Urgent.News

What's breaking now, across thousands of outlets.

AI

Security through obscurity is dead, and AI delivered the fatal blow

RIP, you won't be mourned

Security through obscurity is dead, and AI delivered the fatal blow

The outdated concept of security through obscurity has been rendered obsolete by the advent of artificial intelligence. Software developers and independent researchers are leveraging AI agents to uncover vulnerabilities in products and open source code, leading to an unprecedented surge in security disclosures and software patches.

Even long-believed-to-be secure libraries, running on 80% of web servers, have been proven susceptible to AI-driven attacks. Experts and researchers warn that the rise of AI-driven exploitation poses a significant threat to operational technology (OT) security and critical infrastructure, as attackers no longer require specialized expertise to exploit these systems.

AI can effectively reverse-engineer fixes and uncover exploits within a matter of hours, potentially bypassing the patch gap window for open source components. While this development may present additional challenges for system administrators and defenders, some experts argue that it signifies a positive shift away from the flawed notion of security through obscurity.

However, the effectiveness of AI-generated patches remains a concern, with recent studies indicating that more than half of AI-generated patches fail to address the vulnerabilities adequately.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in AI

Self-Hosted and On-Prem AI Code Review: What Actually Works for Enterprise Teams?

Hello Devs 👋 AI code review is getting pretty normal these days. You open a PR, an AI reviewer looks at the changes, and a few seconds later you have comments about bugs, security issues, missing…

  • Qodo's Agentic Toolbox integrates codebase context into AI coding agents like Claude Code and Codex.
  • Qodo, Greptile, and CodeRabbit are notable self-hosted AI code review options for enterprise teams.

More from Sunday 13 September →