Yinon Costica, co-founder and VP of Product at Wiz, explains why AI automation disproportionately benefits threat actors over cyber defenders on Big Technology Podcast.
Assertion Supported
Costica: Most AI security incidents stem from insecure cloud infrastructure
“Actually, when we look at AI related incidents, the majority of them is within this layer of Using the infrastructure in an insecure manner that allows threat actors to just do what they are used to do in cloud in the past.”
Insight
Costica: Vibe coding does not absolve developers of understanding their code
“The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance proc…”
Insight
Costica: AI currently only accelerates automation of existing cyber risks
“AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a j…”
Opinion
Costica: DeepSeek's database leak was a typical cloud exposure, not an exotic exploit
“It was a very, ah, what I would say, typical exposure that exposed a lot of sensitive data, but yet, ah, if we look historically, there were similar incidents, for instance, with Microsoft releasing a token that had access to sensitive data in, you know, a buc…”
Assertion Supported
Costica: Four of six AI technologies at Pwn2Own had critical RCE vulnerabilities
“Six technologies were presented. Out of these six technologies, four were actually Researched and found to be vulnerable at what we call the highest impactful vulnerability, which is remote code execution, RCE, which means that you can do anything with the tec…”
Insight
Costica: Ransomware groups reliably return data to protect their business reputation
“If you think about ransomware, it's a business. It has rules to it, right? You know, when you pay the ransom, you get the data, right? It's a rule. You don't, you're not tricked into it because it's a business and they need to maintain their reputation.”