Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

Foundational AI labs are now offering 'red and blue agents' capable of autonomously hacking systems to find flaws. This directly threatens the business model of established vulnerability scanner companies like Tenable and Rapid7, forcing them to quickly integrate LLMs or risk being displaced by more effective, model-native solutions.

Related Insights

The security of software is increasingly determined by how much AI compute was spent trying to break it. Companies use diverse AI agents to autonomously attack their own code. The amount of money spent on APIs from labs like Anthropic to find vulnerabilities is becoming the best indicator of a system's robustness.

AI has armed cyber attackers with a new weapon: swarms of coding agents. Unlike human attackers, these agents can exhaustively and rapidly review an entire codebase to find vulnerabilities, dramatically increasing the speed and scale of cyber threats. This necessitates a boom in AI-powered defensive tools.

The plummeting cost of finding exploits via AI models means enterprises cannot simply patch vulnerabilities reactively. The necessary strategic shift is to build foundational security controls for each asset class, including a new, dedicated security layer specifically for the AI stack.

The same capabilities that make AI models powerful for writing code also make them exceptional at finding and exploiting vulnerabilities at a scale and speed no human "white hat" hacker can match.

While AI will increase cyber risk by enabling faster vulnerability scanning and generating potentially insecure code, it will also be the solution. AI agents will be needed to review code and defend systems, creating a massive new market for "agentic security" companies.

In recent competitions, Gray Swan's automated red teaming system, called "Shade," has become more effective than human experts at breaking models within a given timeframe. This signals a turning point where specialized AI is becoming the primary tool for finding security flaws in other AIs.

The traditional cybersecurity model of humans finding and patching vulnerabilities cannot keep pace with AI that discovers thousands of exploits in hours. This fundamental mismatch in speed and scale will require a complete overhaul of how software security is managed.

Previously, attackers spent weeks inside a system before striking. AI agents can now find and exploit vulnerabilities at machine speed, rendering traditional detection insufficient. The focus must now be on immediate recovery and resilience, assuming a breach has already occurred.

AI models like Mythos aren't just finding vulnerabilities; they are creating working exploits almost instantly. This forces security and engineering teams to abandon manual patching in favor of automated, machine-speed defense pipelines.

Human attackers often follow the path of least resistance, ignoring complex exploits. AI agents, however, will exhaustively test all possible paths to achieve an objective. This means a company's entire backlog of "P2" and long-tail vulnerabilities, previously risk-accepted, now becomes an immediate, exploitable attack surface.