惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
宝玉的分享
宝玉的分享
Jina AI
Jina AI
Martin Fowler
Martin Fowler
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
GbyAI
GbyAI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Privacy International News Feed
D
DataBreaches.Net
Security Archives - TechRepublic
Security Archives - TechRepublic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Scott Helme
Scott Helme
U
Unit 42
Hacker News - Newest:
Hacker News - Newest: "LLM"
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
Vercel News
Vercel News
I
InfoQ
N
Netflix TechBlog - Medium
罗磊的独立博客
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
S
Securelist
S
Schneier on Security
T
Troy Hunt's Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cisco Blogs
H
Hacker News: Front Page
Spread Privacy
Spread Privacy
T
Tenable Blog
博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
Recent Commits to openclaw:main
Recent Commits to openclaw:main
D
Darknet – Hacking Tools, Hacker News & Cyber Security
博客园_首页
量子位
AI
AI
L
LINUX DO - 最新话题
J
Java Code Geeks
小众软件
小众软件
爱范儿
爱范儿
月光博客
月光博客
H
Help Net Security
aimingoo的专栏
aimingoo的专栏

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
Why Mythos Finding Vulnerabilities Faster Doesn't Make You More Secure
Seemant Sehgal · 2026-05-29 · via Forbes - Innovation

Seemant Sehgal is Founder & CEO of BreachLock Inc., a leader in Continuous Attack Surface Discovery & Penetration Testing as a Service.

getty

​Every few weeks, I see the same thing happen. A major AI lab ships a new frontier model, the security industry erupts with headlines about autonomous vulnerability discovery and my inbox fills up with variations of the same question from CISOs and security leaders: "Does this change everything?"​

My answer, after 30 years in this industry—first running security programs as a part of the CISO's office, then building security products from the vendor side—is always the same: Faster discovery has never been the constraint. And until we're honest about that, we'll keep celebrating the wrong milestones.​

The Metric That Actually Matters​

The AI models like Mythos getting attention right now are genuinely impressive. Discovery is faster, broader and more autonomous than anything I saw coming up in this industry. That's real progress, and I don't want to dismiss it.​

But here's what I've noticed after three decades of watching technology waves reshape this space: Every leap in discovery capability tends to widen a gap that already exists. This is the gap between what you find and what you actually fix.​

When I was running security programs, the problem was never that we couldn't identify enough vulnerabilities. It was that we had more findings than we could confidently validate, more validated findings than we could intelligently prioritize and more prioritized findings than engineering teams could absorb without disruption. AI acceleration doesn't close that gap; it makes it larger and faster.​

What Faster Vulnerability Discovery Actually Produces​

I want to be specific about what happens operationally when discovery speed increases without equivalent maturity in the rest of the pipeline.​

First, shorter time-to-exploit. When AI dramatically compresses the time between finding a vulnerability and weaponizing it, defenders don't benefit equally. Attackers, who don't have change management processes or DTAP constraints, move faster on new discovery than most enterprise security teams can respond.​

Second, more noise. The most persistent operational problem I see in security programs isn't a lack of findings. Instead, it's an overabundance of unvalidated ones. AI-powered scanning at scale produces more alerts, more potential issues and more tickets. Volume creates the illusion of progress while burying the signal that actually matters.​

Third, prioritization becomes exponentially harder. There's a paradox at the center of modern security operations: The more you can find, the harder it becomes to decide what to act on. Most organizations I've worked with are not capacity-constrained on identification. They're judgment-constrained on prioritization.​

The Three Things AI Still Can't Change​

I've watched this dynamic play out through every major technology wave, namely automated scanners, bug bounty platforms, cloud-native tooling and now AI. And through all of it, three things have remained constant.

​A potential vulnerability and a confirmed, exploitable vulnerability in your specific environment are completely different threat categories. Confirming real impact, understanding what that finding means for the business and determining whether it represents actual risk—this work hasn't been automated away. Unvalidated findings don't move the needle; they just create work.​

Why Prioritization Requires Judgment That Tools Don't Have

Risk is not a CVSS score. It's a function of your environment, your business model, your regulatory exposure, your threat actors and a dozen other variables that differ from organization to organization. I've seen critical-rated vulnerabilities that represented low real-world risk and medium-rated findings that were existential for a specific business context. The judgment to tell those apart reliably still lives with experienced practitioners.​

The Demand For Discipline That Compounds

Fixing vulnerabilities without introducing new instability is an operational discipline. Whether you're following structured release processes, change management frameworks or continuous deployment pipelines, faster discovery puts more pressure on remediation workflows, not less. Organizations that haven't matured that discipline find that AI-accelerated discovery creates a larger backlog, not a shorter one.​

Where I've Seen Organizations Actually Improve​

The security programs that have made meaningful progress on outcomes—not just on metrics—share a common pattern. They stopped asking "How do we find more?" and started asking "How do we close the loop faster?"​

That shift looks different depending on the organization, but it usually means treating validation as a first-class step, not an afterthought. It means building continuous adversarial testing that mirrors how real attackers operate, not just generating snapshots on a quarterly schedule. It means integrating discovery, validation, prioritization and attack surface management as a connected operational loop, not separate tools producing separate reports that no one has time to reconcile.​

Most importantly, it means measuring outcomes, not findings generated, not scans completed, not tickets opened. How quickly does a confirmed high-impact finding reach remediation? How much of the remediation queue represents real risk versus noise? What percentage of last quarter's validated findings are actually fixed?​

Those numbers tell you whether you're improving your security posture or just generating more activity.​

The Question Worth Asking​

The next frontier model announcement will likely come in a few weeks. It will be faster, broader and more capable than what came before. That's the direction this technology is moving, and it won't stop.​

When it lands, I'd encourage security leaders to resist the reflex of asking "Can this replace our current tooling?" and instead ask: "Do we have the operational maturity to take advantage of this?"​

Because the honest answer, for most organizations, is that they don't yet have a validation workflow that can keep pace with what they're already finding. They don't have a prioritization process that produces consistent, defensible decisions. They don't have remediation velocity that matches discovery velocity.​ They cannot visualize attack paths.

No AI model closes those gaps automatically. Those are organizational and operational problems, and they require organizational and operational solutions—with technology as an enabler, not a substitute for doing the hard work.

The Imperative To Validate Attack Paths​

The future of security isn't about finding more vulnerabilities. It's about validating exploitable vulnerabilities and concluding how they fit in an attack path. Capabilities such as adversarial exposure validation combined with human judgment can help the industry cover the gap between finding and fixing.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?