Cybersecurity Today

← Cybersecurity Today5 sep · 30 min

Surviving and thriving in the AI Vulnpocalypse

Surviving and thriving in the AI Vulnpocalypse5 sep30 min

Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation

In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems.

Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.

She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders.

The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world.

00:00 Weekend Show Intro

00:07 Katie Moussouris Background

02:00 Bug Bounties Then and Now

03:31 AI Hype and Model Escapes

05:06 The Real Cost of Fixing

08:36 Smart AI Regulation

12:34 Tools for Defenders vs Rogues