WorkThe story, in brief

Microsoft pushes safer software construction as AI makes offense cheap

AI just made vulnerability discovery cheap. Microsoft's chief AI security officer says the entire defensive playbook has to change.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

As AI lowers the barrier to finding and exploiting software vulnerabilities, cybersecurity teams must shift from patch-and-react to building fundamentally safer software from the start — a structural change in how the profession operates.

The key facts

8 to know
  1. David Weston, VP of AI Security at Microsoft, keynoting Black Hat USA 2026

  2. Core argument: AI abundance of offensive capabilities vs. scarcity of vulnerabilities has flipped

  3. Implication: reactive patching model is obsolete; proactive secure-by-design is now the industry standard

  4. This represents a profession-wide shift in cybersecurity practice and responsibility

  5. David Weston, VP of AI Security at Microsoft, keynoted Black Hat USA 2026 on AI-driven offense abundance

  6. Core thesis: AI is ending scarcity of vulnerabilities, making offensive capabilities cheap and abundant

  7. Industry response: moving from reactive patching to fundamentally safer software construction

  8. Implication: cybersecurity teams must reorganize work practices and methodology

Go to the source

SiliconAnglesiliconangle.com

Publisher excerpt: AI is ending the era of scarce vulnerabilities, making powerful offensive capabilities abundant and forcing cybersecurity teams to move beyond reactive patching toward fundamentally safer software construction. That reality was the core of a Black Hat USA keynote by David Weston (pictured), vice…
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI illustration by KeyNews
Work01

The Emerging M&A Map For AI Agent Security

As agents move from pilots to production with real system access, enterprise security models are breaking. The M&A map is forming around who controls agent permissions, monitoring, and governance — a new class of identity management problem that practitioners need to architect for now.

Crunchbase News
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

AI privacy budgets: Ask for the calculation, not the claim

Enterprise AI buyers are accepting privacy budget numbers without verification. This deep dive explains what questions to ask vendors about federated learning privacy claims, and why the gap between contractual promises and operational evidence is where real exposure lives.

CIO
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

Andrew Kelley Interview: Why He Built Zig, Banned AI Contributions, and Moved Zig off GitHub

Open-source governance is shifting in response to AI-generated contributions. Zig's formal ban and migration off GitHub signals broader industry concern about code quality, maintainer burden, and the cultural impact of automated submissions — a flashpoint for how AI changes the work of software development.

InfoQ AI/ML