Wake Me After the Vulnpocalypse
I shared a few thoughts in a podcast with Chris Hughes a week ago that, based on responses, have created some annoyance in the assurance industry.

First up, I'm gonna do my thing and default to defense of the community: This isn't a bug bounty problem. Bug bounty is where you see it most obviously, because the carriers are security researchers who are expecting a response, accountability is hard, and if you fail at it you'll get called out.
(This is no diss on Chris's headline there btw... but sometimes headlines are the only things that people read, so I wanted to call that out. Also yes, AI enablement is testing triage and prioritization across just about every cybersecurity discipline right now).
The vulnpocalypse was already here. Anyone who has run a half-decent offensive team over the past 15 years knows what I'm talking about - The state of appsec has definitely improved, but it's still pretty bad out there if you consider the Internet and all of technology as a whole.
(I should also note that I absolutely hate the term appsec... If you're sending a packet, its creation, transit, and receipt rely on code. Code is apps, and apps are code. As someone who got their start in cybersecurity during the "netsec" era, I feel pretty strongly that "appsec" definition-ed itself into a hole a long time ago, and now some of the artificial lines, defined more by the market than by risk reality, are being called out).
The vulnpocalypse wasn't evenly distributed. The statement above is a deliberately polarizing one: Many would vehemently argue it, but some would quietly nod. If you know you know... Building things that work is hard, building them securely is harder - and when push comes to shove the former wins.
If we're honest, no one expected a swarm of technical debt collectors. Mythos, Daybreak, GLM 5.2, Kimi k3... OK, cool. We get it. Advances in technology making it easy to point out where technologists are bad at things is a thing, and it's not a new thing. If we're lucky, we'll get the chance to make risk sexy again... After all, we're here because of an active adversary... Right?
So, what is this? This is why I frame it as a slopdemic. The industrialized DISCOVERY is a significant shift in the economics of the cybersecurity market, but in other ways it's just a louder version of the same thing.
Here's what I think a vulnpocalypse is: The industrialized EXPLOITATION of vulnerabilities. We've seen shadows of my version of this: SALT, VOLT, and FLAX TYPHOON are three of them, the industrialization of supply-chain attacks are another good example. I don't believe we're seeing it at the level industrialized exploitation makes truly possible at this point, and I also don't think this is very far off.
This is also why I think the "Ostrich risk management" approach some companies have taken in response to the increase in noise is especially dangerous during this season: Burying one's head in the sand might help with noise or inconvenience, but it doesn't improve resilience. Telling hackers (or AI models, for that matter) to "stop it" only works when the hacker or the model is actually listening to you, and the annoying thing about criminals is that they have a habit of doing exactly the opposite.
A shock to the system isn't the same thing as a fix. I've watched a couple of these play out up close, and the risk is always that the noise fades faster than the fragility . What actually changed here is the clock: discovery has compressed toward instant while remediation still runs at human speed, the loop is now too small for most defenders to fit inside, and access to actual, malicious exploitation capability is democratizing. The gap is the exposure, not the report volume.
"Wake me after the vulnpocalypse" is obviously a bit of a joke and I'm not actually asleep, far from it in fact. The thing worth waking me for hasn't happened yet, and what we do in the meantime is the entire crux of the problem the cybersecurity industry, and the collective attack surface of the Internet, are on the clock to figure out. The slopdemic is the last cheap dress rehearsal any of us are going to get.

Comments ·
members only