバイスにおいて、これまで気づいていなかった脆弱性を悪用されるリスクが高まります。つまり、セキュリティ欠陥に対する重要な修正が劇的に増加する中、消費者もソフトウェアの更新に慣れる必要があります。また、組織は最初から管理すべきパッチの量を最小限に抑えるために、セキュアなアーキテクチャへの投資を望むようになります。
「今がその時です。もう後戻りはできません。巨大な津波が押し寄せています。」
しかし、ムスーリス氏はこれを絶望する理由として捉える必要はないと述べています。「これが史上 worst の出来事だと扱う必要はありません」と彼女は *The Verge* に語りました。「これは、防御を強化し、これまで先送りしてきたことを行うための予算を獲得するための機会だと捉えるべきです。」
組織がどのような姿勢をとろうとも、準備は不可欠です。リスクはより高まり、スクリプトキディ(未熟なハッカー)でさえも脆弱性を発見して悪用する機会が大幅に増えています。企業は、AI を活用した新たな脅威に対処するための計画を策定する必要があります。
「2026 年は成否を決める年です」と Guido は述べています。「今こそシステムを保護し、まだ時間があるうちに先手を打つ必要があります。もしそうしなければ、2026 年の終わりにすべてが炎に包まれることになります。」
このストーリーのトピックや著者をフォローして、パーソナライズされたホームページフィードで類似の記事をもっと見たり、メール更新を受け取ったりしましょう。
- Yael Grauer
-
-
-
原文を表示
Last August, some of the best cybersecurity teams in the business gathered in Las Vegas to demonstrate the strength of their AI bug-finding systems at DARPA’s Artificial Intelligence Cyber Challenge (AIxCC). The tools had scanned 54 million lines of actual software code that DARPA had injected with artificial flaws. The teams were capable enough to identify most of the artificial bugs, but their automated tools went beyond that — they found more than a dozen bugs that DARPA hadn’t inserted at all.
Even before the security earthquake that Anthropic delivered this month with Claude Mythos — the new AI model that seems to find vulnerabilities in every piece of software it’s pointed at — automated systems were growing increasingly capable of finding coding flaws. And fears are growing that not only can AI detect these flaws, but also be used to exploit them, putting hacking skills into the hands of everyone across the planet.
“Mythos or not, this is coming.”
This isn’t an empty threat. For decades, this type of no-skill hacker, known as a script kiddie, has wreaked havoc, running scripts they ripped from the internet or copied from exploit tool kits. They didn’t fully understand or have the technical know-how to write these scripts themselves. And yet they were still able to deface websites and propagate viruses.
What’s happening now represents a major escalation, where people without technical backgrounds are able to use AI to enhance their capabilities in a way that wasn’t possible with simple scripts. It is likely to have far more wide-reaching repercussions.
“There’s a tidal wave coming. You can see it. We can all see it,” said Dan Guido, CEO and cofounder of cybersecurity firm Trail of Bits, which was a runner-up in the challenge. “Are you going to lay down and die, or are you going to do something about it?”
Image: Joseph Rogers / The Verge
Even beyond Project Glasswing, Anthropic is trying to prevent the misuse of its software by criminals. A week after announcing Mythos, the company released Claude Opus 4.7, which for the first time built in safeguards meant to block malicious cybersecurity requests. (Security professionals who want to use the model defensively can apply to the company’s Cyber Verification Program.)
Anthropic’s announcement of Mythos sent shockwaves throughout the industry, but there were warning signs of AI’s cybersecurity prowess prior to it. In June 2025, the autonomous offensive security platform XBOW beat out human hackers to top the leaderboard of HackerOne, a bug bounty platform, indicating big leaps in the ability of AI models to find bugs.
By the time AIxCC rolled around, “there were already 10 to 20 different bug-finding systems that could find orders of multitude more bugs than we could patch,” Guido said.“This is actually not a new problem.”
“2026 is the year when all security debt comes due… 2026 is the make-it-or-break-it year.”
AI is great at pattern matching, and it’s becoming easier and easier for people to find variants of bugs that are already known and ones that have not yet been discovered. And writing exploits is becoming easier as well.
“You can use AI tools and with very minimal human guidance, and in some cases no human guidance, find a zero day in widely used software,” said Tim Becker, senior security researcher at Theori, which was also a finalist in the competition.
The concern is palpable across the industry, and improvements to models — along with improved understanding of their capabilities — are happening at lightning speed.
Open-weight models, or models whose trained parameters (also known as weights) are publicly available, also pose risk. In fact, sophisticated threat actors would be far more likely to run their own deployments to prevent the exploits from being exposed on Anthropic or OpenAI servers, Becker said, as Anthropic may retain data to monitor abuse. And the industry is bracing for what may come next. Other model creators may not be as cautious as Anthropic, potentially unleashing their powerful new tools straight to the public.
“Mythos or not, this is coming,” Guido says.
Mythos represents a step up at writing exploits, but current models are capable, too. Security researchers are already using more widely available models to report vulnerabilities to vendors before they’re exploited in the wild. That means there’s also the risk of malicious actors using them for ill purposes, such as creating exploits for oppressive regimes or stealing sensitive data on their own.
Industry experts predict that the advancement in AI security capabilities is going to lead to a lot more exploits. Bad actors could direct AI to find bugs in uncommon pieces of software that no one previously would have put in the effort to exploit.
“The bar to diving into a new million-line codebase and finding a bug is so much lower than it used to be.”
“Now, because effort is cheap, you can do things that are lower down the food chain. You can write exploits for software that only one company has. You can write exploits for software that exists in only one configuration that one company has. And you can do it on the fly. So during the middle of an intrusion into some hospital and there’s a wall standing between you and what you want, you can just point an LLM at that wall and say, ‘Figure out a flaw here,’ and it can grind until it’s successful. And it’ll find some vulnerability, it can find some configuration, it’ll run an exploit, for a weakness that no one ever has before, and it’ll do it with almost no effort on the part of the user… the hacker… the script kiddie,” said Guido.
This supercharges script kiddies, he says, because they’ll be able to operate on their feet without the constraints of memorizing the weaknesses in random UNIX utilities but instead defaulting to the pretraining in the tool they are using. They’ll be able to iterate through exploits targeting weaknesses at machine speed, something that no human — let alone script kiddie — can do.
It’s hard to determine exactly how much this is improving attacker capabilities, though there definitely seems to be a correlation. Security researchers can help us try to wrap our heads around the scale of bugs being discovered.
Before Becker started working on automatic bug finding with AI, he worked on vulnerability research, finding zero days and reporting them to maintainers. He said it used to take him weeks or months to find a high-impact vulnerability in a brand-new codebase, and now it only takes hours.
“I just drop the code into our AI bug-finding tool and in a couple hours I get a report with a bunch of candidate vulnerabilities, and most of them end up checking out and being real issues,” he said. “The bar to diving into a new million-line codebase and finding a bug is so much lower than it used to be.”
Every release of an automated tool has led to some level of panic about how it might be exploited, whether that’s text-to-image generators or open-source tools like the exploit development and delivery system Metasploit. The panic even goes back to 1995, when a free software vulnerability scanner namedSATAN (an acronym for Security Administrator Tool for Analyzing Networks) was released.
“You can just point an LLM at that wall and say, ‘Figure out a flaw here,’ and it can grind until it’s successful.”
Often automated tools don’t lead to the same level of mayhem that had been expected or predicted, due to prevention measures put in place, low adoption rates by attackers, or other factors.
Joshua Saxe, CTO and cofounder of Security Superintelligence Labs, wrote in a blog post that exploits themselves don’t cause cyberattacks, and that adoption of AI vulnerability research tools has been incremental.
“There seems to be an implicit mental model where some new adversarial tool becomes available... and therefore we will immediately see criminal behavior with those tools. It’s a kind of mental model where you don’t even have to think about or do any empirical inquiry into what the humans are actually doing,” he told *The Verge*.
Saxe points out that it’s possible there’ll be friction in various attacker constituencies adopting these tools within their existing workflows and organization cultures.“There’s a whole human and organizational element here,” he said.
“It may be that there are certain attacker constituencies that are going to jump on these new tools, or it might be that the adoption curve is quite slow.” Some may keep breaking into networks by phishing or using exploits they already have, while others might begin developing new exploits using these tools.
Image: Joseph Rogers / The Verge
While the rate of adoption is impossible to predict, there are steps companies can take to prepare for the coming onslaught of vulnerability reports.
Katie Moussouris, founder and CEO of Luta Security, coined the term “Vulnapalooza” in a blog post complete with a concert poster and festival survival guide for security teams, explaining that this is the moment for companies to secure their weaker points. The advice for companies is not different from standard best practices: segmentation, working on identity and access management, using memory-safe code, and using phishing-resistant authentication and up-to-date software.
The Cloud Security Alliance released an expedited strategy briefing on developing a “Mythos-ready” security plan detailing many of these concepts. The report also emphasized the need to not only patch vulnerabilities but also to identify which ones to prioritize. But the need to match machine speed threats is new, and the amount of bug reports is already skyrocketing, leading to the need to prepare for more incidents and mitigate and contain them at a faster rate.
Moussouris says that many people in cybersecurity roles have been laid off because of AI’s efficiencies, even though those efficiencies are exactly why more humans need to remain in the mix. Companies will need human threat hunters, threat intelligence officers, and incident responders to deal with the onslaught of new exploits. And they’ll need people to decide which patches to prioritize and implement.
“We don’t have the AI defensive equivalent to automate all of those tasks, and I think we’re going to need to staff up and hire a lot of people,” she said. And organizations will need to build out secure software and secure architecture for networks to avoid ending up in an endless cycle of patching. “You have to build more secure software in the first place. We can’t incident respond our way to resilience.”
Organizations that aren’t ready to hire people could at least streamline their vendor onboarding processes to make it easier to bring on people or services as needed. “You don’t want to be stuck in a four-month procurement process for a vendor when you’re under fire and can’t keep up with the patch rollout,” Moussouris said.
While many are concerned about vulnerabilities, Moussouris believes the so-called “vulnpocalypse” will actually manifest as a “patchpocalypse.”
“The model has already identified thousands of vulnerabilities, and that patch tsunami that’s about to come from this coordination effort, that’s going to be the first major pain point,” she said.
Organizations that are slow to patch their systems may have a rude awakening. Waiting too long risks active attacks on services that target vulnerabilities found by AI, perhaps even using exploits written by the models.
“From the time a vulnerability is announced to the time where there is exploit code available has now shrunk to pretty much zero, and that is a major adjustment that I think people will have to take into account in their risk assessments and how long they can take to do things and how many resources they are applying towards this problem,” she explained.
There is an opportunity to use AI to at least speed up the remediation or mitigation process. Becker says that Theori is building a commercial tool called Xint that it’s been running on open-source codebases, manually reporting high-severity findings to maintainers by sending detailed reports along with remediation suggestions on its own dime, both as a community hardening project and to demonstrate the tool’s capabilities. Xint’s current version was able to find all the bugs Mythos did when scanning the same codebases. It also found 12 additional zero-day vulnerabilities that were not part of Anthropic’s announcement.
But mitigating these bugs will not be as quick as finding them because it requires engineers who are extremely familiar with the codebase to determine whether the patches are the best way to fix the issues found or whether they may make the code less maintainable or harder to understand in the future. Sometimes a patch represents a way to fix a problem, but not the best way, so it’ll take human time and effort to get the solutions to the finish line.
The huge surge in bugs being reported can lead to a long queue of things to patch, especially for open-source maintainers, who may be unable to keep up with the load.
While not all bugs are useful in an attacker’s tool kit, sorting through the pile to determine which ones are a priority to fix can be almost as difficult as fixing them.
“A lot of the prioritization needs to be contextual,” Moussouris said. For example, a very bad bug running internally that would be hard for an outsider to access might be lower priority than a less critical bug that is exposed on the company’s perimeter.
Beyond prioritization of bugs, organizations will also need to decide when to apply patches that restrict functionality and may even lead to downtime, and when to wait. The fewer security controls they have in place, the more time they will need for patching.
Simply putting out a patch makes it easier for attackers to reverse engineer the bug fix and exploit vulnerabilities they may have been otherwise unaware of on devices that have not yet been updated. That means that consumers, too, will need to get used to updating their software as critical fixes for security flaws increase dramatically. And organizations will want to invest in secure architecture to minimize the amount of patches they need to manage in the first place.
“The thing is, it’s now or never. There’s a tidal wave coming.”
But as Moussouris frames it, it doesn’t have to be a reason to despair. “You don’t have to treat it like this is going to be the worst thing that ever happened,” she told *The Verge*. “You can treat it like, this is our opportunity to shore up some defenses and get some budget to do things we’ve been putting off.”
Whatever attitude organizations take, they need to be prepared. The stakes are higher, and even script kiddies have a lot more opportunities to find and exploit vulnerabilities. Companies need a plan to deal with this new threat of AI-enabled attacks.
“2026 is the make-it-or-break-it year,” Guido said. Companies need to secure their systems now, while they still have time to get ahead. “And if they don’t do that, we’re going to end 2026 with everything on fire.”
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
- Yael Grauer
-
-
-
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み