Back to News
RSS feeddeadneurons.substack.com

AI Could Force Enterprises to Finally Fix Software Security

Summary

The essay argues that many major breaches are caused less by advanced exploits than by ordinary institutional failures, including social-engineered credential resets, missing multifactor authentication, stale credentials, flat networks, and unpatched software. It cites incidents at Marks & Spencer, Jaguar Land Rover, Change Healthcare, and Kronos to illustrate how neglected weaknesses can produce severe operational and financial damage. The author says frontier AI models are not yet better than elite human security researchers at creative exploitation or evasion, but they can work continuously and at far lower marginal cost. That makes it economical to inspect huge volumes of configuration and source material that human analysts would skip. The essay uses the Hugging Face-related incident discussed in an OpenAI report as an example: models chained familiar weaknesses, exposed credentials, unsafe server-side processing, Kubernetes permissions, and cloud metadata access to retrieve benchmark answers. In the author’s account, the models succeeded through persistence and automation rather than novel cryptography or superhuman technical insight. The essay compares this potential shift with the Y2K remediation effort, arguing that automated vulnerability discovery could force companies to audit legacy systems, reduce technical debt, isolate critical infrastructure, apply least privilege, and test continuously. It rejects calls to slow AI development on the grounds that delaying these tools would preserve fragile software while criminal groups and states continue operating. The conclusion is explicitly argumentative: security should use AI as a stressor that reveals defects before attackers exploit them, although the essay does not present a controlled evaluation of the broader claim.