The CISO dilemma: Why AI speed makes security basics essential | TechTarget

https://www.techtarget.com/rms/onlineimages/iot_g1226985345.jpg

Enterprise security leaders are routinely inundated with vendor hype claiming their AI tools will single-handedly rewrite the Security Operations Center. In the trenches, however, defenders are still fighting broken identity and access management systems, unpatched web app vulnerabilities and third-party supply chain exposure.

This operational reality took center stage at the CyberRisk Alliance Cybersecurity Summit in Bellevue, Wash., yesterday (Oct. 1), where panelists and practitioners concluded that AI speed doesn't replace security basics -- it magnifies every existing flaw.

AI revitalizes 20-year-old vulnerabilities

A common misconception across boardrooms is that AI empowers adversaries to launch entirely novel classes of attacks. In practice, AI simply drops the barrier to entry for adversaries to deploy decades-old attack vectors at unprecedented speed and scale.

As Johnny Wong, principal consultant at Veracode, highlighted during the CyberRisk Alliance event, LLMs trained on public code repositories are actively reintroducing 20-year-old OWASP Top 10 vulnerabilities -- such...

Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE

Read more