Why AI Is Breaking Software Security As We Know It
youtu.be
Interesting talk by Feross Aboukhadijeh, CEO of Socket, on where we are with security, open source, and AI.
How’s the whole skills.md thing going?
English is the malware now
Ok, what about MCP?
[Researchers] found nearly 2,700 instances of vulnerable servers running on the open internet and we know this has been actively exploited in the wild. This is the kind of thing that can happen when we start bolting MCP onto things.
So, not good?
The time to exploit has gone massively down. In 2018, you had 2.3 years to patch before there was an attack against you. Now you have about 10 hours. It’s wild. 10 hours from disclosure to active exploitation. If your team finds an exploit on Monday morning, attackers are using it on Monday afternoon. We can’t use our old, manual processes to respond. We need automation.