
Risky Business Risky Business #831 -- The AI bugpocalypse begins
11 snips
Apr 1, 2026 Ed Wu, founder of Dropzone and builder of an AI SOC platform. He discusses Dropzone’s automated AI analysts and prebuilt 'huntpacks'. Conversation covers AI-driven threat hunting, how automation surfaces weird and security-relevant artifacts, and using models to accelerate vulnerability discovery.
AI Snips
Chapters
Transcript
Episode notes
Models Refuse Exploits But Enable Skilled Exploit Development
- Retail LLMs often refuse to write exploit code but will provide detailed PoC analysis and attack paths.
- That level of guidance lets an experienced developer convert analysis into functioning exploit code even if the model won’t produce it directly.
AI With Skilled Humans Multiplies Vulnerability Research Speed
- Claude plus developer expertise acts as a force multiplier for vulnerability research.
- Tasks like fetching repos and reasoning about WebKit internals took minutes and produced exploit-worthy guidance for an informed human.
AI Bug Wave Will Persist Because Of Legacy Systems
- The AI-driven vulnerability wave will be long-lived because many sectors run legacy tech with slow patch cycles.
- Industries with 20-year lifecycles and poor patch processes will remain vulnerable as models find low-effort bugs at scale.
