Gary Marcus Warns LLM-Generated Code Is Piling Up a Security Nightmare
GaryMarcus · x · 2026-09-19
Gary Marcus and Nathan Hamiel (Senior Director of Research at Kudelski Security) co-authored "LLMs + Coding Agents = Security Nightmare", arguing that LLMs and coding agents are radically expanding the cyber attack surface.
- Origin: Marcus's view crystallized after an Nvidia talk by Rebecca Lynch and Rich Harang at Black Hat Las Vegas, plus conversations with Hamiel, the track lead for AI/ML at the conference.
- Core claim: LLM reliability failures like hallucinations carry over into generated code, and vibe coding is piling up huge volumes of insecure code—a new systemic risk.
- Prompt injection gets special attention: malicious input can make systems take unintended actions on the attacker's behalf, magnified in the agent era.
- The piece extends Marcus's earlier "LLMs are like Swiss cheese for security" warning: more adoption, more trouble.
- Framed against the cat-and-mouse history dating to the 1988 Morris Worm, the authors argue LLMs + agents are a fundamental expansion of the attack surface, not just another vulnerability class.
More from coding & agent
- Dev launches Jev Search: free open-source tool that picks where to search and ranks results — gaganghotra_ · 2026-09-19
- Ex-Meta Llama 3 RL lead joins Merrai, an AI memory-layer startup, as advisor — misovalko · 2026-09-19
- Braintrust adds Jev as a judge scorer: typed decisions at up to 193.6× speed and 444.6× lower cost — multiply_matrix · 2026-09-19
- Chrome team publishes a framework for designing WebMCP tools for agentic workflows — gaganghotra_ · 2026-09-19
- I spent $3.40 on Jev in 24 hours: it will be Jev + LLMs, not Jev vs LLMs — gaganghotra_ · 2026-09-19
- Agentic Benchmark Checklist paper shows flawed agent benchmarks skew results by up to 100% — ddkang · 2026-09-19