
On finding vulnerabilities and shipping fixes
August 17, 2026
Over the last year, I’ve watched AI models and tools that find vulnerabilities in code take a central role in security industry communications. Every few weeks, a new product announcement promises impressive results, such as AI tools that detect SQL injection, spot memory corruption bugs, identify logic flaws at scale, or chain tens of known vulnerabilities together. This can be impressive for attack purposes, but it is more an interesting novelty than defensive security.
Read More