Security researchers: patching bugs won't survive AI-driven vuln research, redesign needed

max_paperclips · x · 2026-10-05

Responding to Guillermo Rauch's take that security will become verification engineering plus capital allocation for software companies, researcher matrosov pushes further: memory safety is a symptom, not the cause—recent Linux kernel disclosures trace back to design decisions and trade-offs. Throwing more tokens at the attack surface won't help; nothing today is ready for AI-driven vulnerability research at scale. He argues for AI-assisted redesign, architecture validation, formal methods, and rejecting attack surface at the design phase—hardware included.

Related event: Vercel CEO: Security to Become a Core Function of Software Companies in the AI Era(2 posts)→

Original post →

More from Safety

Safety channel →