AI tools are outpacing signature-based defenses as novel exploits get cheaper
Google's Big Sleep AI agent discovered a live SQLite vulnerability, CVE-2025-6965, and patched it before any attacker could exploit it — marking the first time an AI preempted a real-world exploit. Separately, autonomous pentesting tool XBOW topped HackerOne's US leaderboard in June 2025, submitting around 1,060 vulnerabilities and outperforming human bug hunters. Research from DARPA's AI Cyber Challenge showed autonomous systems finding and patching real-world bugs in open-source software at an average cost of $152 and 45 minutes each. Meanwhile, Anthropic reported a Chinese state-linked group using an AI model to autonomously execute 80–90% of an espionage campaign, and Google documented malware that queries an LLM at runtime to evade antivirus detection. Security experts warn that traditional signature-based defenses — firewalls, WAFs, and IPS feeds — are structurally unable to detect novel exploits, which now account for 70% of real-world attacks and are increasingly being generated cheaply by AI.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in