Loading video...

Video Failed to Load

Go Home

AI "cyber models" aren't going to solve our security problems. "If we just patch all the vulnerabilities then we're safe" is a convenient story but it's also not true. If you're worried about cybersecurity, the solution involves hard work, not just more tokens.

36,308 views • 9 days ago •via X (Twitter)

49 Comments

MikeTalonNYC's profile picture
MikeTalonNYC9 days ago

but... hard work is hard!

Zack Korman's profile picture
Zack Korman9 days ago

This is the core problem isn’t it

Josh Long (the JoshMeister)'s profile picture
Josh Long (the JoshMeister)8 days ago

I promise, I independently conceived this before I watched to where you said “GPT Zoolander.” Great minds… 🧠‍🤝‍🧠

Zack Korman's profile picture
Zack Korman8 days ago

Hahaha that’s amazing

izan's profile picture
izan9 days ago

Zack is actually a cyber model and you should all buy his pinup calendar

Zack Korman's profile picture
Zack Korman9 days ago

“I’ll show you what a cyber model really looks like”

izan's profile picture
izan9 days ago

"Paint me like one of those Mistral AI"

Marius Reinecker's profile picture
Marius Reinecker9 days ago

Nah, it's fine. When they go rouge, they just change colour. Harmless. We should really worry about when they go rogue, though.

Zack Korman's profile picture
Zack Korman9 days ago

That’d be kinda dope if they did

Marius Reinecker's profile picture
Marius Reinecker9 days ago

😉I know very well how rogue is spelled bc I've been playing pen&paper RPGs forever. It's also to my eternal regret not having put more effort into learning French at school when I had the chance. Oh, and I'm autistic. There's that, too.

Zack Korman's profile picture
Zack Korman9 days ago

lol sorry I missed the joke

Marius Reinecker's profile picture
Marius Reinecker9 days ago

You were busy paying attention to the important things. But there are niches in CS for folks like me and being pedantic is an advantage.

ShrekOverflow's profile picture
ShrekOverflow8 days ago

Unfortunately, the current security response seems to be like so:

Zack Korman's profile picture
Zack Korman8 days ago

This is extremely accurate and an extremely good fit. And honestly so painful to watch because it’s exactly how most security teams work

Zack Korman's profile picture
Zack Korman9 days ago

Hah thank you! The job of security involves work. Stunning news

Kamil Staszewski's profile picture
Kamil Staszewski9 days ago

It's the first thing companies does now. Instead of changing practices that lead to bugs, we rather call "cyber-llm scan .", close eyes and then fix those mistakes with the help of coding-llm. Rarely, we look back, adapt our coding practices, add more checks to CI, improve or introduce regular security practices that were established in the past.

Zack Korman's profile picture
Zack Korman9 days ago

Yea. “Just one more LLM bro. I promise it will fix it bro”

Kamil Staszewski's profile picture
Kamil Staszewski9 days ago

It costs shit ton of money. If it wasn't for sub, on a decent size codebase (150k loc) llm based application scan can cost to up to 2k USD using current models. That's what keeps companies from abusing it. I'm aware of that number cause I had to calculate it at work recently.

GS-InfoSec's profile picture
GS-InfoSec9 days ago

Part of the reason for the limited use is adoption. I believe they will be very good at things like risk and compliance. That is where we will really see an impact that reduces noise. Find all the bugs, and patch everything has never been a good strategy. Big picture correlation, assessment, and strategy is going to supercharge imo.

Zack Korman's profile picture
Zack Korman8 days ago

@techspence I mean I agree, but there are entire products that have to be built out to really support that (especially just getting the right data into the right place). And that isn't there yet, that I know of

GS-InfoSec's profile picture
GS-InfoSec8 days ago

@techspence A lot of companies are tackling IT debt, immature data gov, and security/privacy issues to get in position for AI. They aren’t ready. They don’t have the people with the AI skills.

Carmen's profile picture
Carmen4 days ago

Imagine if regular companies said "our cyber defenses are shit, let's hope we don't get hacked." Would you still trust them?

Shasheen_B's profile picture
Shasheen_B9 days ago

It’s all about the bloody secrets. The best models still do not solve fundamental problems. They have amplified it.

Tyler's profile picture
Tyler9 days ago

GRC bros in shambles

Zack Korman's profile picture
Zack Korman9 days ago

Hahah I gave them some credit!

Tyler's profile picture
Tyler9 days ago

Fair in your treatment, as usual.

Dirty Indy 🟥🟧🟨's profile picture
Dirty Indy 🟥🟧🟨8 days ago

Train your Pokémon’s

Erik Ex Plano's profile picture
Erik Ex Plano9 days ago

Agreed. And the most important piece (IMNSHO) is architecture: selecting what kinds of pieces you use and how they all fit together to meet the org’s requirements. LLMs seem to be pretty shit at this.

Zack Korman's profile picture
Zack Korman9 days ago

Yea a lot of orgs with horrible architectures are in trouble. A lot of orgs with good architecture are mostly fine even if they do a much worse job

Clément's profile picture
Clément9 days ago

ClaudeStrike wen

Zack Korman's profile picture
Zack Korman9 days ago

Oh my god that is admittedly a good name

darkmage's profile picture
darkmage9 days ago

Spending tokens is hard work though :D

Zack Korman's profile picture
Zack Korman9 days ago

Depends how poorly you spend them

darkmage's profile picture
darkmage9 days ago

I hard agree that the term "cyber model" makes no sense. I can see where your issue is now. The AI companies have usurped cyber security thrones and are now attempting to lord-over the discussion. On a political-level, this is definitely undesirable. Thats the first 1min32sec

darkmage's profile picture
darkmage9 days ago

3min in Sure, the cybersecurity field is broad and includes more than the "cyber models" typically are designed for. This nuance is understood and expected. The spearhead of defense is certainly offense, and the expectation is that great offense means great defense (IMHO)

darkmage's profile picture
darkmage9 days ago

4min in Not sure where this is going because I haven't heard anything new yet. This video is clearly not for me. Best of luck

Zack Korman's profile picture
Zack Korman9 days ago

As a general rule my videos about cybersecurity are for non-cyber people and my videos about not-cyber are for people in cyber.

darkmage's profile picture
darkmage9 days ago

This explains everything! You are filling a vital role.

Mona Lisa's profile picture
Mona Lisa9 days ago

We do, they work for the mossad

Shez Malik's profile picture
Shez Malik9 days ago

most of what gets u hacked is working as intended

learner's profile picture
learner8 days ago

We can’t. I’m pretty sure all Fortune 500 companies still have vulns from 200X

Jon Towles {MVP}'s profile picture
Jon Towles {MVP}5 days ago

One could argue if you patch the vulnerabilities you’re safe for a little bit and then not again. Shit look at windows, just set a record for the most patches ever. It’s never finite. The complacency with a side of hubris is what actually gets you into trouble

Ryan McCormick's profile picture
Ryan McCormick9 days ago

I agree with most, we've always sucked at security & the answers have largely been available. But once there are no vulnerabilities it's all configuration. Configuration can be audited perpetually. The next phase is cryptographic certification of computation and capability.

Carl Sue's profile picture
Carl Sue8 days ago

Man, I'd love to debate you on this. I think we see the future similarly, but I disagree with pushing existing frameworks as they stand. They fill a gap now, but not all will be AI resilient, and I think the cybersecurity-as-a-department mindset might be short-lived.

Zack Korman's profile picture
Zack Korman8 days ago

What would you do instead

Carl Sue's profile picture
Carl Sue8 days ago

We can both agree on many of your points, especially for companies that have deployed a solution but not truly implemented a complete one. IMHO, the solution is not limited to using AI to get these things implemented properly. A better direction is to use some resources to keep tech debt at a reasonable level of degradation while pushing most resources toward building more correct capabilities. Everyone is in a different maturity on where bringing in AI makes the most sense, which is why the big players push threat modeling hardest for “security-focused models.” Reducing costs there lets companies identify the next area that can be modernized and either companies like yours will build for that gap or in a lot of cases I think the functionality will be built in house and slowly dissolve into other parts of the business. As an example it’s better to build say an autonomous credentials management system that reports into a security architect then fund an IAM service if you’re in a position that you have neither or a partially built environment and need to fill the gap.

CyberBox's profile picture
CyberBox8 days ago

@ZackKorman Agreed. Tool sprawl and shelfware stem from weak operational lifecycle. AI won't fix context. True ROI needs continuous posture validation, tight API orchestration, and detection engineering.

Carl Sue's profile picture
Carl Sue8 days ago

@ZackKorman It also needs investment into things like micro harnesses which adapt a workflow instead of just adding another tool. Simplify security while insisting on high standards.

Jonathan Yantis's profile picture
Jonathan Yantis8 days ago

The core risk I see at most enterprises is broad permission graphs and ease of lateral movements. A cyber critical model has near infinite paths to their goals once inside most enterprises.

Related Videos