Wiz co-founder Yinon Costica discusses emerging security risks in generative AI tooling, pointing to results from the Pwn2Own hacking competition.
Assertion Supported
Costica: Most AI security incidents stem from insecure cloud infrastructure
“Actually, when we look at AI related incidents, the majority of them is within this layer of Using the infrastructure in an insecure manner that allows threat actors to just do what they are used to do in cloud in the past.”
Insight
Costica: Vibe coding does not absolve developers of understanding their code
“The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance proc…”
Insight
Costica: AI automation disproportionately benefits cyber attackers over cybersecurity defenders
“And now with AI, the interesting thing that the threat actors can automate a lot more, but from a defense perspective, it doesn't give me the same order of magnitude of, let's say, improvement that the threat actor can gain. So, in essence, there is an aggrava…”
Insight
Costica: AI currently only accelerates automation of existing cyber risks
“AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a j…”
Opinion
Costica: DeepSeek's database leak was a typical cloud exposure, not an exotic exploit
“It was a very, ah, what I would say, typical exposure that exposed a lot of sensitive data, but yet, ah, if we look historically, there were similar incidents, for instance, with Microsoft releasing a token that had access to sensitive data in, you know, a buc…”
Insight
Costica: Ransomware groups reliably return data to protect their business reputation
“If you think about ransomware, it's a business. It has rules to it, right? You know, when you pay the ransom, you get the data, right? It's a rule. You don't, you're not tricked into it because it's a business and they need to maintain their reputation.”