惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News: Ask HN
Hacker News: Ask HN
D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
U
Unit 42
V
Visual Studio Blog
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG
博客园 - Franky
C
CXSECURITY Database RSS Feed - CXSecurity.com
大猫的无限游戏
大猫的无限游戏
P
Privacy & Cybersecurity Law Blog
T
The Exploit Database - CXSecurity.com
Simon Willison's Weblog
Simon Willison's Weblog
L
LangChain Blog
I
Intezer
V2EX - 技术
V2EX - 技术
Google DeepMind News
Google DeepMind News
T
Threat Research - Cisco Blogs
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
腾讯CDC
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
TaoSecurity Blog
TaoSecurity Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
F
Fortinet All Blogs
Project Zero
Project Zero
Blog — PlanetScale
Blog — PlanetScale
S
Security @ Cisco Blogs
量子位
M
MIT News - Artificial intelligence
美团技术团队
C
Cisco Blogs
S
Schneier on Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
G
Google Developers Blog
N
News and Events Feed by Topic
MongoDB | Blog
MongoDB | Blog
The Hacker News
The Hacker News
H
Help Net Security
S
Secure Thoughts
Scott Helme
Scott Helme
SecWiki News
SecWiki News
T
Troy Hunt's Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
博客园 - 叶小钗
O
OpenAI News
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 司徒正美
T
Tenable Blog

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July Exclusive: Major Australian jewellery brand confirms cyber incident Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Exclusive: Prime Properties listed as breach victim by M3rx ransomware DigiCert launches AI Trust architecture to secure agents, models, and content Winners of the 2026 Australian Cyber Awards unveiled Op-Ed: Redefining performance in the AI-powered SOC NZ council cyber attack leads to ID and financial data being exposed Alert! Wave of fake toll, parking scams impacting countries worldwide, including Australia and New Zealand Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims Aussie ice-cream franchise Gelatissimo suffers alleged hack by DragonForce Anthropic Mythos: The model, the myth and the mundane​ Report: Aussie small businesses doing it tough as job scams double, losses rise Cyber attacks on medical devices pose ‘significant’ impact on real-life patient care Twisted Firestarter! Aussie, US, and UK cyber agencies warn of Cisco malware campaign Generation Life informs customers of “cyber incident” as owner shares incident with ASX CBA launches new scam-finding AI agent Sri Lankan government hack sees $3.7m destined for Australia stolen CrowdStrike extends cloud threat detection to Google Cloud Hey big spender! Microsoft to invest $25bn in Australian AI infrastructure Genetec marks Sydney milestone with visit by high commissioner of Canada to Australia Rental platform under fire for collecting excessive personal data Exclusive: SA genealogical research firm confirms cyber incident following SafePay ransom claims PentenAmio announces acquisition of Armour Communications Exclusive: Aussie passports compromised in alleged Favelle Favco data breach Cutting edge: Anthropic’s Claude Mythos preview is a ‘double-edged sword’, expert says Treasury staffer charged for NSW government data breach Op-Ed: AI won’t patch the holes in your SOC Game on! More than a third of FIFA World Cup 2026 partners expose Aussies to email fraud risk Dark web markets: A complete Aussie identity costs as little as $200 Exclusive: NSW-based Strata Republic allegedly breached by Kairos ransomware group Mortgage fraud now harder to detect thanks to AI McGraw Hill confirms ShinyHunters breach, won’t confirm if any Aussie customers impacted Update now: Active exploitation of Nginx UI vulnerability CVE-2026-33032 underway National Defence Strategy 2026: Spending on military cyber capability to reach at least $15bn Exclusive: Qld pharmacy chain allegedly breached by Kairos ransomware Op-Ed: ASIO has broken its silence on cyber crime, and you should listen Too-hard basket: NIST to scale back CVE updates as vulnerabilities soar OpenAI launches GPT 5.4-Cyber in response to Anthropic Glasswing NZ racehorse auction stalled by cyber attack Op-Ed: Microsoft April Patch Tuesday reveals 167 vulnerabilities ADF joins international military exercise focused on cyber resilience and multi-domain operations OpenAI CEO’s home targeted in attempted drive-by just days after Molotov attack Exclusive: Aussie communications company Mastercom ‘aware’ of INC Ransom claims Booking.com confirms cyber incident, customer reservation data potentially compromised Report: Majority of CISOs not ready for the next big cyber attack Why Anthropic’s Project Glasswing matters, and what CISOs need to know WASTED! GTA developer Rockstar Games confirms hack as ShinyHunters demands ‘pay or leak’ Exclusive: Gunra ransomware lists Eric Davis Dental as breach victim Op-Ed: Why zero trust for OT should start at the boundary, not the boiler room Exclusive: NSW pharmacy management firm allegedly breached by INC Ransom US Treasury launches intelligence-sharing initiative with crypto companies Citigroup says AI speeds up new account openings Cyber war: Pro-Iranian hackers vow to fight on despite a fragile ceasefire with the US Exclusive: Victorian resort hotel allegedly breached by Space Bears ransomware Game on! Nationwide student competition aims to tackle Australia’s cyber skills gap Exclusive: Anubis ransomware gang claims hack of WA-based Shine Aviation Ransomware group claims hack of legal giant Jones Day Anthropic, partners announce Project Glasswing cyber security initiative Exclusive: Aussie tech firm Seeing Machines confirms potential cyber security incident Space Bears claims cyber attack on Sydney dental clinic
Q&A with Adam Meyers: “It's going to be an absolute bloodbath.”
david.hollin · 2026-05-15 · via Security

Cyber Daily chats Claude Mythos and how to tackle the flood of AI-powered vulnerability disclosures with CrowdStrike’s Senior VP, Counter Adversary.

Cyber Daily: Everyone’s talking about frontier AI and its power to find vulnerabilities and speed and scale, but there seems to be a lot of noise and not much signal right now. What’s the real deal?

Adam Meyers: Well, you know the real deal is that vulnerabilities are always happening.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

I think we've seen a couple of interesting experiments and some interesting data around one particular model, in particular Mythos, right? We've been saying since November, or even before, that we're looking down the barrel at an influx of vulnerabilities, because AI is ideally suited for being able to find and exploit vulnerabilities. When you think about how you find a vulnerability, there are really two ways.

There's what I like to call the artisanal way, where you find a target, and you completely reverse engineer everything about it, how it works, and you find a bug, and you write the world's most beautiful, perfect exploit that will enable you to exploit that target. But then what most people do to do this at scale is fuzzing. And with fuzzing, you're throwing a bunch of garbage at an input, and you're hoping it crashes the program or the software, and then when that software crashes, it creates a log or a crash dump, which has information about what caused it to crash, or the state when it crashed.

And then if you look at that log, you can see if it's exploitable, and perhaps it gives you a path to exploitation. So that's kind of the two ways that people do vulnerability exploitation.

What we've seen so far with AI is they're using it for static code analysis, which is great if you have the source code, which is why you see a lot of the work so far has been done that's public is on open source projects, because you have the source code for those; when you start getting into black box testing, you actually have to instrument the software. And there are a lot more steps to it that are, I think, a lot more complex. It's doable with AI, but for what we've seen so far right now, it's really been focused on the software source code and finding bugs there.

AI can be really useful at dialling in what garbage you throw at the input to try to break the software. And it's extremely good at analysing the crash dumps to see if they're exploitable. You know, for that, I would argue even smaller models, not general-purpose models like CHatGPT or Mythos or something like that, but you could build custom models that will really be dialled in and more deterministic, meaning you're going to have the same outcome every time. And then you can use a general-purpose model to help write the exploit.

So I think we'll see, over the next couple of months, more specific tools and models for different pieces of this. And you're already hearing about harnesses and scaffolding inside the AI. That's all because that's how you can help the AI get access to do the thing that you're trying to ask it to do.

But yeah, this is coming either way, and I think it's model independent. The thing that everybody's focused on is the exploits and zero days, right? We've been kind of trained by the media and the security industry that zero days are the thing that you can't plan for, and it's the worst possible situation, right? A cyber Pearl Harbor, or something to that effect. And the reality is, a zero day is not that big of a deal.

We find zero days once a quarter, on average, at CrowdStrike. And for us, zero day is not the end of the story. It's the start of the story, because everything that happens after that zero day gets exploited by the threat actor, whether it's a human or a machine, they still have to move laterally, they still have to escalate privilege, they still have to accomplish the thing that they're trying to do. They're not just finding a bug; they're trying to execute a mission.

So that's where we hunt, right? That's where we find bad guys. Every single day at CrowdStrike, we look at 6.7 trillion events per day, and we see something like 65 million events per second at peak that we're hunting on. So there's a tremendous amount of data, a tremendous amount of grey space for us to hunt adversaries, whether they be machine or human. So I don't really think that that's going to be the big issue here.

For me, the big issue is on the solution to this, which is… If you look at last year, there were 48,000 roughly, CVE or common vulnerability exposures, and that's a lot. We’re already looking at, I think, a 27 per cent increase in the first quarter of this year over last year. So there's more bugs being found. Whether it's by a human or a machine, is irrelevant. The Chinese can weaponise a vulnerability inside of two days when it's disclosed, and that's what we call an n-day, when there's a vulnerability that's found and a patch is available. So threat actors have figured out how to weaponize N days, China in particular, very quickly.

In fact, at their Tianfu Cup, which just wrapped up in January, there was a whole track that was really about “How do we weaponise known vulnerabilities”, right? Because they understand the value of that. But let's say AI has an impact here. Let's say it's modest, which I think, you know, 10x would not be a leap of imagination for what an AI can do.

So let's say a 10x is it, and there are now 480,000 CVEs. I don't think the CVE system can even handle that. But now, as a CISO, as a defender, as somebody that's responsible for patching systems, you have to start prioritising, because you can't patch everything at once. That's impossible, and most organisations… I mean, take a look at Salt Typhoon, what we call Operator Panda. They hacked into a telco and got access to the President of the United States, when he was president-elect; they got access to his cell phone data. That's a hard target in my mind, and they did it using not a zero-day but a two-year-old Cisco vulnerability that wasn't patched, right?

That's a huge problem. So now, if you 10x the number of vulnerabilities that all these folks are dealing with, it's going to be an absolute bloodbath.

Cyber Daily: So, how do we educate organisations to follow that basic cyber hygiene and patch?

Adam Meyers: Well, it's not just about patching, which is, I think, where a lot of people think “Oh, it's just simple, just patch”. But when you patch something…

Think about that telco example, right? Let's say it was a Cisco switch that was routing traffic at the telco. If they shut that down to patch, they're going to disrupt how many phone calls, how many text messages, how much network traffic? And so they have to have a good strategy for patching, and they have to schedule downtime, they have to have failover, and they have to have all of these conditions that are ideal so that they can do the patch, and if something goes wrong with the patch, they're running up against the clock, and they're going to have a real bad day.

So patching is not as simple as patching, and with the number of vulnerabilities, 48,000 vulnerabilities, you can't patch everything, so you have to prioritise. Organizations have historically prioritised based on one or two things. The first one is prevalence. Kind of like an old method, which is to say, if there's a bug or if there's a patch that I need to issue, how much of it is in my environment, and the one that's the highest amount, that's what I'm going to patch first.

That methodology has kind of gone by the wayside, and more organisations gravitate towards criticality-based patching. So they look at the CVSS, which is a component of the CVE, and they look at that score, and they say, “Okay, if it's above a certain threshold, that's break glass,” right? We're gonna have a network outage. We're gonna do whatever we need to do, because that's going to be a bad day if somebody exploits that.

The problem is that they're looking at these vulnerabilities, and they're looking at that CVSS score. So let's go with Palo Alto. They have this GlobalProtect VPN product, and a lot of people use it, and there were two vulnerabilities in GlobalProtect about a year and a half ago. The first one was a remote unauthenticated access. So any user who exploited this vulnerability could get unauthenticated access to the device, unprivileged but unauthenticated access to the device, and that had a CVSS score of like 5.5 and organisations would look at that, and they would say, "Well, that doesn't hit our threshold, so we're not going to patch it. We'll schedule that for the next maintenance window,” right?

Then they look at the next vulnerability that comes out; same time, same patch cycle. And this one is a local privilege escalation. That's 8.5, that means that if you have access to that device, you can escalate privilege to system or admin or whatever it is. And they look at that, and they say, “8.5 that's at our threshold. We should probably patch this”. And then somebody pipes in, and they say, “Well, it's 8.5, but it's a local privilege, so they'd have to have access to the box to be able to use it. So it's really not that big of a deal, right?”

And then they forgot about that first vulnerability. So now if you chain those two together, what is going to happen is it's a kill shot, right? Unauthenticated access with a local privilege escalation – game over. And they don't look at those two together. They're looking at them in a bubble, and so that really makes it difficult for them to leverage criticality-based patching.

And then the third model, which is one that I promote, and I think people should adopt, is to look at what is being exploited in the wild, because then at least you know this is actively being exploited. In that Palo Alto situation, both were being exploited together in the wild, CISA puts out something called the Known Exploited Vulnerability Catalog, and that lets organisations see all the things that are actively being exploited, and we contribute to that all the time. We'll notify CISA if we see vulnerabilities being exploited, they add it to the catalogue, and that helps people patch.

So I think particularly as we start to see the increase in vulnerabilities at the hands of AI, and the effectiveness of those vulnerabilities that organisations are going to need to certainly adopt a prioritisation based off of what is actively being exploited, and that's where threat intelligence will be really useful for them to understand what's out there, who's using it, and what are they doing with it.

Cyber Daily: You mentioned the volume of vulnerabilities that are being reported, and it's just skyrocketing year over year, quarter over quarter. And I know that recently, NIST said that it was no longer going to be enriching every CVE that crossed its desk; it was going to announce new prioritisation criteria. Is that a response to this Vulnerability Apocalypse, that we just can't cover all of them?

Adam Meyers: I think it's a response to a few things.

I mean, I think they've had some funding issues as well, associated with CVE. And I think, you know, CVE was designed many, many, many years ago, when we had far fewer vulnerabilities, far less software sprawl. And, oftentimes, as you look at the number of vulnerabilities year over year, I think it wasn't built to this scale. And I think they recognise that it's unmanageable.

And there are some other issues with CVE. For instance, you don't see a lot of cloud-based CVEs, because if it's a SaaS vulnerability, they patch it on the cloud side; there's nothing for the customer to do. So you don't really need to call it out as a CVE, because once the bug is found, you fix it, it's game over. So there are aspects of the whole vulnerability landscape that have been changed by cloud and by SaaS.

CVE also doesn't cover… If you look back at the last couple of weeks, we've seen a massive uptick in supply chain attacks, and they're targeting software libraries that are being used across the supply chain, and CVE doesn't account for that. So I think it is not the solution that it was back when you were dealing with the Morris worm and a handful of Unix vulnerabilities. To defend NIST here, you can't possibly expect them to cover every single product. And when you look at the enrichments, they're not super detailed, you know, it's not, it's basically metadata, usually, just what's come from the initial disclosure anyway. It's usually exactly the same thing, and the vendors typically have way more information in their disclosure than the CVE does anyway.

CVE is really useful for categorising vulnerabilities when you're doing a vulnerability assessment on a network, and then you could give them a list of all the CVEs that you found, and frankly, most of the auditors that were doing that had no idea what those vulnerabilities were anyway. I've been in places where they found a vulnerability that was 15 years old, and they're like, “You need to patch this”. But as far as I’m concerned, you need to burn that system out in the woods, because if it's been exposed for 15 years, vulnerability patching is not going to fix your problem.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: