"AI is giving attackers a huge advantage!"

"Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

@cR0w permission to pop this up on LinkedIn?

:D

@cR0w
It briefly amazed me, now it just dismays me. I work for the government. Almost all our management and about half the devs are all-in for AI. I'm older and more sceptical. I've seen a few silver bullets fly by in the past, and I don't have much desire to rearrange my job to prompting, reviewing, and hoping the AI code turns out okay. I should be able to hold out until retirement, but younger folks don't have that luxury.

@AdamDavis @cR0w

Yeah and we're gonna "retire" as they crash the markets and decide all the social security we've paid is theirs not ours

@cR0w Until recently I worked somewhere that was pressuring developers into using the AI tools it was paying for.

One feature of working for that company was its "security" - pretty well anything you tried to do ran into some roadblock or other because "security".

So I asked the AI: "How do I get round this 'security' feature?"

And instead of reporting me to security it actually gave me an answer. Which, in the nature of code generated by AI, didn't actually work, but it gave me a clue as to how to come up with something that did.

@cR0w And even Western gov's are taking decisions using AI-powered chatbots that got trained with data up to the 90's it seems.

@cR0w 2026 Cybersecurity Priority List (according to LinkedIn)

AI
AI for Security
AI Security for AI
Agentic SOC
AI-SPM
CNAPP
CWPP
CSPM
CIEM
KSPM
DSPM
ASPM
.
.
.
Patch your shit
The fucking basics

@cR0w Also trust! I remember when certain small companies used to set themselves apart and build a lot of goodwill by having humans create things for the community.. now it's all slop all the time coming from their social accounts

@iagox86 @cR0w I used to love writing short blog posts for my company. Nothing earth shattering, but just interesting enough that it kept our name circulating and maybe, just maybe, helped out a few people interested in the same problems.

Then we got bought, and the blog was all shaped by marketing from then on. (same at the company after, as great as it was in other ways). Community engagement became just plain engagement.

Find me another small company of nerds who just want to help out others, and share bits of what they've learned for the community, and I'll be happy.

@cR0w That was the point.

@cR0w

People, not the machines, have chosen to destroy these things by pretending that LLMs are the AGI they were hungry for, and told they were getting, and investing accordingly despite all evidence to the contrary.

@cR0w AI is giving its user an advantage and that only shows how human nature is destructive in general. It's still time to apply it to better means. What are YOU doing?

@cR0w I blame Devo...

D - E - V - O

@cR0w everyone going on about supply chain attacks (and some trying to add dystopian af shit everywhere in the name of "preventing it")

while just letting ai walk right in 

@cR0w "AI is giving attackers a huge advantage."

Mhm yup you couldn't set up proper security from the sounds of things, that or you let AI "code" a core component of the software like the fucking kernel.

So never let AI touch critical code.