AppSec Built for Human-Speed Threats Won't Survive AI-Agent Attacks, Researchers Warn

joshua_saxe · x · 2026-09-07

Security researcher matrosov argues that nearly everything built for application security assumed a threat model where a human had days to think — understand the problem, define a fix, then scale remediation. Prior approaches leaned on pre-generated heuristics (rules, SAT/SMT) or hypotheses (fuzzing harnesses), all viable only because humans understood the problem first. With AI-driven attacks, discovery and remediation must happen almost simultaneously — what caseyjohnellis calls "OODA loop compression." Teaching AI agents to drive the same tools doesn't fix it, and ineffective mitigations neither stop AI attackers nor buy time.

Original post →

More from coding & agent

coding & agent channel →