[DigitalToday reporter Chi-gyu Hwang] The spread of AI agents has effectively brought an end to security through obscurity, The Register reported on Sept. 13 local time.
Security through obscurity refers to an approach that assumes a system is safe if its structure or vulnerabilities are kept hidden from outsiders.
It is a way for companies to try to maintain security by not disclosing software code or network designs. It may have worked in the past, but it is difficult for it to hold now that AI can quickly find vulnerabilities, the report said.
Software companies and independent researchers are using AI agents to find bugs in products and open-source code, the report said. This includes many vulnerabilities that are decades old. As a result, the number of vulnerability disclosures and patches has risen to record levels, and project managers are struggling to cope.
Brett Leatherman (브렛 레더맨), deputy assistant director of the FBI's cyber division, said of open-source libraries used by 80 percent of web servers: "For 10 years, the community believed they were safe, but the latest AI models found serious vulnerabilities."
Dustin Childs (더스틴 차일즈), head of Trend Micro's Zero Day Initiative, cited a case in which Microsoft patched 974 vulnerabilities at once. He said patches also covered long-forgotten elements such as the Telnet client and the NFS portmapper, a Unix technology from the 1980s.
Experts are particularly concerned about risks in operational technology fields such as industrial control systems. John Hultquist (존 헐트퀴스트), chief analyst at Google's Threat Intelligence Group, said: "OT systems have been protected by knowledge that existed only in the heads of a small number of experts, but that approach is no longer sustainable." In fact, five U.S. government agencies recently warned that attackers broke into Siemens S7 series PLCs using AI-generated exploit scripts.
Kati Moussouris (케이티 무수리스), founder of Luta Security, said security through obscurity was not effective from the start and that AI has advanced attack techniques much faster than defensive techniques..
The OnePassword research team CVE (Kati Moussouris (케이티 무수리스), founder of Luta Security, said security through obscurity was not effective from the start. She pointed out that AI has advanced attack techniques much faster than defensive techniques.
The OnePassword research team generated 6,080 patches for six CVEs using ChatGPT-5.5 and Opus 4.8 and found the share that fully fixed vulnerabilities was only 26 percent. Cases that failed to fix vulnerabilities or instead created new vulnerabilities accounted for 53.9 percent. A Veracode survey also found the average security pass rate remained at 56 percent, based on more than 100 models and 80 coding tasks.