{"id":623999,"date":"2026-09-14T03:36:25","date_gmt":"2026-09-14T03:36:25","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/623999\/"},"modified":"2026-09-14T03:36:25","modified_gmt":"2026-09-14T03:36:25","slug":"security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/623999\/","title":{"rendered":"Security through obscurity is dead, and AI delivered the fatal blow"},"content":{"rendered":"<p>The term &#8220;security through obscurity&#8221; describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency.<\/p>\n<p>Now it\u2019s obsolete. Don\u2019t believe us? Here\u2019s proof.\u00a0<\/p>\n<p>Software vendors and independent researchers alike are now <a href=\"https:\/\/www.theregister.com\/patches\/2026\/05\/14\/welcome-to-the-vulnpocalypse-as-vendors-use-ai-to-find-bugs-and-patches-multiply-like-rabbits\/5240027\" rel=\"nofollow noopener\" target=\"_blank\">using AI agents to find bugs<\/a>\u00a0\u2013 some <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/04\/openais-codex-chains-decade-old-dos-techniques-into-http\/2-bomb\/5251377\" rel=\"nofollow noopener\" target=\"_blank\">very obscure<\/a> and <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/23\/mythos-discovers-squidbleed-a-memory-leak-thats-gone-undetected-since-clinton-era\/5260367\" rel=\"nofollow noopener\" target=\"_blank\">decades old<\/a>\u00a0\u2013 across products and open source code, leading to <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/14\/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves\/5271434\" rel=\"nofollow noopener\" target=\"_blank\">record-breaking numbers<\/a> of security disclosures and patches, and a <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/27\/its-looking-like-a-hot-messy-summer-for-security-teams-as-ai-finds-countless-previously-hidden-vulns\/5260478\" rel=\"nofollow noopener\" target=\"_blank\">massive backlog for project maintainers<\/a>.<\/p>\n<p>\u201cYou see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,\u201d Brett Leatherman, assistant director of the FBI&#8217;s Cyber Division, told The Register. \u201cThe latest models were <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/08\/anthropic-mythos-model-can-find-and-exploit-0-days\/5224393\" rel=\"nofollow noopener\" target=\"_blank\">able to break those<\/a> and say, \u2018yeah, there\u2019s significant vulnerabilities in here.\u2019\u201d<\/p>\n<p>Whether or not security through obscurity is dead \u201cisn&#8217;t even an opinion question,\u201d Trend Micro\u2019s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft\u2019s <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/09\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/5295160\" rel=\"nofollow noopener\" target=\"_blank\">record-breaking Patch Tuesday<\/a> addressed 974 CVEs.\u00a0<\/p>\n<p>\u201cWhen you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,\u201d Childs said. \u201c<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69431\" rel=\"nofollow noopener\" target=\"_blank\">Telnet client<\/a>\u00a0\u2013 is this even still used in any secure environment? <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69768\" rel=\"nofollow noopener\" target=\"_blank\">Windows RNDIS<\/a>\u00a0\u2013 the USB-networking protocol Microsoft has been trying to deprecate for years. <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-71334\" rel=\"nofollow noopener\" target=\"_blank\">NFS <\/a><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-71334\" rel=\"nofollow noopener\" target=\"_blank\">Portmapper<\/a>\u00a0\u2013 1980s Unix tech. And <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69732\" rel=\"nofollow noopener\" target=\"_blank\">Link Layer Topology Discovery<\/a>\u00a0 \u2013 the Vista-era network-map protocol nobody&#8217;s thought about since Vista \u2013 just to name a few.\u201d<\/p>\n<p>Meanwhile, attackers are also using AI to reverse-engineer fixes and <a href=\"https:\/\/www.anthropic.com\/research\/n-days\" rel=\"nofollow noopener\" target=\"_blank\">find exploits within hours<\/a>. In one recent case, at least four espionage crews, most suspected of links to China, <a href=\"https:\/\/www.theregister.com\/research\/2026\/09\/09\/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits\/5295399\" rel=\"nofollow noopener\" target=\"_blank\">slammed shut the \u201cpatch-gap\u201d window<\/a> for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch \u2013 but before the downstream stable release was pushed to users.<\/p>\n<p>What this means for OT security<\/p>\n<p>During interviews at Black Hat in August, both <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/07\/asimov-was-right-about-rules-for-robots-says-ex-us-cyber-director\/5284397\" rel=\"nofollow noopener\" target=\"_blank\">former US National Cyber Director Chris Inglis<\/a> and <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/14\/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure\/5287594\" rel=\"nofollow noopener\" target=\"_blank\">John Hultquist<\/a>, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS).\u00a0<\/p>\n<p>These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets\u00a0\u2013 all critical services that people use daily, and assume will continue working reliably.\u00a0<\/p>\n<p>The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers.\u00a0<\/p>\n<p>AI upended this assumption. It means that criminals don&#8217;t need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them.<\/p>\n<p>A couple of weeks after Black Hat, five US agencies said that <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/19\/not-a-theoretical-risk-feds-warn-as-attackers-use-ai-made-code-to-hack-critical-infrastructure-controllers\/5289960\" rel=\"nofollow noopener\" target=\"_blank\">attackers used AI-generated exploitation scripts<\/a> to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. \u201cThis is not a theoretical risk \u2013 it is an active threat,\u201d the feds warned.<\/p>\n<p>AI \u201cis excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems,\u201d Hultquist told The Register in an interview last week.\u00a0<\/p>\n<p>\u201cThey&#8217;ve been largely secured because the expertise was in a handful of people&#8217;s heads, and that&#8217;s not going to last forever,\u201d he said.<\/p>\n<p>AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. \u201cThat&#8217;s going to have implications for a lot of different areas of security, but definitely for industrial control systems.\u201d<\/p>\n<p>However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn\u2019t necessarily a bad thing.<\/p>\n<p>&#8216;Never a winning strategy&#8217;<\/p>\n<p>\u201cI&#8217;ve always been of the mind that security through obscurity was never a winning strategy,\u201d <a href=\"https:\/\/www.theregister.com\/security\/2022\/08\/10\/us-government-is-understanding-hiring-security-talent\/1176302\" rel=\"nofollow noopener\" target=\"_blank\">Katie Moussouris<\/a>, founder and CEO of bug bounty consultancy Luta Security and the <a href=\"https:\/\/www.theregister.com\/security\/2023\/11\/22\/microsofts-bug-bounty-turns-10-but-are-we-any-more-secure\/290742\" rel=\"nofollow noopener\" target=\"_blank\">fairy godmother of bug bounties<\/a>, told The Register. \u201cBut that&#8217;s because I&#8217;ve been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it.\u201d<\/p>\n<p>Plus, she added, AI makes hacking a whole lot easier.\u00a0<\/p>\n<p>\u201cPeople might not have familiarity with the particular tech stack that you&#8217;re running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards,\u201d Moussouris said.<\/p>\n<p>However, finding bugs and other weaknesses has never been the big security problem, she added. \u201cIt\u2019s triaging and prioritization and actually getting things fixed.\u201d This, Moussouris said, has also been her <a href=\"https:\/\/www.theregister.com\/security\/2025\/08\/24\/bug-bounties-the-good-the-bad-and-the-frankly-ridiculous\/589210\" rel=\"nofollow noopener\" target=\"_blank\">biggest issue<\/a> with the way that organizations implement bug bounty programs.<\/p>\n<p>\u201cAI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn&#8217;t caught up on the defensive side,\u201d Moussouris said. \u201cWe&#8217;re not there with AI automated patching, remediation\u00a0\u2013 anything of the sort.\u201d<\/p>\n<p>A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. <\/p>\n<p>1Password\u2019s research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI&#8217;s ChatGPT-5.5 and Anthropic&#8217;s Opus 4.8.\u00a0<\/p>\n<p>\u201cThe average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent,\u201d <a href=\"https:\/\/1password.com\/blog\/why-ai-generated-patches-still-require-human-review\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a> Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application\u2019s behavior 20 percent of the time. This included things like changing \u201callow list\u201d logic to \u201cdeny list\u201d logic.<\/p>\n<p>\u201cConversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time,\u201d Hoodlet said.<\/p>\n<p>Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average <a href=\"https:\/\/www.veracode.com\/resources\/analyst-reports\/2026-genai-code-security-report\/\" rel=\"nofollow noopener\" target=\"_blank\">security pass rate for AI-generated code<\/a> was just 56 percent.\u00a0<\/p>\n<p>\u201cIf people are telling you that you need to accelerate on the fixing side, and the defense side\u00a0\u2013 that\u2019s just not cutting it,\u201d Moussouris said.\u00a0<\/p>\n<p>\u201cOrgs that are looking at this as we&#8217;re going to throw more resources at finding and fixing bugs, and they&#8217;re not investing in taking a look at their process failures that led to so many bugs\u00a0\u2013 those organizations are going to die on the treadmill,\u201d she added. \u201cThey will literally have a heart attack and die. Like there&#8217;s no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer.\u201d<\/p>\n<p>The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln.<\/p>\n<p>\u201cA lot of organizations don&#8217;t even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium,\u201d Moussouris said.\u00a0<\/p>\n<p>The number of flaws fixed is important, but it doesn\u2019t show the entire picture, she added. This involves looking at types of vulnerabilities, too. <\/p>\n<p>\u201cLike: We&#8217;ve got a lot of injection flaws. That&#8217;s something we could solve with better, safer templates earlier in our CI\/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast.\u201d \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"The term &#8220;security through obscurity&#8221; describes an old idea that networks and systems will remain secure so long&hellip;\n","protected":false},"author":2,"featured_media":624000,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[220,218,219,61,60,80],"class_list":["post-623999","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/623999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=623999"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/623999\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/624000"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=623999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=623999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=623999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}