AI Threat Hunting: Claude Uncovers 600+ Open-Source Vulnerabilities | Security Boulevard Ep. 20
Anthropic has started to “let Claude off the leash” for vulnerability scanning—and the results are a forcing function for the security industry. In this episode, Tom Hollingsworth is joined by Fernando Montenegro and Alan Shimel to break down what it means when an AI system can surface 600+ vulnerabilities across open-source projects, including at least one Ghostscript issue discovered via a novel approach that security researchers hadn’t used before.
The conversation moves from the raw headline to the operational reality: if AI accelerates discovery, defenders inherit an urgent backlog. The panel discusses why you won’t see a full list of CVEs immediately (responsible disclosure still matters), how prioritization changes when findings scale into the hundreds, and why organizations may struggle to keep pace if their change management and patch pipelines are built for a slower era.
The bottom line: AI-assisted research can dramatically increase visibility into latent risk—but the security and engineering machinery behind remediation has to evolve just as fast.
If AI can surface hundreds of vulnerabilities in weeks, what should security teams change first—prioritization, disclosure workflow, or remediation automation? Subscribe to Security Boulevard for weekly analysis on what’s changing in security and what actually matters in practice.
Transcript
Once more unto the breach. Dear Security researchers, welcome to Security Boulevard, the cybersecurity podcast from the Futureum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms. Let's meet today's guest before we jump in, starting with our old friend, Mr. Allen Shimel.
Allen, it's good to see you. Good to see you, Tom. How are you man?
I'm, I'm good. It's, uh, getting kind of interesting trying to keep up with all the security news out there, but I think we've got a fun topic for today. Yes.
It, it's, you know, that old, I don't know if it's an Irish proverb, an or ancient Chinese saying or something in Hebrew, but may you live in interesting times. These are certainly interesting times, or Fernando's gonna tell me he was actually Brazilian, but No, no, no, it's not, it's not Right now as we're recording this, Brazilians are busy wrapping up Carnival, so yeah, they're, that's Proverbs. They're probably still asleep, but luckily someone woke up to join us and that voice is Fernando Montenegro.
Fernando, it's good to see you again. Oh, it's lovely to be here. Thank you so much.
Alright, and of course, I'm Tom Hollingsworth. I'm the event lead for all things related to security here at Tech Field Day. Uh, let's jump into today's episode.
I'll give you a hint. We're gonna be talking about ai, but we've got a couple of topics that we wanna discuss that kind of meld together. Uh, the first one is the fact that, uh, anthropic has started kind of letting clot off the leash a little bit.
Uh, it has done some vulnerability scanning and managed to turn up over 600 vulnerabilities, uh, across various open source projects. And, and that has some security researchers asking some very interesting questions about the capabilities of AI systems to be able to do, uh, threat modeling, threat hunting. Uh, one of them in particular that I thought was kind of interesting, I believe it was in Ghost Script, uh, was a vulnerability that no one had been able to find for years.
And, uh, the way that the system actually found that vulnerability was novel. It, uh, in short, it said, well, this was a problem that they patched years ago, but did they manage to patch every instance of that across every software release? And it actually found out that they hadn't.
And so it used that as a potential avenue for exploit. So I kind of want to, I want to jump out here by saying to the, the group is the power of AI in this case, the ability to iterate across every version of every product to find something that we might've missed along the way. Lemme jump in just for a second.
Uh, I think that one of the things that we have to, let's go back for, forget AI for a second, right? Normally, how would we find vulnerabilities, right? You can, you can read the source code, you can, uh, brute for something like we've, we've done fuzzing forever, right?
Mm-hmm. What I find fascinating about this is that this is what AI can do, or, or, or what, at, at, at a very expensive cost. We can get into the cost later, but what AI seems to be able to do is to quote unquote reason through these different stages of analyzing a piece of code.
And, and what I personally find fascinating is not so much the number of vulnerabilities it found, but the fact that it went through these methods that we're codifying these methods along the way. And, and of course, if we're codifying them now, it, uh, it, uh, it behooves us to think that we'll see, uh, more efficient finding in the future. Like, where else can this be applied to?
So that's, that's the thing I found really interesting about this. I I think you gotta look at this with a little historical context, and Tom, you, you touched on it there before we had AI and before we had Claude Opus, and let's be clear, this isn't just Claude, it's Claude Opus. Yes.
6. But before we had these things, how did we find vulnerabilities? How did we find bugs?
Well, hopefully we did a lot of testing pre-release and found bugs and fix them before. But the fact of the matter is, most bugs in, in production systems were found two ways. The really bad way is the bad guys found it, and they exploited it and made an attack.
And my goodness, when the stuff hit the fan, we said, how did this happen? And we find out, and now we, and then we patched it. That's the worst case scenario, right?
A better case scenario was good guys found it. Somehow or another we found it. And it was very hit or miss for many years, especially when I first got into security with the advent of bug bounties, right?
And, and, uh, oh, I forget her name now, she worked Katie, Katie Ma, Katie MAs, yes. Started with the bug bounties and everything else, and then probably the, you know, the, so the rise of security researchers who were just out here looking for bugs and, and they got paid a couple dollars when they found they got paid a lot of money if it was a big bug. But with those security re researchers came the rise of fuzzing, right?
I remember when fuzzing was a new thing, but with fuzzing, you could, you could go to any open source project or any kind of website or whatever and hit it with a fuzzing scanner that would, you know, this is before we hadis, I said, but it would cry a lot of different variations and see if it found anything. It was like, you know, putting a blind person in a round room and saying, go find the corner. Um, you know, it, it really hit or miss what we have here with ai.
It, it doesn't fuzz like a fuzzing scanner does, but it takes fuzzing to the E degree. It could look at the code and run the permutations, if you will, to find those corner cases, to find those, you know, situations where something could be exploited. And that, you know, this is an article I, it's up on DevOps do com.
I wrote about, this is called Opus, the greatest security Researcher of all time. It's the fastest, it found six bugs in open source projects in a few days. It's like a year's worth of research in a few days.
So fundamentally, that changes the game, right? Our friend Fernando, our friend, Gotti, Gotti Everett, and, and a young lady from Google, and I'm, I think it's Heather, but I, I may have her name wrong, but it's in my article, they called this to the day, six months ago. They said, we're gonna have a, an apocalypse, a vulnerability apocalypse where AI's ability to find new vulnerabilities will outstrip our ability to keep up with it.
They said, give it six months, and almost six months to the day later, this came out. So, I don't wanna disagree with you, Alan, I finally get to say that. I don't wanna disagree with you, but I have some problems with this.
So here's my first problem. It, it discovered 600 vulnerabilities, right? Where's the CVSS details for those?
They didn't publish them. In fact, of the 600 that they published, they only talked about three projects, which already kind of makes me wonder what's going on, because I didn't realize this until I did some research. 5 had a little problem with the mallek call in programming?
Uh, it would flag Malick as a potential vulnerability every time, because Malik can be overflowed, even though the programmers would immediately point out, you realize that we wrapped it in an error handler so that if it ever did overflow, it would immediately dump out and it wouldn't actually create a vulnerability. But just like an overeager intern that's three days out of college, it would flag every instance of Malick that it found not realizing that there's probably no better way to do that, because all you gotta do is go out to the Linux kernel mailing list and wait for three months until someone suggests rewriting the linnux kernel in c plus plus. Because everybody does it, it, it's, it's a truism because everybody thinks that there's a better way to do it, even though the guy who's been writing it for the better part of 30 years knows there's no better way to do it.
Uh, just grab the, the comments for some of the drivers that have been submitted. Some of them, I love the comments of like, don't ever f and touch this, because nobody knows how it works, but it works. That's the perfect thing for AI to go.
No, no, no, I can rewrite that. I think it's also telling that you brought up the Bug bounty program, because one of the problems that we're seeing with AI is that AI tools are causing bug bounty programs to get shut down. All you gotta do is go look at the curl utility.
They had to shut down their bug bounty, like absolutely crater it because so many people were analyzing the curl programming database with AI tools, and they were catching all of the errors, and I use the quoting fingers there on purpose, and then they were submitting them hoping they were gonna get a hundred bucks or a thousand bucks. And finally the maintainer said no more. Because I can tell when it's ai, I can tell that you aren't actually doing any of the, the research around why that was written the way that it was, and you're just hoping for a quick cash in.
It's the same problem that we've seen a hundred times when there's a new tool out there that people think will lessen their workload. Their very first solution to using it is get rich quick. Because remember, script kitties back when they had, uh, nuclear weapons and push button capabilities, what did they do with them?
They used them to start extorting companies. They used them to start trying to break into places where the security was subpar until we improved our security. I think we're in a, a, we're in an era of AI kitties where they have access to these massive tools and they, they can pay $20 a month just like the rest of us, and then they can go out and try to basically recoup that cost by doing all these things.
And I think what's ultimately gonna end up happening is either the programmers are gonna have to get better, or they're gonna have to put some very strict rules in place. We will not accept submissions from these tools. Um, you need to provide like documentation or exploitability, otherwise we're done.
So we're, we're, I'm, I'm conflating a bunch of different things here and, and I'm sorry, fitting in between in, in the context that I see different problems at scale here, different, the different things playing out, right? Uh, I very much agree that yes, we should see more about those 600 vulnerabilities for sure. The other thing to keep in mind is that I, from where I've seen, from what I've seen, that exercise costed 20,000, right?
It's not as if, hey, you're gonna pick up a cloud subscription, uh, tomorrow and then start fuzzing your way, start vulnerability finding your way across things, right? So there is a cost to these things, which of course, for a large criminal enterprise or a mid-size criminal enterprise, and increasingly a small size enterprise mm-hmm. Right?
Is not, is not outta the realm of possibility, right? Which ties us back to look at all the, the open capacity that's available right now with open claw instances that are, that are available at like 19,000, 20,000 or whatever, right? But sorry, I, I, I, I digress.
There is absolutely what, what I find, what I found fascinating about the the opus thing is that it, it's how it navigated the problem. I think that the navigation of the problem was phenomenal, right? The other thing is that about the Bud Bounty programs, right?
And, and I'm thinking here about the fact that like, when we talk about AI security, we always talk about AI for security, security for ai, and one use case we rarely talk about is security from ai. What happens when your adversaries start using ai? And, and I think about this overflow in security bug bounties as as kind of that problem, right?
It's kind of like fraudsters trying to overload a, a, a call center, right? But in, I think that the approach here is to, uh, uh, curate more, like of course it becomes a more expensive, uh, to run, uh, bug bounty program, right? But I think there's still, there's still an they, those can still be saved, right?
Because have enough curation so that you can have, uh, like some automated, uh, uh, uh, triage early on. And then at some point, and, and, and the bug bounty, uh, companies have done this. I mean, hacker One and Bug and, and some of the others, right?
Have invite only programs. Hey, you can only submit, you'll only accept you if you invited. It's not, not democratic of, hey, open up entire world, but world, it's an option, right?
But anyway, I think that the, the, the broader point here is that there is, uh, there's tremendous to what's being done. We're just trying. It's the, so let, let weigh in.
Herem, bless your listen. He got all Southern on me there. Yeah.
Well, you know, we're in about fair play, but are you trying to make the argument that all of a sudden AI has created a situation where we have more vulnerabilities that aren't necessarily reachable, exploitable, or workable, or what you're really saying is meaningful, and this is just clogging up the pipes of poor vulnerability, remediators workloads. Is that the hill you wanna die on? Because that's a hill that I've been watching the battle on for about 30 years.
Nothing's changed. A, uh, don't blame AI for that. This, this is something that's been going on a long time.
You've got your telephone book. For those of you who remember what a telephone book looked like, a telephone book full of vulnerabilities every time you use the scanner. And it was job security, right?
It was like painting the Barno Bridge back home in New York. They start right after New Year's on one end, they finish right on the other end, right around Christmas. They take that week off and then start again on the other end for the new year.
That's what vulnerability remediation's been like for as long as I've been in security. It, it's not new. No, it's, you're right.
V vulnerability discovery is not new. 'cause we've been looking for these things for years. Any good programmer will do that.
What's happened is, is that the speed that we can find them has drastically increased. And it goes back to things like Problem Yeah, like encryption keys, right? It used to be that cracking any kind of password or something like that would take orders of magnitude more time.
But we have gotten to the point now because of the massive amount of compute power that we have with the ability to precalculate rainbow tables, that effectively any numeric password is, is instantly broken. Even lowercase passwords with a mix of numbers and letters probably takes about three days. Whereas it used to take like three weeks at, at the best case.
So the problem is, we, we now have to adapt faster. AI has shrunk the window for us to find these things and remediate them. Yes, it has.
May I introduce, bring into the conversation. I, I was working for an economics term. What may I bring into the conversation?
The concept of the Red Queen hypothesis, right? It's actually not, uh, it's actually not, uh, as much economics as it's evolutionary biology, right? But it's how much, uh, you have to keep running, right?
Just to stay in place. Mm-hmm. Right?
And I think that, uh, what what was notable to me on, on, on, and, and Alan, I agree with you wholeheartedly. Vulnerability's been around forever. What, what is changing is that, oh, look, this thing needs to be fixed.
Not in 2 85 days. This thing needs to be fixed in a week at best, if not soon. Well, that's prioritization, though, fer, right?
Yeah. You can't fix all 600 in a week. You gotta figure pick, you gotta pick your battles.
But lemme lemme also Tom to a couple of the other points you made in Fernando make, why don't we have the list of CVEs and the whole list of 500 or 600 vulnerabilities? Because until patches exist for them and we're ready to patch them, it's called responsible disclosure. If, if, if, if the, if the Anthropic people put that list up before there were patches out there, i I call for them to be hung from the nearest tree.
You don't do that. You can't do that. You can't do that.
But agreed, that, that, that's first of all. Second of all, though, here's the, the real politics of this guys. If Anthropic or the good guy, quote unquote, good guy, security researchers aren't using these tools to find these vulnerabilities, you know, who is of course, the bad guys, and they're gonna find them and they're gonna pick the ones that matter, right?
They've got, they're, they're well organized, they've got great resources, and this is available to them too. So there's a bit of a race here, right? And, and it's not a new race.
It's just, as you both have said, AI has upped the stakes. And that's what Gotti and, and the woman from Google, you're thinking about Heather Atkins, she's a, she's amazing. Like she's one of the power behind Google Chrome, right?
Yes. Yes. Yeah.
Thing, that's what the races, not that all these vulnerabilities exist. I think we all suspected that they, they're out there. But how the heck do we keep up with this?
And that brings me to the next article I wrote, son of MBO or Open Claw versus Opus. It takes AI to be ai, my friends, right? And I think of all open Chlor could be a platform's T cells, a platform's immune system waiting in, in our bone marrow, if you will, about platforms to take their marching orders to go out and, and remediate these, assuming we have remediations, uh, to go out and remediate all these vulnerabilities that these ai, these ais are finding, whether they're found by white hat, black hat, gray hat, no hats, right?
We, we, we need something that scales. And I think ai, you, you're gonna need, AI is the bottom line here. And absolutely, and I think we've seen some of this, some of this happening.
I, I would argue that, uh, the, by the way, I love the, the of multiple so much. The, the, the thing I would mention though, that is that what I think organizations and practitioners should be on the lookout for is not just on the capabilities, right? It's not just, can you, uh, do we release a swarm of agents to fix vulnerabilities, right?
It's is our operating environment are our development practices, are our, uh, software pipelines, is our change management process, uh, capable and ready for this type of autonomic, uh, uh, operation. I remember that. This, I go back years.
I remember having a cloud a con, this was the earlier days of cloud speaking with the cloud architect for a very large financial institution. And, and the guy was nearly in tears, right? Because he was telling me, look, uh, this was the time of, of, of how quickly can you deploy to prod?
We can roll things out to prod within an hour, right? Uh, and it's amazing and, and it's wonderful, but Cab Change advisory board still only meets twice a month, and every change has to be approved, right? It was so, uh, uh, that, that experience stuck with me forever, right?
It's like, can the way that we are running things, uh, match what the technology environment looks like? So my, my push to, uh, to people is, okay, great, you can deploy all the technology you want, but if you can't let the technology actually do its thing, if it really helpful. So here, here's a lesson I learned very early on in my cybersecurity career.
You know, Mitchell, Mitchell, Ashley and I were two of the three co-founders of a company called Still Secure. We had intrusion prevention, vulnerability management, network access control. At the time, intrusion detection was the standard, right?
It detected an intru, a potential intru intrusion, and alerted you at the time. Vulnerability scanning once a year was a, a wish, you know, uh, you know, that's what you would hope many organizations did it. We came up with automations to automatically block the most obvious intrusions to automatically remediate, do a work, put in a workflow, and remediate vulnerabilities failed miserably.
Failed miserably. You know why? People were afraid to automate remediation.
Fernando, much like your discussion, I probably had a discussion five or 10 years before yours because the cloud wasn't around yet, but it was with one of the global CIOs for Citi. Back then it was called Citibank. Yeah, it was still Citibank.
Now, of course, it's just Citi. How long does it take you to do your Microsoft patch Tuesdays to get your patch? Tuesday stuck.
90 days. Now remember, patch Tuesday came out once a month. Once a month.
They were three months behind, and some of those patches were, were needed. You got critical. Why, Peter, why, why 90 days?
Because we have to test it across our entire network before we can get approval. Make sure it doesn't break anything because we'd rather live with the vulnerability than break something else. Very similar to your cloud story.
This, now, I think the world has changed. I think we're more accepting of remediation when I speak to the vulnerability, vulnerability vendors today, Fernando, like Qua, and I'm sure you speak to them too, Qualys, rapid seven, whatever. I forgot who owns EI now, but, uh, the company behind EI scanner, um, you know, the, the AppSec scanners, they're all building automated remediation in, I dunno, you know, Qualys has this concept of rock risk operation Center Yep.
Where you make, you know, a, a weighted decision on should I automate the remediation or, or maybe wait for a cap. But I think the world is changing. We are becoming more, um, forgiving or, or, or open to automated remediation.
We have to, when you've got this thing finding 600 vulnerabilities, even if only a quarter of them are are serious, we can't wait 90 days or even 30 days. And, and, and I think that that is where we work. We help, we, we should be helping people be more nuanced about their environments, right?
There are environments where, yes, we should wait 90 days for a patch because we wanna make sure it doesn't break. But here's the big thing. That environment has to have compensating controls to account for the fact that they may be, and, and that nuance of how far do you, uh, uh, how much do you add in terms of compensating controls is a risk-based decision, right?
Uh, and requires a, um, a deeper understanding of the threat environment and, and the operating environment of where, how, what does your organization actually do? How does it do it? And so on, right?
Which to bring this back to, to, to Claude Opus, I find it fascinating that it accelerated it in my view. Like in, in this calculus, I see Claude Opus changing the threat environment. It basically said, look, right, for any kind of software that you're running, assume that someone can find vulnerabilities that much faster.
If that is true, however they find it, what changes in how we proceed? Oh, you know what? Perhaps we segment our network, these sec these machines here, or these systems here, we put on, on, uh, different controls than these ones and so on, right?
It's the red queen hypothesis. Sorry. It's the, like, you, you, you, you're, you're changing, you're running just to stay in place.
So I would posit That the reason why it's taking 90 days in, in Alan's specific case, but more importantly, the reason why it takes so long to roll out patches is risk. We know that, but my poit there is, you can't fire an agent or a script. Now you're probably thinking to yourself, yes, you can, you can disable it or whatever.
Yes. But you can't make it feel shame. And that's what people want when they, they point at somebody to say, you shouldn't have done this.
They don't want to improve the behavior. I mean, yes, they don't want it to happen. They want that person to feel shame for having done it.
They want to slow down the way that things are done, because risk does not like speed. That's always been a problem. But, But who in this equation?
In this case, it's the stakeholders in, in finance, in, in business continuity. The people who stand to lose money for any downtime, the people whose job is resource allocation and, and they don't like doing things twice, they don't like unknowns. Because a vulnerability is a known problem.
A patch that fails is an unknown problem because we don't know how to fix the patch. And Microsoft has actually had a problem with that as of late, the last couple of rounds of their big Windows 11 updates have had to roll a few things back because, oops, that interaction didn't work the way we wanted it to. In fact, I found about a one last night, it's causing problems because the patch for the patch is causing problems.
And so it's like your three patch patch patches behind where you should be, because every time you try to apply them, it breaks something new. So let me bring up this idea, because I, I, I, I was thinking about this way you guys were discussing about what happens when we just kind of open it up and say, okay, we trust the systems enough to solve these problems. What happens when the attackers know that?
So if you guys remember Star Trek, the next generation, when they captured Hue the Borg, they had a plan. They were gonna implant a, basically an unsolvable problem into Hue and send it back to the collective and cause the collective to crash. What happens when I know that AI agents are the ones that are standing for vulnerabilities and I start doing things to mess with them, to hide my real payloads?
Uh, remember the the infinitely expanding zip file problem where you had a, uh, like an 38 deep nested zip file that would constantly unpack itself until it overwrote your hard drive? Like, what if I leave one of those for an AI agent to find, or what if I code everything in poetry so that it evades the, the detectors like once? Now that is the no Star Trek one right there.
Remember, there was a, a species you spoke like in parables and poetry and Dharma and Gilad at gra. Exactly. Exactly.
But, But that's the thing, right? Is once I start crafting my evasion techniques to evade the scanners, who catches it after that? Because if I've turned my scanning over to the system, who goes back to look at the logs at this point and go, wait a minute, you know, Chaco and the wall spell, that doesn't sound like something one of my people would write unless it was Billy the Star Trek nerd over there in the dev system.
But like, that's the deal. They, the attackers will always modify their, um, systems to evade the protections that we got. It's one of the problems we face in the physical world, right?
As soon as we started scanning everything for explosives, what did they do? They parked the explosives outside of the building. And now you've got, that's why you have Ballards, and you can't park within 150 feet of a federal building now.
So, but I, I think here's the, here's the weak link in that Shane, Tom are, uh, the, the, the powers that be the people who own and operate the code, are they gonna purposely try to evade AI scanning vulnerability scanning? I can understand if the AI scanners are being for the bad guys, right? That might be a way to kind of camouflage or, or what have you.
But you know, for as long as I've been in security, and Fernando, you've heard this term, Tom, you've heard this term, this concept of self-healing systems. Mm-hmm. Right?
I think it was originally Cisco that came up with that actually self-healing systems where why can't the platform the same way the platform today pre, you know, and software supply chain security is applying das and SAS and SCA scans. Why can't the platform do an opus scan and find things as well? And, and you know what?
Keep it, keep it in the family. Keep it behind the curtain before it gets out in the public. And, you know, the so-called hacker's eye view from, from outside.
Why can't we build this into our platforms and into our process? Well, part of it is that it costs too much. Like, uh, that we go back to economics, right?
Fundamental problem we have in this industry is that it's externalized risk, right? The, uh, we are navigating the scenario of how do you, how do, who pays, who is paying for this, right? At the end of the day, it's the end user organization that is spending that, that's paying an FT to patch.
It's an end user organization that is paying an an ft to do the scan, scan to find what's vulnerable, right? Uh, it's a, are you paying failure to do the scan or is it you're just paying the AI company for tokens regardless, like the company's paying? So, uh, we go back to product liability laws.
At which point do we want thing to, to, to normalize in terms of who's, like we've had and as the three of us, like we discussed the changes at CI a a few weeks ago, right? Uh, where is secure by default in all of this, right? And, and Tom, I just wanna go back to the, the Star Trek references.
I wouldn't, I wouldn't mention those. I would go back to the hunt for red October. Do you remember how semen Jones found the red October?
Yeah, It was, he, he did not believe the computer, because the computer know what was going on. But, but what he did was he picked up the, so for, for those who haven't watched the red October, I highly recommended, right? Uh, but I, sorry for the spoiler there.
One of the way, the, the way that, uh, that, uh, a very, very, very clever solar man finds the, the, the, the red October, which supposed to have stealth propulsion drive, right? Is that he takes the found and he, and he speeds it up by a factor of 10, right? And then it becomes, what, what was just a a, a very low hum becomes a cho ch ch ch ch chuck, which is obviously manmade.
And that's how they find it, right? I mentioned this in the context of the way that we address these kinds of, of, of prompting injections and, and, and this type of bypassing of, of, or, or this time of, or this type of trying to gain the AI scanner is by having a second level scanner that doesn't watch for vulnerabilities. It watches for anomalies in the primary path, right?
Uh, so if you, it's something that says, look, nobody's supposed to be talking about poetry, right? That's an anomaly. So how we compose the systems, right?
It works in our favor too. It's not, let's, let's end this on a positive note, it's not just about the packers having lay of the land, it's that we can use these things for defense too. So I'll leave you with this thought.
The reason why we are where we are right now is because context is expensive. Yes. It's, it's, so if I ask you, have you ever seen the hunt for rud October?
The answer is easy, yes or no, it's binary. But then I say why? That's the expensive part.
So if we want to translate this into modern economics, the first part is easy, right? Detecting is the vulnerability there or not? Why or how is it exploitable?
That's where you're gonna start burning tokens, is because you've gotta provide the context. And that's why we have had such a hard time with this before, is because nobody likes yes or no, nobody likes on or off. They want to know context.
And for a human context is actually fairly easy to provide because our brains are wired to do it. But when we're trying to replicate that system in electricity, in water usage, in token consumption, that's when we start seeing the actual cost behind it. And I think that that's the challenge that we're gonna have to get over is because we're always gonna want to know why.
So I, I think that's the difference between just a scanner and an AI scanner. I, I think the nature of AI has to have the y built in. If you'll, Yes, It can't just give you a scan result, it has to have the y built in.
But you know, Fernando, you mentioned product liability loss. Product liability loss is what's reasonable for a product manufacturer to do, to prevent an injury, to make sure it's safe product, et cetera. That same reasonableness test, which is the test of negligence, will apply to owners of code who say, I don't wanna know.
I don't wanna use the AI scanner. I don't wanna know. I wanna bury my head in the sand.
And if something happens, I guess I'll find out. And, and then at some point a jury is gonna decide whether that was a reasonable risk and whether or not they're liable for someone's or many people's damages. And that's the way our system works.
And that's the way, and I, I, and I agree, and that's where we're going. And that's like, I, I perhaps I should start, stop talking economics and start talking law. I'm not a lawyer.
I don't come from a, I come from from a family of, of people in the legal profession. But, um, yes, that's where we're going. And, and that's how this industry is evolving.
And that's not necessarily a bad thing. It just means that we're now that much more strategic for society at large. Absolutely.
Let's embrace that. I think we're gonna go ahead and wrap it here, but please stay tuned for our Law versus ethics episode, which will be coming up soon. 'cause I just made a note that we're gonna talk about that.
But before we go, I wanna make sure that everybody knows that these are two of the hardest working men in the industry right now, uh, because they are writing so much stuff. Um, Alan, I'm pretty sure you probably wrote a blog post while we were sitting here knowing how, how productive You're Well, I did, I did pull it up when I want for later. I did some, you know, some of the ideas you and Fernando were talking about.
I put them on this screen and I'll, I'll play with it later. Unfortunately, I, in about 10 minutes, I have yet another video to do. But yeah, I'll get to it now.
One of the other things I wanted to bring up here is Textron Gang has been doing live recordings, like, like you've been broadcasting live. That's kind of exciting. We'll Be live.
So we recorded this at towards, at 10 in the morning East Coast time. I'll be live on Text Drunk Inc. Today at noon.
I'm live on Text Drunk Gang every day at noon. Make sure Monday to Friday, make Sure you're tuning in for that 'cause like that, those, those are some fun discussions. Um, absolutely.
Fernando, whatcha working on? So, uh, we're just, uh, kicking off. So we just published in December, uh, our cybersecurity decision maker survey data.
And I can spend five days talking about the, the, the, the data. We're just kicking off the new edition for that. So that should be coming the April timeframe.
Uh, before that, there's all the excitement around covering the, the RSAC conference and, and what's coming around that. So that, that's what's occupying my mind right now. As of right now, my calendar for the conference is 99% full kind of thing, but, um, but uh, yeah, that's, that's, that's what top of mind.
Plus writing about all things ai. Of course, I haven't, I'm writing on ai. I got one more thing I wanna throw on the pile for people.
By the time that people listen to this, we should have published our initial list of what we're calling the Quantum Security 25, the 25 Leading Thinkers and Quantum Security, post Quantum Security. We're doing that in, in partnership with our friends at Digi Cert. And if you think this AI stuff is crazy about security, what do you see?
What Quantum's gonna do to it? And uh, so go check that out as well. The Quantum Security 25.
I'll remind you that if you wanna see what Quantum will do to security, I suggest you check out the Seminole Work sneakers with Robert Redford. Um, That's a great movie. You astronomy, I get to quote that and hackers all the time, and people think I'm kidding and I'm not, because believe it or not, risk architecture really did change everything.
Thank you, Angelina, Julie. Yeah, movies. Were ahead of their time.
Well, we hope that you enjoyed listening to this episode 'cause I had a lot of fun recording it. But if you did, we would love it if you joined the conversation, check out our YouTube channel and maybe download this in your favorite podcast application of choice, like if you're running or mowing the lawn or whatever it is you do in, in your spare time. Uh, but when you do, do one of three things for us, leave us a rating, leave us a review or leave a comment, agree or disagree.
We, we just wanna have some fun discussion going on 'cause that really does help the show grow. com and the Future Room Group. com is the place to go.
You can also check out the Textron TV website or the techron TV app. I'm trying to get it running on an old iPod video. Uh, check in for the results.
But if you have any other smart device, I'm sure it'll work on that. Apple tv, Roku, iOS, Android, you name it. We'll also want you to check out Security Boulevard on X, Twitter and LinkedIn.
The handle is security, BLVD, and there's a lot more content that you wanna check out there. We wanna thank you all for tuning in. We'll check you all out next week.