Home » Security News » Cyberattacks Are Evolving Faster Than Ever. Securi...

Cyberattacks Are Evolving Faster Than Ever. Security Updates Are Catching Up

Cyberattacks Are Evolving Faster Than Ever. Security Updates Are Catching Up
Photo: FlyD / unsplash.com

Add Techlomedia as a preferred source on Google. Preferred Source

The way companies deal with software security is changing. Cyberattacks are becoming more sophisticated, but security teams now have a new advantage that was not available at the same scale a few years ago. I am talking about AI. Companies are using AI to find vulnerabilities, investigate large amounts of code, test possible fixes, and move security issues through their development processes faster.

This is important because the traditional approach to software security has a natural limit. Large software projects contain millions of lines of code, and security teams cannot manually inspect everything or test every possible attack path. Some vulnerabilities can remain hidden for years because they are difficult to identify or require a combination of conditions to exploit. AI is now helping security teams search through this complexity at a much larger scale.

Google’s work on Chrome is one of the clearest examples. The company has been using AI for security fuzzing and vulnerability research, and its newer systems are also being integrated into the software development process. Google says its Big Sleep and CodeMender systems now run in its continuous integration environment every 24 hours across Chrome changes. In May, these systems helped block more than 20 vulnerabilities from reaching production, including a critical issue. Google has also found a Chrome vulnerability that had existed in the codebase for more than 13 years.

AI is also being used beyond simply finding a bug. Google has described multi-agent workflows where one AI system generates a possible fix while another reviews it. Other AI agents can help write tests for different supported platforms and configurations. This means AI can become part of the entire security process, from identifying a problem to helping developers test and fix it. Google says these systems can save developers weeks of work in some cases.

Microsoft is taking a similar approach internally. Its MDASH system uses more than 100 specialized AI agents to search for different classes of vulnerabilities, validate potential findings and help generate fixes. Microsoft claims its security teams used the system to find 16 vulnerabilities in parts of the Windows networking and authentication stack, including four critical remote code execution flaws. The system is now being used by Microsoft engineering teams across areas including Windows, Azure and identity.

What is interesting here is that these systems are not simply replacing security researchers. They are being used to extend what existing security teams can do. Microsoft itself describes MDASH as a way to give security teams greater reach into areas that would be difficult to cover through manual analysis alone.

Security researcher Indrajeet Bhuyan believes this is one of the biggest changes AI is bringing to security research. “AI is definitely making researchers faster, but I think it is also making some vulnerabilities practical to find that would previously have taken too much time to investigate,” he says. AI can help researchers with code analysis, attack paths, test cases and proof-of-concept development, while humans still need to validate the findings.

The same idea can be seen in Google’s approach, where AI agents are being added to existing development, testing, and review processes rather than operating as a completely separate security function.

The other major change is happening after vulnerabilities are found. Finding a security bug is only a part of the problem. Companies also need to understand its impact, develop a fix, test that fix, and distribute the update before attackers can exploit the vulnerability. Microsoft says it is incorporating advanced AI models into its Security Development Lifecycle so vulnerabilities can be identified and mitigations developed earlier. The resulting fixes still go through Microsoft’s existing security processes, including its regular security updates and out-of-band updates when required.

This is gradually pushing software security toward a more continuous model. Instead of relying only on periodic security reviews, companies can keep scanning code and development changes as they happen. Microsoft says its automated security systems now remediate millions of vulnerability instances in its environment each month, while Google is running AI security systems continuously as part of Chrome’s development process.

There is also a practical reason why this change in approach matters. Attackers are using AI too. Microsoft says modern attackers can use advanced AI models to discover vulnerabilities, identify attack paths, and scale parts of the exploitation process faster than traditional manual methods. That creates pressure on software companies to reduce the time between discovering a vulnerability and fixing it.

Bhuyan sees the same shift from the perspective of security researchers. AI can help researchers move from an initial idea to a working exploit much faster by analysing code, finding attack paths, generating test cases and trying different bypasses. “The researcher still needs to validate the finding, but AI can significantly reduce the time from an idea to a working exploit,” he says.

The result is not a world where security updates become unnecessary. It is almost the opposite. As software becomes more complex and attackers become faster, security updates need to happen sooner and security teams need better tools to keep up. AI is becoming one of those tools, especially for the parts of security work that involve searching through huge amounts of code, finding unusual patterns and repeatedly testing possible fixes.

For users, the change may not always be visible. They will still see a browser update, an operating system patch, or a security advisory. But behind those updates, the process of finding and fixing vulnerabilities is becoming increasingly automated.

Some of the security bugs being discovered today may have been sitting unnoticed in software for years. The difference is that companies now have systems that can continuously look for them and help security teams investigate and fix them.

As more of this routine work becomes automated, the bigger change may be in the role of the people behind it. A junior developer or security analyst may spend less time manually searching for obvious problems and more time reviewing AI-generated findings, understanding complex vulnerabilities, and deciding how they should be fixed safely. That does not make human expertise less important. It changes where that expertise is needed. AI could eventually give smaller security teams the ability to work at a scale that previously required much larger teams, while changing what it means to learn and build a career in software security.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.