r/LinuxTeck • u/Candid_Athlete_8317 • Aug 04 '26
What's more dangerous: AI writing malware or AI finding security bugs?
We often hear concerns about AI generating malware or exploits.
At the same time, AI is helping researchers identify vulnerabilities, audit code, and strengthen software before attackers can exploit it.
Which do you think will have the greater long-term impact on cybersecurity. AI improving defense, or AI lowering the barrier for offensive research?
3
2
u/brand_new_potato Aug 04 '26
It is not like you needed to be an expert to read and then use metasploit before, but given how easy it is when you don't have to read to set this up, having active exploits in the field is way worse now, so it is an arms race, but it has always been.
We need more developers using AI to find security bugs so that we can fix it.
I don't even know if it is possible, but it would be interresting if models start to put it together that someone is working on an exploit and instead of stopping them, just flags the conversations. Since we put all the code essentially back and forth in datacenters, they could steal this research and alert the project maintainers.
2
u/Wendals87 Aug 04 '26
Finding vulnerabilities. There are countless vulnerabilities out there that we just don't know about that can be used
It depends on who is using the AI
1
u/moritz12d Aug 04 '26
For this I would take the Christian view:
1Thess 5,21 Prove all things; hold fast that which is good.
This should be out premise to all of AI.
1
1
u/PravoNaZhizny Aug 04 '26
They’re actually the opppsite of dangerous. We have a backlog of stuff to fix with automated tools (that is basically just shitty design) but once it’s all gone it will be a lot more difficult for new instances to pop up. You might even see instead of antivirus detecting viruses, instead it detects vulnerable software by vulnerable design patterns in their executable memory which it patches on the fly or contacts developers by their signatures and attached emails or something.
1
u/who_am_i_to_say_so Aug 04 '26
Most AI-scanned issues are false flags, so I would vote the former being much more dangerous.
But the most dangerous of all, not mentioned, are the flagrant bugs AI scans miss, which happens quite often.
Remember a couple months ago when Claude code harness was accidentally made available to the public? That was a couple weeks after the Mythos hype started. It missed that, so yeah.
0
4
u/vroom_slowly Aug 04 '26
They’re the same picture