Security through obscurity is dead, and AI delivered the fatal blow
AI agents are killing security through obscurity, accelerating vulnerability discovery and patch-gap exploitation, experts warn, with OT/ICS systems most at risk.
An opinion/analysis piece arguing AI has made security through obscurity obsolete, citing record vulnerability disclosure volumes after Microsoft's Patch Tuesday addressed 974 CVEs. FBI Cyber Division assistant director Brett Leatherman said latest AI models found significant vulnerabilities in open source libraries running on most web servers. The article cites at least four espionage crews (most suspected China-linked) exploiting Chromium's patch-gap window with a rapid exploit kit, and a five-agency advisory on AI-generated exploitation scripts breaching internet-exposed Siemens S7 Series PLCs at water, manufacturing, and energy facilities. Experts including John Hultquist, Chris Inglis, and Katie Moussouris warn AI erodes the expertise barrier protecting obscure OT/ICS systems while defensive AI patching lags, with studies showing AI-generated patches fail more than half the time.
Production data in testing is still common, and Tricentis' CISO wants it gone
Tricentis CISO Erika Dean urges keeping production data out of test environments and describes red-teaming that caught a prompt injection gap.
In a Help Net Security interview, Tricentis CISO Erika Dean recommends keeping production data out of QA and testing environments, even in finance and healthcare, where weaker QA controls create risk. Her team red-teamed an agentic chatbot before launch, found a prompt injection gap, and held the release for a week until it was fixed. She says vendors who cannot explain data residency, retention, and model training use are disqualified regardless of product quality.
12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing
GBHackers compares twelve application allowlisting tools for 2026, naming ThreatLocker and Airlock Digital leaders and Microsoft WDAC the free native option.
GBHackers published an editorial comparison of twelve application control and allowlisting tools for 2026, assessing control depth, manageability, and pricing models. It ranks ThreatLocker and Airlock Digital as leading dedicated allowlisting options, positions Microsoft WDAC/AppLocker as the free native choice for Windows estates, and highlights CyberArk and BeyondTrust for coupling control with privilege management.