Yinon Costica, co-founder and VP of Product at Wiz, discusses the root causes of observed AI security breaches.
Insight
Costica: Vibe coding does not absolve developers of understanding their code
“The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance proc…”
Insight
Costica: AI automation disproportionately benefits cyber attackers over cybersecurity defenders
“And now with AI, the interesting thing that the threat actors can automate a lot more, but from a defense perspective, it doesn't give me the same order of magnitude of, let's say, improvement that the threat actor can gain. So, in essence, there is an aggrava…”
Insight
Costica: AI currently only accelerates automation of existing cyber risks
“AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a j…”
Opinion
Costica: DeepSeek's database leak was a typical cloud exposure, not an exotic exploit
“It was a very, ah, what I would say, typical exposure that exposed a lot of sensitive data, but yet, ah, if we look historically, there were similar incidents, for instance, with Microsoft releasing a token that had access to sensitive data in, you know, a buc…”
Assertion Supported
Costica: Four of six AI technologies at Pwn2Own had critical RCE vulnerabilities
“Six technologies were presented. Out of these six technologies, four were actually Researched and found to be vulnerable at what we call the highest impactful vulnerability, which is remote code execution, RCE, which means that you can do anything with the tec…”
Insight
Costica: Ransomware groups reliably return data to protect their business reputation
“If you think about ransomware, it's a business. It has rules to it, right? You know, when you pay the ransom, you get the data, right? It's a rule. You don't, you're not tricked into it because it's a business and they need to maintain their reputation.”