AI can find zero-days but still can’t reliably write secure code
Summary
Recent studies indicate that while AI models are becoming adept at finding zero-day vulnerabilities, they still struggle to reliably generate secure code. A significant portion of AI-generated code contains known vulnerabilities, highlighting a critical gap in AI's cybersecurity capabilities despite advancements in exploit generation.
IFF Assessment
AI's increasing ability to find zero-day vulnerabilities, coupled with its persistent inability to reliably write secure code, creates an imbalance that favors attackers over defenders.
Defender Context
Defenders need to be aware of AI's dual nature in cybersecurity: it can be a powerful tool for finding vulnerabilities but also a source of new weaknesses if used for code generation without rigorous security validation. This asymmetry means that while AI can help identify threats, its own code generation capabilities may introduce new attack surfaces.