惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
An Ounce Of Prevention Is Worth $4.88 Million Of Cure
Michael George · 2026-05-27 · via Forbes - Innovation

Michael George is CEO of Syncro, a SaaS company specializing in PSA and RMM software for managed service providers (MSPs) and IT teams.

getty

Forty-four thousand security professionals, 650 exhibitors and a floor full of solutions built to answer the same question: Once an attacker is inside, how do we stop them faster?

That framing—detect and respond, react and remediate—has defined security investment for the better part of a decade. Walking through the RSAC Conference in San Francisco this year, I kept hearing the same acknowledgment underneath the vendor noise: It isn't working well enough.

Additionally, a major AI announcement that landed days after the conference closed put an exclamation point on why the industry's posture needs to change, and urgently.

The Cost Of Responding Has Become Unsustainable

IBM's 2024 Cost of a Data Breach Report put the average breach at $4.88 million, a 10% increase from the prior year and the largest year-over-year jump since the pandemic. Seventy percent of breached organizations reported significant or very significant disruption to their business operations.

The number that deserves more attention is the root cause data. Security Magazine's 2024 analysis found misconfigurations driving 80% of security exposures. IBM's X-Force Threat Intelligence Index found misconfigured cloud services involved in nearly a quarter of all cloud security incidents. These are not sophisticated nation-state intrusions exploiting unknown vulnerabilities. They are failures of environment hygiene, correctable before any attacker arrives.

Incident postmortems keep revealing the same pattern: The organization already owned the tool that would have stopped the breach. The breach happened because the environment carried configuration drift, a policy went unenforced across endpoints or the foundational work fell behind. Reaction was (and is) expensive because prevention was skipped.

AI Is Arming Attackers Faster Than It Is Arming Defenders

The AI conversation at RSAC cut both ways, and the more substantive half was uncomfortable. The most serious discussions were about AI accelerating attack, rather than accelerating defense.

Microsoft's 2024 Digital Defense Report tracked 600 million cyberattacks per day across its customer base. CrowdStrike's 2025 Global Threat Report documented adversary breakout times falling to under 30 minutes, meaning the window between initial access and lateral movement inside a network keeps compressing. Threat actors now have access to the same models and automation capabilities that security teams do.

Then, days after RSAC, Anthropic announced something that put a hard edge on those conversations. They built a model, Claude Mythos Preview, that autonomously discovers and chains zero-day exploits across every major operating system and browser.

The model found thousands of critical vulnerabilities entirely without human steering, including a 27-year-old flaw in OpenBSD and a chained browser exploit spanning four separate vulnerabilities. The capabilities were significant enough that Anthropic declined to release it publicly, making it the first time a leading AI lab has openly said a model is too capable for general deployment. They instead launched a controlled defensive program, Project Glasswing, to use the model to patch critical software before those capabilities proliferate.

Once Weaponized, The Attack Surface Expands Faster Than Defenders Can Respond

The core concern is that once Mythos-class capabilities escape controlled programs and reach malicious actors, the number of AI-initiated attacks will increase exponentially, and the speed and sophistication of those attacks will outpace any reactive defense.

A joint analysis from the Cloud Security Alliance, SANS Institute and OWASP concluded that organizations are already likely to be overwhelmed by threat actors using AI to find and exploit vulnerabilities faster than defenders can patch them. And Anthropic's own documentation notes that Mythos "presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders." Detection and response, by definition, requires something to detect. Against autonomous exploit chains moving at machine speed, that window collapses.

The only viable answer is to not be the easiest target when that wave arrives. That means shift-left: investing in prevention now and hardening identities, endpoints and networks before an attacker finds the drift that makes the difference.

The Market Is Repricing Where Security Value Is Created

Q1 2026 cybersecurity financing hit $3.8 billion across 211 rounds, up 33% year over year. AI Security captured 46% of all capital deployed that quarter. The investment community is not waiting to see what AI-enabled attacks look like at scale. It already has a view, and it is directing capital accordingly.

The shift gaining momentum on the RSAC floor, in the technical sessions and in the conversations that happen off the main floor, is back toward prevention. Left of boom. Environment hardening over incident response. Getting in front of the failure rather than cleaning up after it.

The organizations that do this work now will be in a measurably different risk position than those still running reactive playbooks when Mythos-class capabilities become broadly accessible.

Government And Capital Are Paying Attention At The Same Time

On the policy side, Alexei Bulazel, the NSC's Senior Director for Cyber, delivered a keynote signaling the current administration intends to take a more assertive posture on offensive cyber operations, particularly against nation-state threats from China. That posture moved from conference keynote to active government engagement within days. The Federal Reserve and Treasury briefed major U.S. bank CEOs on the cyber risks the Mythos model represents.

I also attended a Moelis and Company event where former House Majority Leader Eric Cantor spoke about the federal legislative landscape. The convergence of private capital, bipartisan policy interest and enterprise urgency is real. Security is infrastructure now, and the legislative environment is catching up.

What This Means Right Now

The window between RSAC's conversations about AI-accelerated attacks and AI actually delivering autonomous zero-day exploit chains at scale turned out to be days, not years. The organizations that treat that as a distant problem will be in a fundamentally different position than those that treat it as a present one.

RSAC confirmed the direction. Glasswing confirmed the timeline.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?