AI Can Find the Vulnerabilities. Now Somebody Has to Fix Them.
Cybersecurity has developed an interesting new problem. We are getting better at finding holes in software, but that does not necessarily mean we are getting better at closing them.
Artificial intelligence is changing vulnerability research because machines can now examine enormous amounts of code and identify potential weaknesses at a speed that would be impossible for a human team. That is good news for defenders. It is also a reminder that vulnerability discovery is only the first step. After somebody finds the hole, somebody still has to decide whether it matters, notify the developer, build a patch, test it and get that patch onto the systems that actually need it.
That is the problem the Trump administration's Gold Eagle initiative is trying to attack. The federal program is designed to coordinate vulnerability discovery and remediation across government, researchers, software developers and critical-infrastructure operators. Its use of VINCE gives the effort an existing technical foundation rather than requiring the government to build the entire system from scratch.
That is a sensible approach because the cybersecurity industry already has plenty of smart people and plenty of security products. What it does not always have is coordination. AI could make that problem larger by generating vulnerability reports faster than organizations can process them. The danger is not just missing a serious vulnerability. It is burying that vulnerability beneath thousands of less important findings.
There are already private-sector projects trying to deal with this. Akrites, backed by the Linux Foundation and technology companies, focuses on open-source vulnerability........
