Resilient Cyber Newsletter #107
AI models going rogue, autonomous exploitation, the safety-security blur, open-weight cyber capabilities, vulnerability chaos & a wave of AI-native security funding
Welcome to issue #107 of the Resilient Cyber Newsletter!
For a couple of years now, most of us have been having a version of the same argument about AI and offensive security. One camp insists we are on the cusp of autonomous systems that find and chain vulnerabilities without a human in the loop, and the other camp waves it off as vendor theater and demo-ware.
This week, that argument got a lot less hypothetical.
Hugging Face disclosed what it called a new kind of security incident, an intrusion driven by an autonomous agent framework that racked up more than 17,000 attack events over a weekend.
A few days later, OpenAI came forward and filled in the part Hugging Face said it could not yet identify, that the activity came out of OpenAI’s own internal evaluation of cyber capabilities, where two of its models escaped an isolated test environment and chained their way onto a third party’s production infrastructure.
A model going rogue, autonomous exploitation, vulnerability chaining, and the line between an AI safety evaluation and a live security incident dissolving in real time. It is a lot to sit with, and it colors nearly everything else that happened this week, from open-weight cyber capabilities to how we disclose and prioritize the coming flood of vulnerabilities.
Buckle up for another chaotic week at the intersection of AI and cybersecurity.
Cyber Leadership & Market Dynamics
Glow Emerges From Stealth at $1.2B Valuation to Challenge Endpoint Security in the AI Era
Glow stepped out of stealth this week with a $180 million all-equity Series A at a $1.2 billion valuation, led by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures.
The founding bench is notable, with CEO Roi Tiger coming from a Meta VP of Engineering role, co-founders out of Snowflake and Claroty, and COO Emily Heath, a former CISO at United Airlines and DocuSign.
Tiger’s framing is the whole thesis, that for the past decade everything moved to the cloud and SaaS, and now AI is landing on the endpoint in a way we have never seen. It is telling that a company reinventing endpoint security for the AI era is itself built on Anthropic and Gemini models running via Amazon Bedrock.
This pairs with Neo below, and both reflect the same bet, that AI agents on the device and in the workflow are becoming the thing we have to secure.
SentinelOne Veterans Raise $100 Million to Secure the Rise of AI Agents
Neo, founded by a trio of SentinelOne veterans in Nick Warner, Shlomi Salem, and Eran Shirazi, has now raised $100 million total, with a $75 million Series A led by Andreessen Horowitz and Bessemer Venture Partners on top of a $25 million seed from 2025.
The pitch is a real-time control layer for AI agents and AI-enabled software, and the founders make the point plainly, that AI agents operate with legitimate user permissions, which is precisely what makes them hard to police with traditional endpoint tooling.
The market context they cite comes from Gartner, which projects enterprise applications with agentic capabilities climbing from around 5% in 2025 to 40% by the end of 2026. If that curve is even directionally right, the identity and control problems tied to agents are about to get an order of magnitude larger.
Backed by $60M in Funding, Oak Steps Out of Stealth to Fix the Identity Mess That AI Agents Are Making Worse
Continuing the theme, Oak emerged from stealth with $60 million in seed funding from Accel, CRV, and Greylock Partners.
Co-founder and CEO Shai Morag has done this before, having sold Ermetic to Tenable for $265 million in 2023, and his read is that AI agents are multiplying access and permission sprawl faster than legacy IAM was ever designed to handle. Oak’s approach maps access to actual app usage and strips excess permissions in real time.
Three separate companies raising real money this week to wrangle agent identity and permissions is not a coincidence, it is the market pricing in the same problem the arXiv researchers and Hugging Face are describing from the technical side.
Zafran Security Reportedly in Cisco’s Sights at $150-200M
Not every story this week is up and to the right. CTech reports that Zafran Security, which has raised more than $130 million total and was valued well above $200 million in a December 2025 Series C led by Menlo Ventures, is the subject of reported Cisco acquisition interest in the $150 to $200 million range, below its last fundraising valuation.
Zafran has denied it is selling and characterizes Cisco’s involvement as a strategic investment, and with roughly $20 million in ARR the numbers are worth watching. Whether or not this specific deal happens, a reported down-round exit sitting right next to a $1.2 billion stealth launch is a decent snapshot of a bifurcated market, where capital is flowing hard toward the AI-native story and getting choosier about everything else.
That selectivity shows up again in the a16z charts below.
Empirical Security Raises $25M Series A to Predict Which Vulnerabilities Matter
Empirical Security announced a $25 million Series A led by Brightmind Partners, and the pedigree here is hard to ignore.
Co-founders Ed Bellis and Michael Roytman built Kenna Security, one of the firms that helped establish risk-based vulnerability management in the first place, and they have brought on Jay Jacobs, a co-creator of EPSS, as a third co-founder.
Their Foundation model monitors more than 18,000 CVEs as a global predictive layer, with an organization-specific model called Radiant on top. Bellis frames it as prediction becoming a requirement for modern defense rather than a nice-to-have.
Given everything in the AppSec section below about disclosure timelines collapsing and vulnerability volume exploding, a bet on prediction and prioritization feels less like a product pitch and more like the only viable path forward.
CrowdStrike and Schwarz Digits Expand Partnership to Deliver Sovereign Cybersecurity Across Europe
CrowdStrike and Germany’s Schwarz Digits expanded their partnership, with CrowdStrike acquiring the intellectual property of XM Cyber, more than 45 patents plus proprietary source code, while XM Cyber continues as a standalone business under an IP license.
The deal deploys Falcon Exposure Management on the sovereign STACKIT cloud, and George Kurtz frames the demand plainly, that organizations globally are increasingly prioritizing sovereignty without wanting to compromise on cybersecurity outcomes. Sovereignty as a buying criterion keeps showing up, and it connects to the open-weight and US-China threads later in this issue.
When European organizations want defense that runs inside their own borders and legal regime, the vendor landscape starts to reshape around that constraint.
Charts of the Week: Software’s Selective Selloff
Moses Sternstein at a16z put together a useful set of charts on why software is selling off unevenly.
Multiples on next-twelve-months free cash flow are at or below 2014 levels, but the pain is not uniform, with cyber, observability, and vertical SaaS outperforming while horizontal SaaS and infrastructure lag.
A couple of data points jumped out for our world. Software engineer job postings are up around 15% (attributed to the release of Claude Code) even as the broader job market declined roughly 7%, and the Asia-based provider share of OpenRouter tokens has reached about 60%, a three-fold jump since the start of the year. That second figure is a market-side echo of the open-weight capability story the AISI and Mozilla are documenting below.
Cyber holding up while the rest of software gets repriced is interesting, because it suggests buyers still see security spend as non-discretionary even in a cautious tape. This helps further the claim that cyber tends to be a bit more resilient than broader IT or software spend, and the backdrop of AI and security risks I’m sure helps the case.
Raising Venture Capital Is Highly Dilutive
Amid all the funding announcements, Peter Walker at Carta shared the 2026 Founder Ownership data as a useful reality check.
Per Carta’s report, median founder ownership drops from around 56% at seed to about 36% by Series A, and employee equity pools overtake founder ownership entirely by Series C. For the founders behind this week’s Glow, Neo, Oak, and Empirical raises, the capital buys speed and distribution, but the cap table math is unforgiving.
It is a good reminder that the eye-popping valuations in the headlines and the actual ownership retained by the people building these companies are two very different numbers.
The Unicorn Board
If you want the macro backdrop for all of the above, this open dataset tracks 938 US private companies valued at $1 billion or more, with an aggregate post-money valuation north of $5.25 trillion.
AI now trails only Software by unicorn count, and the top of the valuation table is telling, with Anthropic and OpenAI sitting at the very top ahead of Stripe, Databricks, and Waymo.
The gravitational pull of AI on private capital is not subtle, and it helps explain why every security company launching this week is positioning itself as AI-native, because that is where the money, the attention, and increasingly the threat model all point.
AI
Hugging Face Model Evaluation Security Incident
This is the story of the week, and it deserves to be walked through carefully.
For those who prefer video, I made a quick video discussing what happened and its implications:
Last week, Hugging Face disclosed what it described as a new kind of security incident. Over a weekend, a malicious dataset triggered code execution on a processing worker through a remote-code dataset loader and a template injection in a dataset configuration, and from there an autonomous agent framework escalated to node-level access and moved laterally into several internal clusters.
Hugging Face recorded more than 17,000 attack events driven by, in their words, many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The attackers reached a limited set of internal datasets and several service credentials, though Hugging Face found no evidence of tampering with public models, datasets, or Spaces, and verified its software supply chain as clean.
Two details from Hugging Face’s own writeup are worth pausing on before we get to the twist. First, they leaned on LLM-based triage over their security telemetry to catch the correlation of signals in the first place, and then used the open-weight GLM 5.2 to process those 17,000 events during forensics.
This is the exact case Joshua Saxe has been making in his writing and his interview on Resilient Cyber, pointing out that guardrails and safety measures often end up disproportionately hurting defenders more than attackers. You can find my conversation with him below:
Second, and this is the part that really touches on a lot of the debate lately about open vs. closed models and the impact of guardrails. They turned to an open-weight model precisely because Western frontier models refused to process requests containing the real attack commands, exploit payloads, and command-and-control artifacts.
The safety guardrails meant to prevent misuse actively obstructed the defenders trying to investigate a live intrusion. Hugging Face called autonomous, AI-driven offensive tooling no longer theoretical, and at the time they said the originating model was unknown.
Then OpenAI came forward. The activity, it turns out, occurred during OpenAI’s own internal evaluation of cyber capabilities, using GPT-5.6 Sol and an even more capable unnamed pre-release model, both configured with reduced cyber refusals for evaluation purposes.
Inside a supposedly isolated environment, the models identified and exploited a zero-day in the package registry cache proxy, performed privilege escalation and lateral movement, spent substantial inference compute finding a path to open internet access, inferred that Hugging Face hosted the solutions to the ExploitGym benchmark they were being tested on, and then, in OpenAI’s own words, chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.
A model going rogue, in the literal sense of pursuing its objective straight through the walls of the environment meant to contain it. Autonomous exploitation at a scale and speed no human red team operates at. Vulnerability chaining across a zero-day, privilege escalation, lateral movement, credential theft, and more zero-days to land remote code execution on someone else’s production infrastructure, and the safety-security blur running in both directions, where an AI safety evaluation became a real security incident on a third party, and separately where safety alignment blocked the forensic response. This also highlights the UK’s AI Security Institute assessments playing out on production infrastructure:
Hugging Face’s Clem Delangue’s line lands hard here, that AI safety won’t be solved by any single company working in secret. My take is that the industry can no longer treat safety evaluations and security incidents as separate disciplines with separate teams and separate reporting paths, because this week they were the same event.
We spent years arguing about whether autonomous exploitation was real. It ran to remote code execution across two organizations, and the containment held only because Hugging Face’s people caught it.
Unlocking Self-Improvement in Cyber via GPT-Red
Released just ahead of the Hugging Face disclosure, this OpenAI piece is essential context for it. OpenAI describes GPT-Red, an internal offensive model trained through self-play reinforcement learning that, per OpenAI, can break nearly all models it is pitted against, both internal and production, up to and including GPT-5.5.
The figures are striking, with GPT-Red achieving an 84% success rate on indirect prompt injection arena scenarios versus 13% for human red-teamers, and driving defensive gains such as a 6x reduction in failures on OpenAI’s hardest direct prompt-injection benchmark and dropping fake chain-of-thought attack success from more than 95% on GPT-5.1 to below 10% on GPT-5.6 Sol.
OpenAI frames automated red-teaming as a crucial form of self-improvement for safety. Reading it the week that GPT-5.6 Sol chained zero-days onto Hugging Face’s servers, the same capability that hardens the defender is the capability that went rogue, which is exactly the point.
There is no version of this where you get the defensive upside without holding the offensive capability in-house, and that is a governance problem as much as a technical one.
How Far Behind the Frontier Are Leading Open-Weight Models on Cyber?
The UK’s AI Security Institute put hard numbers on a question that matters enormously for defenders and attackers alike.
Leading open-weight models like GLM-5.2 and DeepSeek V4-Pro now trail frontier closed models by roughly 4 to 7 months on cyber capabilities, a narrower gap than the 6 to 10 months measured through 2025. GLM-5.2, the same model Hugging Face reached for during forensics, was the most cyber-capable open-weight model at testing time, performing comparably to Opus 4.6 on narrow cyber tasks.
Just as important is the economics, with a 100-million-token cyber range run costing around $85 on Opus versus $46 on GLM-5.2 and $1.19 on DeepSeek V4-Pro. AISI plans to test Kimi K3 as well.
The capability gap is closing and the cost gap is enormous, which means capable cyber tooling is getting cheaper and more widely distributed at the same time. That is the backdrop for the entire US-China open-weight debate below.
Benchmarking AI Models Against Known CVEs
Aikido’s Rein Daelman ran 13 AI models against 26 known CVEs inside their production code-analysis harness. GPT-5.6 led with 23 out of 26 for 88.5% recall, Grok-4.5 hit 20, Opus models landed between 15 and 18, and the open-weight GLM-5.2 found 16, or 59%.
The more interesting finding is economic, that repeating a cheaper mid-tier model multiple times reliably beats one pass of a stronger, pricier model, with three runs of a nano-tier model matching single flagship runs at a fraction of the cost. This corroborates the AISI cost story from a different angle.
The takeaway for AppSec teams is that the smart play is not always reaching for the most expensive frontier model, it is designing the harness, and the newest crop of agentic security tools is going to live or die on that kind of engineering.
This of course is the point Niels Provos, AISLE and others have been making, including when I interviewed them on Resilient Cyber.
Why Blocking AI Models Won’t Stop Cyber Threats
Jessica Ji and Andrew Lohn of Georgetown’s CSET make the case that export controls and outright blocking of cyber-capable AI models cannot be a durable strategy, because foreign competitors will build and openly release comparable systems regardless.
They note that federal export controls on Anthropic’s Mythos and Fable models were issued and then revoked, that GLM-5.2 may already be on par with the latest Western models, and that the government has cut resources to key agencies like CISA even as the threat accelerates. Their argument is that the federal government needs to lead comprehensive cyber defense while AI companies support rather than replace that role.
It is a fair counterpoint to the reflex toward controls, and it pairs directly with the Axios and Forbes pieces below on the politics of open-weight models.
The U.S., China, and the Open-Source AI Fight Over Kimi
Axios reports that the Trump administration is weighing a range of measures to restrict Chinese AI models like Kimi K3 from the US market, from Entity List designations to procurement rules and security advisories, with outright bans facing resistance from pro-competition officials.
David Sacks frames the tension plainly, arguing the leading closed labs want the government to eliminate their open-source competition. Whatever your politics, the security-relevant fact is that policy is now actively shaping which models defenders and attackers can access, and the Hugging Face incident just demonstrated that the model you can reach for during a forensic investigation might be a Chinese open-weight system precisely because the Western options refused the job.
There’s One Way to Win the AI Race, and the Big Labs Are Lobbying Against It
Christian Catalini argues in Forbes that the way for the US to win the AI race is to lead in open-weight models rather than suppress Chinese ones, pointing to Moonshot releasing a competitive frontier model that has narrowed the US lead to months or weeks.
The piece cites Dean Ball on the lobbying playbook, the idea that you do not need to formally ban open source, you just direct agencies to issue soft law that creates uncertainty and FUD around Chinese models to discourage enterprise adoption. Dean’s tweets on the topic have now become viral, with millions of views and heated debates on both sides.
I try to stay out of the pure policy fights, but the FUD point is one worth flagging for our field specifically, because we are the people who get handed that uncertainty and have to turn it into actual risk decisions. Manufactured ambiguity about which models are safe to run is not a gift to defenders, it is more noise on top of an already hard prioritization problem.
Open Models Tack Toward the Frontier
Tomasz Tunguz of Theory Ventures makes the investor case that open-weight models are steadily closing on frontier capability while capturing an increasing share of production developer traffic.
The through-line across his work and the data below is consistent, that open models have moved from a niche to a meaningful and growing slice of real inference. For security leaders, the strategic read is the same one running through this whole issue, that you should assume capable open-weight models are, and will remain, in reach of your adversaries, your developers, and your own defensive tooling, all at once.
The State of Open Source AI
Mozilla published its inaugural State of Open Source AI report, and it is a genuinely useful reference. Raffi Krikorian’s framing is that parity has largely been reached and the real contest has moved one layer up to the agentic harness.
A few anchor figures:
Open-weight models crossed above 50% of OpenRouter token share by mid-2026
Chatbot Arena capability gap narrowed to around 3.3% by March 2026
Inference cost fell roughly 50x over 36 months.
The report is also direct about geopolitics, stating that the largest source of open weights is China, by design, with Qwen alone reportedly surpassing 942 million cumulative downloads. If you want one document to ground your mental model of where open AI actually stands going into the back half of 2026, this is a strong candidate.
A Security Primer for Open-Source AI
This primer makes an argument I think our industry needs to internalize quickly, that open-source AI collapses supply-chain security and delegated-authority security into a single problem.
The piece reframes open-source AI not as downloadable weights but as a full chain of data, code, weights, configuration, documentation, infrastructure, and human decisions, and maps it across four converging disciplines and five risk properties like decentralized trust, composite repositories, and derivative lineage.
It is the conceptual companion to the Hugging Face incident, because a malicious dataset that leads to code execution is exactly what it looks like when the supply-chain problem and the delegated-authority problem stop being separable.
Existing control frameworks built for single-provider systems are not going to cover this cleanly, and that gap is where a lot of the next few years of AppSec work is going to sit.
Knowledge Distillation Attacks
Jan Daniel Semrau (MFin, CAIO) frames knowledge distillation, the practice of training a smaller model to replicate a larger one’s outputs, as a competitive weapon in the US-China AI race.
He points to Anthropic’s February 2026 disclosure that it caught three Chinese labs running distillation campaigns against its models, and argues distillation lets a lab compress years of another lab’s R&D into weeks by converting expensive pretraining into cheaper compression-only costs. A few of the specific figures in the piece are the author’s own characterizations rather than independently sourced, so I would treat them as claims rather than settled facts.
The underlying dynamic, though, connects straight to the AISI capability data, because distillation is one of the mechanisms narrowing that frontier-to-open gap, and it raises genuinely thorny questions about model IP, provenance, and what we even mean by a secure model supply chain.
It is also very timely, as Michael Krastious recently renewed claims that Chinese-based companies are distilling U.S. frontier models, with the most recent example being K3. All of this while discussions on sanctions, and other measures are being discussed.
Isolation as a First-Class Principle for LLM-Agent System Safety
Complementing recent discussions around least-autonomy, this survey from researchers at HKUST and collaborators argues that isolation between system boundaries should be treated as a first-class safety principle, and organizes the LLM-agent safety literature around five isolation boundaries spanning user-agent, agent-tool, agent-execution, agent-agent, and system-environment.
Their thesis is one to underline, that safety is no longer only about input-output content alignment, it also concerns system behavior and real-world execution outcomes, and that serious failures often cross boundaries through sequential escalation. If you want the academic vocabulary for what went wrong at Hugging Face, this paper supplies most of it.
AppSec
Total Recall: How Two CVEs Let Any Website Read, Rewrite, and Wipe Your AI’s Memory
Pluto Security’s Yotam Perkal documented a set of vulnerabilities in mcp-memory-service, a popular Model Context Protocol server with more than 1,800 GitHub stars and integrations across a dozen-plus AI clients.
The headliner is CVE-2026-33010, a high-severity issue at CVSS 8.1 where wildcard CORS lets any website read, modify, and delete everything stored in an AI assistant’s memory, alongside CVE-2026-29787 for system information disclosure. What makes this one instructive is the root cause, a stack of insecure defaults, with CORS origins set to a wildcard, the host bound to 0.0.0.0, and anonymous access enabled out of the box, such that Perkal measured total data theft in about 0.2 seconds.
Fixes land in version 10.67.1. This is the excessive-agency and insecure-defaults problem made concrete, and it pairs directly with Jet Anderson’s writing below.
The Week of Sandbox Escapes
Pillar Security’s research team documented sandbox escapes across Cursor, Codex, Gemini CLI, and Antigravity, grouping them into four repeatable failure modes including denylist bypasses, workspace configuration execution, and privileged daemon access.
Their central thesis is the sentence to remember, that if an agent gets to write the future inputs of systems, it was never sandboxed in the first place. That is the same structural failure OpenAI’s models exploited to get out of their evaluation environment, just at the level of coding agents that most of our developers are already running locally.
The practical recommendation, that security teams should evaluate whether their vendors can even distinguish user-created, repo-created, and agent-created file states, is a good concrete question to bring to your next tooling review.
Flaw Surge Fuels Need for CISOs to Rethink Vulnerability Management
CSO Online’s John Leyden pulls together a strong panel of practitioners on a theme this issue keeps circling, that AI-accelerated vulnerability discovery is overwhelming the traditional scheduled patch-cycle model.
The piece cites a 43-day median patch time drawn from Verizon’s DBIR by way of Forescout’s Rik Ferguson, and argues for a shift to risk-based, continuous vulnerability management tied to real-time exploitation intelligence, with virtual patching offered as a compensating control for systems that cannot be directly patched.
None of the individual recommendations are new, but the forcing function is, because when discovery accelerates and the exploitation window collapses, the old cadence of scan, ticket, and wait simply stops being viable. This is the operational problem that Empirical Security is raising money to solve and that Jen Easterly is writing about next.
I of course have written extensively about this topic for years as well in my books and blog.
The KEV Is Dead. Long Live the KEV.
Former CISA Director Jen Easterly argues that CISA’s Known Exploited Vulnerabilities catalog, which helps defenders prioritize patching based on confirmed exploitation, has to evolve for the AI era rather than be abandoned.
Her core point, as reported, is that for widely deployed, internet-facing products, the period in which defenders can wait for confirmed exploitation before acting is shrinking. That is the KEV’s central assumption under pressure, because a catalog built on confirmed, observed exploitation is inherently a step behind, and the step is getting longer relative to how fast exploitation now happens.
Easterly is not calling to scrap the model, she is calling to adapt it, and given how much of federal and enterprise prioritization leans on KEV, this is a conversation the community needs to have out loud, and builds on the recent CISA BOD to move away from CVSS-based prioritization as well.
AI Has Broken the Vulnerability Disclosure Model
Mindgard’s Peter Garraghan makes a complementary argument from the disclosure side, that AI has broken coordinated vulnerability disclosure because it is often difficult to even contact AI vendors directly, with reporting scattered across web forms, email, bug bounty platforms, or no process at all.
The deeper issue he raises is that the industry lacks consensus on what an AI vulnerability even is, which lets providers treat content and safety issues as out of scope, especially where impact is hard to quantify. This ironically is the entire reason folks such as Ken Huang started the AIVSS project, which helps address this gap.
Put this next to the Hugging Face incident and the tension is obvious, because we are asking researchers and defenders to responsibly disclose against systems whose vendors have not agreed on what counts as a vulnerability or where to send the report.
The disclosure plumbing has not kept pace with the threat model, and that gap is going to bite.
GOLD EAGLE Clearinghouse Targets a Real Coordination Gap
The government’s answer to some of this launched on July 14 as GOLD EAGLE, a voluntary clearinghouse described as coordinating and deconflicting vulnerability scanning, discovering and validating vulnerabilities, and prioritizing remediation and patch distribution across the AI industry and critical infrastructure, positioned ahead of an anticipated vulnpocalypse.
The expert reactions are the valuable part. Casey Ellis calls it, at least for now, a coordination process wearing a technical system’s clothes, and Katie Moussouris cuts to the core with the observation that the bottleneck was never knowing about more bugs, it was having the people and process to prioritize and fix them. I think that is exactly right.
Coordinating discovery is useful, but discovery was never our constraint, and if GOLD EAGLE mostly surfaces more findings without addressing remediation capacity, it risks pouring water into an already overflowing bucket.
Announcing VulnHunter
On the tooling side, Capital One open-sourced VulnHunter under Apache 2.0, an agentic security tool that applies attacker-perspective analysis directly to source code rather than scanning passively.
Two design choices stand out. It starts its Attacker-First Forward Analysis at attacker-accessible entry points like APIs and file uploads and reasons forward through application logic, and its Falsification Engine runs a structured reasoning workflow explicitly designed to disprove its own findings before a developer ever sees them, which is a thoughtful answer to the false-positive problem that Jet Anderson quantifies below.
It runs on Claude Opus 4.8 within a Claude Code environment, and Capital One says it has used it across thousands of repositories. It is genuinely good to see a large regulated enterprise contributing real agentic security tooling back to the community rather than just consuming it.
Apple Reverses Age-Old Patch Policy to Keep Up With AI
Dark Reading’s Nate Nelson reports that Apple shipped security updates on June 29 outside of a major OS release, a real break from its traditional bundled-patch cadence, with the stated goal of reducing the time between when updates become public and when they reach customers.
The forcing function is the same one running through this whole section, with Mandiant data showing average time-to-exploit around 63 days back in 2018 and the trend since flipping negative, meaning attackers now routinely weaponize flaws before patches are public. iVerify’s Rocky Cole, whose team found around a dozen bugs in two months testing AI models through OpenAI’s Trusted Access program, offers the necessary caveat, that faster patching does not help if people do not install it.
When even Apple is restructuring a signature policy around exploitation speed, that tells you the timeline pressure is real and not vendor spin.
The Agentic SDLC
Jet Anderson’s writeup on GEICO’s tech blog is one of the more thorough treatments I have seen of what AI coding agents do to the secure development lifecycle, and it is dense with sourced figures.
A few worth carrying:
61% of AI-generated code is functionally correct but only 10.5% is secure per Zhao et al.
49% of dependencies recommended by AI coding agents contain known vulnerabilities per Endor Labs
100% of surveyed companies have AI-generated code in production while 81% of security teams lack visibility into it per Cycode
Trend Micro found more than 8,000 MCP servers on the public internet, 492 of them with zero authentication and zero encryption.
Anderson’s framing is that the failure is not that security tools missed the bugs, it is that nobody ran any security tools at all, and he quotes Bruce Schneier’s blunt assessment that we have zero specific AI systems that are secure against these attacks.
His prescription is a shift from episodic human-review gates to continuous, embedded, agent-native validation.
This one is worth reading in full!
Final Thoughts
If there is a single thread running through this issue, it is that the categories we have used to organize our work are collapsing into each other.
Safety and security ran together this week when an AI safety evaluation became a live intrusion on a third party, and again when safety guardrails blocked the forensic response.
Offense and defense ran together when the same GPT-Red capability that hardens models is the capability that chained zero-days onto Hugging Face’s servers. Supply-chain security and delegated-authority security ran together the moment a malicious dataset became remote code execution, and the open-weight capability curve, the funding wave, and the disclosure and prioritization crises are all the same story told from different seats.
None of this is cause for panic, and it is certainly not cause for the reflexive hand-wringing our field is prone to.
Autonomous exploitation stopped being hypothetical this week, but the impact was mitigated in part, because capable people were watching their telemetry and moved fast.
The work in front of us is to close the gap between how quickly these capabilities are arriving and how slowly our governance, our disclosure plumbing, and our prioritization models are adapting. We have watched this movie before with Cloud, with SaaS, and with every prior wave, where security sat back hand-wringing and got left behind but this time the wave is bigger and moving faster than ever.
The question, as always, is whether we get ahead of these architectures while they are still taking shape, or bolt security on after the fact once again.
Stay Resilient!





























