AI-powered vulnerability detection will make things worse, not better, former US cyber official warns
Cybersecurity professionals shouldn’t be too quick to celebrate AI’s ability to find software vulnerabilities, because finding the flaws is only part of the problem, a former top U.S. government cyber official said on Monday.
“Some set of folks will say, ‘That’s wonderful, we’re going to have LLMs scanning all of our software and finding bugs at scale and patching it before the bad guys can get leverage,’” Rob Joyce, who served as President Donald Trump’s top cyber adviser during his first term, said at Google’s Cyber Defense Summit in Washington. “Well, the problem with that theory is, we suck at patching.”
Google and other big tech companies may be able to quickly triage and patch the flaws that AI identifies, “but there’s so much technology in our ecosystem now that’s either unsupported or legacy or doesn’t have the person who can install a patch,” said Joyce, who held top roles at the National Security Agency, including head of its Cybersecurity Directorate and chief of its elite Tailored Access Operations hacking unit.
Read more at Cybersecurity Dive