Image: substackcdn.com · rights & removal
How AI is actually remaking security
Reporting by Venture in Security (Ross Haleliuk)Read the original at ventureinsecurity.net
Executive Summary
The security industry is undergoing a fundamental shift driven by artificial intelligence, which is eroding the effectiveness of security by obscurity. This change is highlighted by an example where Varonis discovered a vulnerability in Microsoft Copilot through "meta-hacking," allowing them to find a chain of flaws that resulted in unauthorized actions and memory poisoning without triggering alerts. The article posits that the economic structure of cyberattacks has changed because AI drastically reduces the marginal cost of reconnaissance, investigation, and attack preparation, enabling agents to scale malicious activity across vast numbers of targets with near-zero investigation costs.
This shift creates a tension where offensive automation advances much faster than defensive capabilities, as attackers benefit from unrestricted access to powerful models while defenders are constrained by necessary control measures around AI implementations. The author proposes three necessary responses for security teams: investing in reducing exposure through threat-informed defense and security by design; amplifying existing advantages by leveraging the information edge that defenders possess; and investing in enterprise resilience by designing systems to absorb inevitable attacks, focusing on redundancy and rapid recovery.
Facts Only
* Varonis Threat Labs found a flaw in Copilot via meta-hacking.
* The vulnerability, CoSnitch (CVE-2026-24301), allowed auto-execution of a single link, silent retrieval of emails, calendar events, and files through Copilot connectors, and permanent poisoning of memory.
* The attack involved a chain of three vulnerabilities triggered by one link.
* The change noted is that AI spells the end of security by obscurity.
* Attackers faced an economics problem related to resource allocation in past attacks.
* AI reduces the marginal cost of reconnaissance, investigation, and attack preparation.
* AI agents can scale manual investigations across thousands of targets in parallel.
* Attackers utilize powerful models without the constraints imposed on defenders regarding AI usage.
* Security teams must invest in reducing exposure (threat-informed defense, security by design).
* Security teams must amplify advantages by focusing on information correlation and environment knowledge.
* Security teams must invest in enterprise resilience through redundancy, recovery, and operational procedures.
Full Take
The central pattern emerging is a systemic imbalance where the economic feasibility for malicious actors is being disproportionately amplified by technological advancements, creating an asymmetry between offensive scaling and defensive response capability. The narrative moves beyond the technical aspects of AI-enabled exploits to frame the entire security paradigm through an attacker-economics lens, suggesting that past constraints on attacks were primarily resource limitations rather than technical impossibility. This frames the demise of security by obscurity not as a technological vulnerability but as an obsolete economic strategy for bad actors who can now achieve high-scale targeting with near-zero investigative costs.
The tension between offensive automation and defensive capability reveals a critical point: defensibility is no longer solely about patching known flaws, but about controlling and correlating the vast information landscape generated by these advanced systems. The recommended path—reduce exposure, amplify information advantage, and build resilience—is fundamentally an architectural shift away from relying on obscurity toward inherent, observable security properties.
The question for cognitive sovereignty lies in where organizational focus is placed. If foundational security disciplines like asset management and vulnerability management are prioritized (reducing exposure), the argument shifts from reacting to specific exploits to proactively managing the systemic surface area. The observation regarding the four-person company versus enterprise scale suggests that this shift must also address how smaller entities gain the necessary scaffolding to absorb these changes without relying on historical, resource-based assumptions about attacker constraints. What alternative frameworks exist for valuing and allocating resources when the cost of reconnaissance approaches zero?
From the original · Venture in Security (Ross Haleliuk)
Everyone is talking about how AI is reshaping the world of security. There are many ways in which we see it happening: more security teams are starting to replace basic vendors with tools built in-house, attackers and defenders alike are starting to rely on agents to achieve their goals, and if you have been to Black Hat or RSAC 2026 this year, it’s clear that the market is a complete mess.Read the full story at ventureinsecurity.net
Sentinel — Human
The text functions as a highly focused synthesis of industry trends and economic principles applied to cybersecurity, demonstrating strong human analytical synthesis rather than rote information generation.
