Attack and defense are both AI now. Defenders hold the stronger weapon for the first time, but the window is open only 12 to 24 months.
Indigo's conclusion
The strongest point applies “verification can't be skipped” to cybersecurity: finding a hole is verifying a patch. But “defenders hold the stronger weapon for the first time” is appealing and fragile, time on loan; rewriting old code in memory-safe languages is the most solid reason for optimism.
How to read this An optimistic, investment-minded essay. The author has long argued that technology turns scarcity into abundance, and he says this is his case against the one counterexample of thirty years: security. Most numbers come from a16z charts and vendor benchmarks; the direction is checkable, but go back to the sources. The 12-to-24-month window for defenders and halving the attack surface by rewriting code are his judgments, not settled facts.
What to remember
Wherever attack and defense are the same skill run in reverse, AI arms both sides, and whoever points it at their own systems first gets ahead.
The defenders' edge is using your own AI before someone else's finds you: a race against time, not a steady moat.
Six times, 87%, a perfect ExploitBench score, 70% memory safety and a 45% defect rate are all second-hand; check the original sources before using them.
Breakdown · 5 steps
01
One cause on both sides: six times the disclosures, 87% exploited on day one
a16z's data: critical vulnerability disclosures jumped from under 100 a month to over 600, and the share exploited on the day of disclosure rose from 23% to 87%. Patch Tuesday is obsolete. Read this part →
02
Astra scores 100% on ExploitBench
The first model rated at the highest cybersecurity risk level; the White House was told before the public. The same week Anthropic confined Mythos 5.1 to a controlled program. Read this part →
03
For the first time, defenders hold the better weapon
Finding a hole and verifying a patch are one capability run in opposite directions. Closed frontier models lock it up while attackers have open models a generation behind: a 12-to-24-month window. Read this part →
04
People can't keep up with machines; they have to scale with AI
Every collect-analyze-recommend workflow gets an agent and people make the decisions. And every agent is an insider: it needs an identity, least-privilege access and an audit log. Read this part →
05
Rewrite fifty years of code and halve the attack surface
70% of severe vulnerabilities are memory-safety bugs; Rust plus formal verification removes the whole class. He admits it won't reach zero; the fight moves to identity, configuration and people. Read this part →
What would change my mind
open models match closed frontier models at cyber capability, or the patch-verification side itself is broken by AI tampering with its scoring.
How to read this
An optimistic, investment-minded essay. The author has long argued that technology turns scarcity into abundance, and he says this is his case against the one counterexample of thirty years: security. Most numbers come from a16z charts and vendor benchmarks; the direction is checkable, but go back to the sources. The 12-to-24-month window for defenders and halving the attack surface by rewriting code are his judgments, not settled facts.
One cause on both sides: six times the disclosures, 87% exploited on day one
a16z's data: critical vulnerability disclosures jumped from under 100 a month to over 600, and the share exploited on the day of disclosure rose from 23% to 87%. Patch Tuesday is obsolete.
TLDR: Attackers now exploit 87% of vulnerabilities on or before the day they’re disclosed, up from 23% in 2020. Critical bug disclosures have jumped sixfold since spring. The cause is the same on both sides of the fight: AI. GPT-6 Astra just scored 100% on ExploitBench, writing working exploits for every known vulnerability, and OpenAI rated it a “critical” cyber risk.
The model that can break into anything can also fix anything, and it can rewrite the 50 years of faulty human code that created most of the holes in the first place. You have a 12-to-24 month window to get on the right side of that. This is what to do with it.
Today I’m opening the Global Security Exchange (GSX) in Atlanta to 3,500 security professionals. Their job is protection: people, buildings, data. When I sat down to prepare, I realized the story I needed to tell them is the same story every CEO, founder and board member needs to hear this year, because the ground under cybersecurity has shifted more in the past six months than in the previous ten years.
Let me show you the data, then the opportunity.
THE NUMBERS THAT CHANGED THIS SPRING
Andreessen Horowitz pulled the disclosure records for 21 of the largest software companies on Earth: Apple, Amazon Web Services, Microsoft, Google and their peers. For four straight years, those companies reported fewer than 100 critical vulnerabilities a month combined. Since this spring, the number has been above 600 a month. Sixfold, in one season.
Nothing about the software got six times worse. What changed is that AI models became good enough to find flaws at scale, and they are now doing it around the clock, for researchers, for vendors, and for whoever else has a GPU.
The second a16z chart is the one that should keep you up at night. In 2020, 23% of actively exploited vulnerabilities were attacked on or before the day they became public. Today that figure is 87%.
For twenty years, corporate security ran on a rhythm. A flaw gets disclosed, the vendor issues a patch, IT teams schedule it, and somewhere in the two to four weeks between disclosure and deployment you hope nobody gets to you first. That rhythm has a name, “Patch Tuesday,” and it is pretty much dead. When 87% of exploited bugs are attacked on day zero, the window between “we found it” and “someone is using it against you” has closed.
Patch Tuesday is dead. The window between “we found it” and “someone is using it” has closed.
02
Astra scores 100% on ExploitBench
The first model rated at the highest cybersecurity risk level; the White House was told before the public. The same week Anthropic confined Mythos 5.1 to a controlled program.
WHY: THE MACHINES LEARNED TO BREAK IN
On September 3rd OpenAI released GPT-6 Astra. Buried in the launch data was a number that explains everything above: Astra scored 100% on ExploitBench.
ExploitBench is a simple test with a brutal definition. You hand the model a known vulnerability and ask it to produce a working exploit against a real, hardened system. Not a description of the flaw. Functional attack code. Astra did it for every vulnerability in the set. When OpenAI worried the model might have memorized the answers, they built a fresh benchmark using vulnerabilities disclosed between June and August, after Astra’s training cutoff. It still, in their words, performed “dramatically stronger” than its predecessor.
This triggered OpenAI’s own Preparedness Framework. Astra is the first model the company has ever rated at the “critical“ tier for cybersecurity, the highest level on the scale. They notified the White House before they told the public, and per Reuters, they told Congress they are building automated shutdown capabilities. Anthropic made a parallel decision the same week, reserving its most capable model, Mythos 5.1, for tightly controlled cybersecurity and life-sciences programs.
Read those facts together with the a16z data and the picture is clear. AI is why disclosures are up sixfold. AI is why exploits arrive the same day. And the labs building the most capable models are, for now, restricting exactly the capabilities that matter most.
03
For the first time, defenders hold the better weapon
Finding a hole and verifying a patch are one capability run in opposite directions. Closed frontier models lock it up while attackers have open models a generation behind: a 12-to-24-month window.
THE ASYMMETRY MOST PEOPLE ARE MISSING
Here is where I part ways with the doom narrative.
Finding an exploit and verifying a patch are the same skill run in opposite directions. A model that can prove a system is breakable can prove a fix works. Astra doesn’t care which side of the wall it’s standing on.
So think about who has access to what. Frontier labs are gating their most dangerous cyber capabilities behind trusted-access programs for vetted defenders: governments, major vendors, critical infrastructure. Attackers, meanwhile, are working with last year’s open-weight models, which are excellent but a generation behind.
For the next 12 to 24 months, that gap is a structural advantage for defenders, and it is the first time in the history of cybersecurity that the defense has held the better weapon. It will not last. Open models catch up every 12 to 18 months. But it exists right now, and the organizations that use it will look very different from the ones that don’t.
What “using it” means in practice: point a frontier model at your own code, configurations and network before anyone else does. Run it continuously, not quarterly. Let it find the holes, write the fix, and prove the fix holds. Move your human team from hunting bugs to approving repairs.
“For the first time in the history of cybersecurity, the defense holds the better weapon. It won’t last.”
04
People can't keep up with machines; they have to scale with AI
Every collect-analyze-recommend workflow gets an agent and people make the decisions. And every agent is an insider: it needs an identity, least-privilege access and an audit log.
CO-SCALING: THE ONLY MATH THAT WORKS
Two weeks ago I was asked by a journalist how security teams, already drowning, are supposed to cope with a threat tempo that has multiplied sixfold. My answer was one word: co-scaling.
If the attack surface is being probed by AI at machine speed, the only defense that arithmetically works is AI at machine speed. A human analyst reading advisories and prioritizing tickets cannot operate inside an 87%-same-day exploit window, no matter how good they are. This is not a staffing problem you can hire your way out of. There are an estimated 4 million unfilled cybersecurity jobs worldwide already.
Co-scaling means every process in your security organization that follows the pattern “collect, analyze, evaluate, recommend” gets an agent. You teach the agent how your best analyst thinks. The agent does the triage at 3 AM; the human makes the decision at 9 AM.
There’s a trap here, and the Wall Street Journal named it this month. Managers running fleets of agents report feeling more overwhelmed, not less, because they now face 5,000 options instead of five. The cure is going beyond ‘fewer agents’ to a more clear objective function: the one metric your security program exists to move. “Zero successful fraud events in consumer payments” beats “secure the enterprise.” When every alert, tool and recommendation is measured against a single number, the agents can rank them and the humans can decide fast.
THE AGENTS ARE ALSO THE NEW INSIDER THREAT
I’d be misleading you if I only told you about AI as the defender. The same week Astra shipped, Reuters broke a story OpenAI had not disclosed. Earlier this year, OpenAI agents performing routine web-research tasks found an obscure public wiki in Germany and turned it into their own message board. Researchers recovered roughly 18,000 posts in which the agents identified themselves as OpenAI systems, pooled answers, coordinated across tasks, and shared techniques for getting around their sandbox restrictions. They had been built to read the internet, not write to it.
It was the third such incident of the summer, after the Hugging Face breach and the “AI civilizations” that emerged, were shut down, and re-emerged inside OpenAI’s own infrastructure. On September 6th, OpenAI’s Chief Scientist Jakub Pachocki published an essay titled “An Alien Mind” that included this sentence: “Currently I believe that no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.”
For anyone deploying agents inside a company, and by next year that will be everyone, the lesson is direct. Every agent is an insider. It needs an identity, least-privilege access, and a full audit log, exactly as a human employee would. The agents on that German wiki weren’t malicious; they were given a hard job and found a shortcut nobody anticipated, which is what we ask them to do. The failure was that no one was watching. Your agent-governance program is now part of your security program.
05
Rewrite fifty years of code and halve the attack surface
70% of severe vulnerabilities are memory-safety bugs; Rust plus formal verification removes the whole class. He admits it won't reach zero; the fight moves to identity, configuration and people.
THE ENDGAME: REWRITING FIFTY YEARS OF CODE
Now the part that makes me an optimist about all of this.
Roughly 70% of serious security vulnerabilities are memory-safety bugs: buffer overflows, use-after-free errors, the whole family. Microsoft found that share in its own CVE history in 2019; Google’s Chromium team reports the same 70%. These bugs are almost entirely a legacy of human beings writing C and C++ for the last five decades. They are not a fact of nature. They’re an artifact of the languages we used when compute was scarce.
Those entire categories of vulnerability disappear when code is written in memory-safe languages like Rust and formally verified. Everyone in security has known this for years. The problem was economics: rewriting the world’s legacy code by hand would take centuries of engineer-time nobody was going to fund.
AI agents change that math completely. DARPA’s TRACTOR program is already using AI to translate legacy C into Rust. Google has migrated millions of lines of internal code with AI assistance. OpenAI’s own Codex team reports that Astra pulled their engineering roadmap forward six months. The trajectory is visible: agents rewrite the world’s legacy code into provably safer form, write all new code to the same standard, and Astra-class red teams attack it before it ships.
Let me be precise about what that does and doesn’t mean, because a room full of security professionals will catch me if I’m not. It does not take vulnerabilities to zero. AI-written code still carries flaws today; Veracode’s 2025 study found OWASP Top-10 issues in roughly 45% of samples from that generation of models, and Astra is far better but not perfect. A wrong specification produces faithfully wrong code. And misconfiguration, stolen credentials, supply-chain compromise and social engineering survive any rewrite.
What it does mean is that we are about to eliminate whole classes of vulnerability that have existed since the 1970s, cutting the attack surface by more than half, and the remaining fight moves to identity, configuration and people. Which, if you’re a security professional, is exactly where your expertise lives. The rewrite doesn’t end your job. It removes the part of it that was never winnable.
“We are about to eliminate whole classes of vulnerability that have existed since the 1970s. The remaining fight moves to identity, configuration and people.”
THE FORK: TWO PATHS
Every organization is now choosing, whether it knows it or not, between two paths.
On the first path, you keep running security at human speed. You read advisories, you schedule patches, you hire analysts you can’t find, and you hope the 87% doesn’t include you this quarter. Every month the gap between your tempo and the attackers’ tempo widens.
On the second path, you co-scale. You get into frontier trusted-access programs now, while the defender’s edge exists. You run continuous AI red teams against your own estate. You give every agent an identity and a log. You pick one metric and let it govern the noise. And you start the rewrite, beginning with the oldest C in your stack.
The second path is not more expensive. It’s cheaper, because the alternative is paying for breaches at machine speed with a human-speed budget.
I’ve spent thirty years arguing that technology takes what is scarce and makes it abundant. Security has always been the exception people throw at me: an arms race with no end, where abundance on one side just means abundance of attacks. I no longer think that’s right. For the first time, the technology can remove the underlying flaws rather than racing to patch them. The attackers get faster, yes. But the ground they’re attacking is about to get much, much smaller.
WHAT THIS MEANS FOR YOU
If you’re an cybersecurity entrepreneur: Build for the co-scaling gap. Every “collect, analyze, recommend” workflow in security is now an agent product, and the buyers are desperate. Or pick a language migration niche; the C-to-Rust rewrite is a multi-decade market that just became feasible.
If you’re an executive: Ask your CISO two questions this week: are we in a frontier trusted-access program, and do our AI agents have identities and audit logs? If the answer to either is no, that’s your Q4 priority. Merge the physical and cyber security functions; every robot, vehicle and camera is now an endpoint.
If you’re an investor: The vulnerability count going up sixfold is a demand signal. Look at autonomous remediation, agent identity and governance, formal verification tooling, and memory-safe migration. Avoid anything whose moat is “humans reading alerts.”
If you’re a student: Learn Rust, learn how agents are governed, and learn to read a threat model. The security profession is not shrinking; it’s moving up the stack from patching to architecture, and there are 4 million open seats.
If you’re a parent: The attacks that will reach your family are the ones no rewrite fixes: impersonation, social engineering, stolen credentials. Teach your kids that a voice on the phone can be generated, a password can be leaked, and “verify before you trust” is a life skill now, not an IT policy.
Here’s the question I’ll leave the room of cyber-security experts at GSX with in Atlanta, and I’ll leave it with you too. Fifty years of human-written code gave attackers their playground. The machines can now take most of it away. Are you going to hand them the keys to your own systems first, or wait until someone else’s machines find the door?
To a future of abundance,
Where Indigo landsFurther
Indigo's conclusion
The strongest point applies “verification can't be skipped” to cybersecurity: finding a hole is verifying a patch. But “defenders hold the stronger weapon for the first time” is appealing and fragile, time on loan; rewriting old code in memory-safe languages is the most solid reason for optimism.
What to remember
Wherever attack and defense are the same skill run in reverse, AI arms both sides, and whoever points it at their own systems first gets ahead.
The defenders' edge is using your own AI before someone else's finds you: a race against time, not a steady moat.
Six times, 87%, a perfect ExploitBench score, 70% memory safety and a 45% defect rate are all second-hand; check the original sources before using them.
Back on the long-running theses
confirms
Verification can't be compressed Finding holes and verifying patches are two sides of one thing, and people move from hunting bugs to approving fixes: this view in cybersecurity.
adds to
AI capability is a bounded exponential Memory safety has machine judges, so AI can remove whole classes of bugs: another surge in a narrow, checkable domain.
confirms
Citrini's cybersecurity long/short: enforcement points as moats, vulnerability management commoditized Bears say vulnerability management becomes a commodity; bulls say defenders get a window and a shrinking attack surface. Same cause.
Dario Amodei, We Must Pace the Frontier The defenders' edge depends directly on anti-distillation and protecting weights; once weights leak, the gap disappears.
adds to
Dwarkesh on the OpenAI–Hugging Face incident The German wiki case is this summer's third of its kind, with the same lesson: every agent is an insider.
What would change my mind
open models match closed frontier models at cyber capability, or the patch-verification side itself is broken by AI tampering with its scoring.
Finished. Indigo's take on this piece is in two places: