AI Finds Zero-Days, But Struggles to Write Secure Code

Aug 18·0:00 listen·Source: csoonline.com

Summary

AI models are now routinely finding zero-day flaws that humans and traditional tools have missed for years. What's interesting is this rapid evolution in offensive capabilities scares even their own creators. However, despite these advances in vulnerability discovery, AI models are not progressing as fast in vital areas of cyber defense. A recent study found that 44% of AI-generated code contains at least one known OWASP Top 10 vulnerability. No model had more than a 68% security pass rate, meaning it still generated insecure code once every three tries. The average security pass rate for AI-generated code has hardly improved over the past year, even though all tested models produced syntax-correct code 99% of the time. This creates a critical cyber imbalance. The bottom line is that while AI excels at finding vulnerabilities, it still struggles to consistently write secure code, amplifying existing security risks in software development.

Read the full article on csoonline.com

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening