Security through obscurity is dead, and AI delivered the fatal blow
Security experts say the old strategy of relying on obscurity to protect systems is now definitively obsolete, because AI tools are being used by both defenders and attackers to uncover vulnerabilities that had gone unnoticed for years or even decades. Vendors and researchers are using AI agents to probe widely used products and open-source code, producing record numbers of bug disclosures and patches and creating a growing backlog for maintainers, while attackers are using the same technology to reverse-engineer fixes and craft exploits within hours of patches being released.
The article cites Microsoft's record Patch Tuesday, which fixed 974 CVEs including flaws in long-neglected components such as Telnet client, Windows RNDIS, NFS Portmapper and Link Layer Topology Discovery. It also notes that at least four suspected Chinese-linked espionage groups exploited a "patch-gap" in Chromium, and that US agencies warned attackers used AI-generated scripts to breach Siemens S7 industrial control systems at critical infrastructure sites. Officials including the FBI's Brett Leatherman and Google's John Hultquist warned that AI removes the need for deep technical expertise, particularly threatening operational technology and industrial control systems that previously relied on their obscurity and specialist knowledge for protection.
- AI is exposing decades-old bugs once hidden by obscurity
- Microsoft's latest Patch Tuesday fixed a record 974 CVEs
- Attackers used AI to hack industrial control systems