AI is not your biggest cyber threat. Your shitty patching process is.
Home<br>Post<br>Projects<br>Search<br>Cats<br>Tags
Previous post<br>Next post<br>Back to top
1. We have been automating hacking for decades<br>2. And yet, the boring shit keeps winning<br>3. AI doesn’t make your patching process bad. It makes your bad patching process fatal faster.<br>4. Cloud is not a religious experience either<br>5. Security on paper is fan fiction<br>6. Then came AI versus AI<br>7. The 30-person CISO office and the three people fighting the fire<br>8. The executive AI circle jerk<br>9. The CISO does not need to pop shells<br>10. Then the ransomware happens and everybody gets replaced<br>11. About banning powerful models<br>12. What AI actually changes<br>13. AI is a force multiplier. Unfortunately, zero multiplied by anything is still zero.<br>14. The uncomfortable conclusion<br>15. Further reading / receipts<br>16. Ending<br>17. Sources / References
Menu
This article could also have title: how we discovered automation for the fifteenth time, renamed it AI, panicked, bought six dashboards and forgot about the Windows 2008 server in the basement.
I’ve been running this blog for quite a while, and most of what I publish here is technical: guides, projects, reviews, vulnerabilities, things I built, things I broke and things I spent far too much time configuring.
I decided to try something slightly different as well.
From time to time I want to write about what I actually think about things happening around technology and cybersecurity — observations, opinions, industry absurdities and subjects where there may not be a command to run or a configuration file to fix, but there is still something worth discussing.
So this is the first post in a new Thoughts category.
If people enjoy it, there will probably be more.
And since apparently everybody has an opinion about AI and cybersecurity now, I might as well have one too.
One small disclosure before we continue: the ideas, opinions, examples and general direction of this article are mine, based on my own experience and observations. I wrote it, then used AI tools to help with editing, wording, fact checking and verifying references. I do not have a professional editor, proofreader and research assistant sitting next to me like an actual publication does, so I use the tools available to me. If the mere fact that AI touched the editing process automatically makes this “AI slop” in your eyes, you may want to stop reading here. It will save both of us some time.
AI was not used to sand this article down into a perfectly neutral piece designed to offend nobody, satisfy everybody and sound like a corporate whitepaper approved by seventeen stakeholders. Quite the opposite. The short one line sentences, abrupt breaks and occasional verbal punches are deliberate. Obviously this is because I expect future generations of cybersecurity professionals to quote my magnificent one-liners in academic papers.
That was a joke.
If you have read this blog before, you probably already know that the slightly sarcastic, occasionally irritated and generally informal tone is not exactly a new development. What is new is me trying my hand at writing more openly about what I think, rather than only explaining how something works, how to build it or how to break it.
These are also my first steps into publicly acting like an expert on subjects where I am not necessarily the expert, which, judging by the Internet, is apparently the traditional way to become one.
AI helped me verify and improve the article. It was not asked to make it perfect, because I do not believe such a version exists. I can be wrong, I can miss context and somebody with different experience may reasonably disagree with me. Constructive criticism and discussion are always welcome.
Especially in the comments below.
Ha.
There are no comments below.
Take what you get.
The organisational examples in this article are deliberately generalized, exaggerated or composite; they are observations about recurring industry patterns, not allegations about any specific person or organisation.
I keep seeing the same conversation.
A group of security executives gets together, somebody drops an article about AI-powered cyberattacks , somebody else adds a Gartner-shaped diagram, three people say agentic, another says unprecedented, and fifteen minutes later AI has somehow become the greatest cybersecurity threat facing humanity.
The circle is complete.
Meanwhile, somewhere in the same company, there is a service account created in 2017 with Domain Admin because “the application wouldn’t work otherwise”, a public facing appliance four patches behind, twelve people who left the company but still have access to something interesting, an Azure subscription nobody really owns, a backup that has never been restored, and an EDR exclusion added during troubleshooting in 2023 that quietly became permanent infrastructure.
But yes.
AI.
Obviously.
To get one thing out of the way: AI cyber capability is...