AppSec Built for Human-Speed Threats Won't Survive AI-Agent Attacks, Researchers Warn
joshua_saxe · x · 2026-09-07
Security researcher matrosov argues that nearly everything built for application security assumed a threat model where a human had days to think — understand the problem, define a fix, then scale remediation. Prior approaches leaned on pre-generated heuristics (rules, SAT/SMT) or hypotheses (fuzzing harnesses), all viable only because humans understood the problem first. With AI-driven attacks, discovery and remediation must happen almost simultaneously — what caseyjohnellis calls "OODA loop compression." Teaching AI agents to drive the same tools doesn't fix it, and ineffective mitigations neither stop AI attackers nor buy time.
More from coding & agent
- Andrej Karpathy contributing to open-source AutoResearch, an agent that runs AI research end-to-end — JaynitMakwana · 2026-09-07
- pro-workflow gives Claude Code self-correcting memory that compounds over 50+ sessions — tom_doerr · 2026-09-07
- Open-Source Voicebox Hits 52K GitHub Stars With Local Voice Cloning and Dictation — alex_verem · 2026-09-07
- Merge scrapped its visual agent builder after realizing models could just run workflows themselves — shensi · 2026-09-07
- AI coding instruction files grow 226% on average; study proposes 'catastrophic remembering' and comments as fix — rohanpaul_ai · 2026-09-07
- Claude Code Users Press Anthropic on Whether Usage Resets Are Still Manual or Automatic — burhop · 2026-09-07