Unit 42 Sees AI Rewriting Enterprise Security Work #AI


Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
,
The Future of AI & Cybersecurity

Unit 42 Says Human Experts Will Increasingly Oversee AI-Driven Defense Work

Image: Shutterstock

The job of security professionals will shift more toward administration as security moves to more autonomous agents, predicts Palo Alto Networks’ Unit 42.

See Also: OnDemand | Security Operations in the Age of AI

In a Wednesday roundtable with media, Unit 42 executives shared initial findings after simulating attacks and discovering vulnerabilities as part of Project Glasswing and Daybreak – the names that Anthropic and OpenAI have respectively given to insider access to advanced cybersecurity models.

The company unleashed Mythos 5 and GPT 5.6 Sol on several codebases. These initial findings showed that the current security process will have to change as threats multiply and speed becomes a factor, executives said. Unit 42 estimates that its AI-augmented teams completed two years of penetration testing in just three weeks, unearthing nearly 100 vulnerabilities. More than 40% of vulnerabilities identified by AI models were high or critical severity. Most exploits involved leaked credentials and broken access controls

Sam Rubin, senior vice president, consulting and threat intelligence at Unit 42, told reporters that threat actors now have access to AI agents that make attacks faster. Defenders also must adopt the same tools – and that will change how they do their work, he said.

“The jobs will change, and AI will be doing more and more of the jobs, so I think the job of the security person will be an orchestrator security engineer,” Rubin said.

He added that accountability will spread across the enterprise because of the rise of vibe-coded applications and greater pressure on application security experts to place guardrails into those platforms. But, he said, there will always be a need for a human expert to ultimately be held responsible for protecting the entire company.

Shay Nahari, vice president, offensive security at Unit 42, said during the same briefing that expertise still goes a long way. He likened it to vibe coding, where someone without a coding background can produce code with the help of AI, but it won’t be production-ready or as robust as code from a more seasoned coder using a coding agent, who can come up with something stronger and more deployable.

“There is a very big, big difference between someone who’s doing it for a living, powered by AI, versus someone who’s using this,” he said.

Unit 42 is not the first to suggest that enterprises will be moving some security tasks to agents. OpenAI president Greg Brockman urged organizations to start using agents to address security and safety concerns because vulnerabilities are identified at such speed and scale. More than 100 companies, including OpenAI and Anthropic, signed an open letter urging other enterprises and the government to overhaul security processes and use more AI tools.



Click Here For The Original Source.

——————————————————–

..........

.

.