‘Identifying vulnerabilities is no longer enough’: Companies need to focus on fixing exploitable vulnerabilities, not discovering as many as possible, says Checkmarx CEO

‘Identifying vulnerabilities is no longer enough’: Companies need to focus on fixing exploitable vulnerabilities, not discovering as many as possible, says Checkmarx CEO 图片 1
‘Identifying vulnerabilities is no longer enough’: Companies need to focus on fixing exploitable vulnerabilities, not discovering as many as possible, says Checkmarx CEO 图片 2

Artificial intelligence came at just about the right time, speeding up app and software development as the world started to contend with skills shortages, but it changed the pace so much that security teams have not been able to keep up.

Recently, we’ve seen AI being applied across multiple other domains with role-specific agents and tools, but that’s introduced its own challenges. While tools like Claude Code have proven a hit for generating, reviewing and editing code in seconds, security-focused tools like Anthropic’s Claude Mythos family of models are having broader impacts on the industry.

Anthropic itself has even admitted that Mythos is so powerful that the worry it could be abused by malicious criminals is extremely real – the Preview model is currently only available to a select number of pre-approved partners.

So with AI now capable of inspecting code, discovering vulnerabilities and suggesting fixes, do organizations even need as many human workers on the case, or can they get by with significantly fewer humans in the loop serving as AI reviewers? Recent layoffs have certainly implied as much.

The evolving role of security workers in an AI-first world

But with the entire lifecycle of development now amplified by AI, experts are warning that companies could actually be creating more work for themselves, and more than they could ever handle, leaving them facing strains from angles they weren’t previously exposed to.

For example, fewer than one in 10 companies now fix 90% of identified vulnerabilities within 90 days – implying that the volume of vulnerabilities is indeed increasing, rather than that fix efficiency is slipping.

Anthropic even revealed that its around 50 early Mythos Preview partners discovered more than 10,000 high- or critical-severity vulnerabilities – and thousands more of lesser significance.

Checkmarx CEO Sandeep Johri predicts we could soon find a balance, where vulnerabilities volume matters less and we revert our focus back toward…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论