Who will win the software vulnerability race? Five scenarios

This article is based on an episode from the Cyber & AI Perspectives podcast. Prefer listening instead? Listen to the audio version below.


Today I’ll speak about how new and powerful AI models will be available to both attackers and defenders, and I’ll walk you through five scenarios for who actually wins this software vulnerability race over the next couple of years.

AI can now find software vulnerabilities faster than any human — and it’s helping both attackers and defenders, opening up several possible outcomes over the next two years, from well-resourced organizations pulling ahead to under-resourced ones falling further behind.

Trends with software vulnerabilities

A couple of trends have become quite clear with regards to AI and software vulnerabilities. First, Mythos is much better at finding vulnerabilities than any human, and better than any AI model before it. Second, each of the main players in the AI industry wants to outcompete the others, so we can expect even more capable models in the future. Third, government control over AI models varies across countries, so we can expect that these powerful models will soon be available to everyone — if not from Anthropic or OpenAI, then from companies in other countries where governance and oversight are weaker. Fourth, bad actors are eager users of advanced AI technologies, so they will very gladly use those new models to find new vulnerabilities and boost their revenues.

But there is also a fifth trend, where the good guys — security professionals and software developers — are using AI models to find those same vulnerabilities much more quickly, and patch them more easily.

Optimistic, pessimistic, and realistic scenarios

So, who will win — the good guys or the bad guys? Unfortunately, it’s not that simple — there are several scenarios for how this can play out.

Let’s start first with an optimistic scenario: Permanent defender advantage. Here the logic is that defenders would have an edge, because they have full access to their own source code, build pipelines, and internal context, while attackers only see the outside.

In contrast, there’s a pessimistic scenario: Permanent attacker advantage. Attackers only need one hole, whereas defenders need to close all of them, and AI dramatically lowers the cost of searching.

But there is a flaw in these first two scenarios: the assumption that all defenders are equally capable. And this brings us to the third, and perhaps most realistic scenario: The two-tier scenario. The gap between well-resourced and under-resourced defenders widens dramatically. Large enterprises and cloud providers with AI-native security operations see breaches decrease, while SMEs, legacy industrial systems, and under-resourced public sector organizations become the soft targets where all attacks concentrate.

Two more scenarios for the transition period

But this two-tier scenario doesn’t happen overnight — there’s a transition period first. So let’s see two more scenarios for how this might happen.

Let’s first examine the scenario for well-resourced defenders — let’s call it the Catch-up scenario. In the short term, attackers move faster: AI lets them scan for unpatched flaws and exploit them before defenders even know they exist, so breaches spike in the next few months. But defenders pick up the same tools — using AI to find and patch those flaws faster than before — and the two sides reach an equilibrium. And then, within a year or two, patch cycles catch up to exploit cycles, and breach numbers fall back down — eventually even below where they started, since the software itself has been cleaned up in the process.

Now let’s see what could happen to under-resourced defenders — let’s call it the Drowning defenders scenario. Three pressures face such organizations, with little capacity to handle them. First, their software is increasingly AI-generated or “vibe-coded” — built quickly with AI, without much review — carrying more built-in vulnerabilities with no one to catch them. Second, AI lowers the skills needed for attackers, so far more people can now launch exploits — volume rises even though the sophistication of attacks drops. And third, vulnerability reports pile up faster than anyone can resolve them. The effect here is more flawed software, more attackers able to exploit it, and no working filter to sort what matters.

Same problems, new tools

So, what do we make of all of this? Of course, we don’t know whether or not these scenarios will play out like this. Something completely different might happen.

But there are two things I want you to take away from these five scenarios. First, AI changes the tempo, not the fundamentals. Organizations that get breached two years from now will still mostly be the ones that were slow to patch, slow to test, or slow to adapt — the same as now. And second, setting up automated testing, adopting these tools quickly, and staying disciplined about patching aren’t just technical issues — they’re organizational ones.

So, to conclude — I would argue that the tools are new, but the problems underneath them are not.

If you found this topic interesting, check out the podcast episode “Anthropic’s Mythos and the Future of Vulnerability Management,” where I interviewed Thom Langford, and where he explained why companies that aren’t ready will get hurt.

Advisera Dejan Kosutic

Dejan Kosutic

CEO & Lead Expert for ISO 27001 NIS 2, and DORA Leading expert on cybersecurity & information security and the author of several books, articles, webinars, and courses. As a premier expert, Dejan founded Advisera to help small and medium businesses obtain the resources they need to become compliant with EU regulations and ISO standards. He believes that making complex frameworks easy to understand and simple to use creates a competitive advantage for Advisera's clients, and that AI technology is crucial for achieving this. As an ISO 27001, NIS 2, and DORA expert, Dejan helps companies find the best path to compliance by eliminating overhead and adapting the implementation to their size and industry specifics.
Read more articles by Dejan Kosutic