Black Hat: MSFT Agentic Security Lead Says AI Is Making Critical Vulnerabilities Less Rare
Key Points
- At Black Hat, Microsoft's David Weston warned that AI is undermining the scarcity of critical software vulnerabilities, making advanced attacks cheaper, faster and more common.
- The keynote framed a central Black Hat theme: whether traditional detect-and-respond security can keep pace with AI-powered offensive capabilities.
- Weston argued defenders must shift from reacting to threats toward proactive measures such as memory-safe code and automated remediation to eliminate classes of vulnerabilities before they can be exploited.
Black Hat: MSFT Agentic Security Lead Says AI Is Making Critical Vulnerabilities Less Rare
For decades, cybersecurity has depended on the assumption that the vulnerabilities capable of breaking the most important security boundaries are relatively rare.
At Black Hat’s keynote speech on Wednesday, Microsoft’s lead of Agentic Security, David Weston, warned that AI is beginning to upend that scarcity model, making advanced attacks cheaper and critical vulnerabilities more common.
Weston introduced a theme that will likely shape upcoming Black Hat sessions this week: AI is pushing defenders to reconsider whether detect-and-respond remains a sustainable security strategy.
Security boundaries like networks, identity systems and encryption had traditionally upheld this scarcity principle, once making it extremely difficult for attackers to find vulnerabilities that compromise those boundaries.
"We use these boundaries to isolate our networks, to separate trust domains in places like the cloud, to create authentication, encryption, data protection policies, and ultimately to contain failures with things like hypervisors or process sandboxes. So, every control or policy in your enterprise, in your company, in your system, on your phone relies on these not being easy to undermine,” said Weston.
Traditionally, the scarcity principle meant that most critical breaches occurred above these boundaries, through access vectors like phishing or identity compromise. AI is now weakening that assumption and completely restructuring cybersecurity economics by making attacks cheaper, exposing more vulnerabilities within those boundaries and sharply increasing the volume and speed of high-severity flaws discovered and exploited in critical systems.
"We're seeing nine times the vulnerability volume that we were in March. We don’t know if this curve is going to hold true," said Weston. "But boy, if it changes, we're in deep trouble in the places where we presume vulnerabilities are scarce."
Unlike defenders, attackers are not constrained by policies or budgets, and AI will increasingly enable automated exploitation. As sophisticated attacks become cheaper and easier to execute while critical vulnerabilities become more common, defenders can no longer afford to respond to incidents only as they happen.
"[Attackers] maneuver on AI because you have policies, restrictions, auditing, compliance, and token costs that slow you down. But defenders have the exact same advantage. We don't want to go vuln-for-patch [with attackers]. We don't want to go exploit-for-detection, or evasion-for-detection. Hand-to-hand combat with attackers will cause us to lose in defense,” said Weston.
Despite this, Weston urged security practitioners to look at these variables optimistically, stating that despite attackers changing the economics of cybersecurity, defenders have the power to change the “physics” and gain greater control of the environment attackers have to operate within.
Weston highlighted memory-safe languages and automated remediation as examples of this proactive model. This approach will allow defenders to change the conditions of the game itself, rather than responding to each move individually.
"We know that prevention is key. So, we need to be able to reduce attack surface, improve the security posture and configuration, and ultimately shift less in the infrastructure side. The less that reaches production, the less that's reachable in production -- and that means there’s less for the attackers to go after."
IANS Faculty Recommendations
- Prioritize prevention: Reduce attack surface, adopt memory-safe technologies and automate remediation to eliminate vulnerabilities before they reach production.
- Prepare for more critical vulnerabilities: Strengthen risk-based vulnerability management and automation to keep pace with AI-driven increases in vulnerability discovery.
- Change the environment: Focus on hardening systems, configurations and security boundaries instead of responding one-for-one to every exploit or evasion technique.
Authors & Contributors
Emily Dempsey, Author - Security Reporter, IANS News
Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.