Everyone is talking about how AI is reshaping the world of security. There are many ways in which we see it happening: more security teams are starting to replace basic vendors with tools built in-house, attackers and defenders alike are starting to rely on agents to achieve their goals, and if you have been to Black Hat or RSAC 2026 this year, it’s clear that the market is a complete mess. Everyone is saying the same thing in LLM voice, and few people are able to make sense of what’s going on.
All this is true, but if I were to summarize in one sentence the biggest change I see happening in the industry, I’d talk about something completely different, something I think we aren’t discussing as much as we should: that AI spells the end of security by obscurity. Let me explain.
This issue is brought to you by... Varonis.
How Varonis Got Microsoft Copilot to Rat Itself Out
Varonis Threat Labs didn’t have to reverse-engineer Copilot’s newest flaw. They got Copilot to explain it, one reframed question at a time, a technique called meta-hacking. That’s how they found CoSnitch (CVE-2026-24301), a chain of three vulnerabilities that lets a single link trigger auto-execution, silently pull emails, calendar events, and files through Copilot’s own connectors, and permanently poison its memory, all without a single anomalous signal. It’s the third Copilot flaw Varonis has found this year, with one click being all it took.
The security control nobody wants to admit they rely on
For decades, we as an industry have been saying that “security by obscurity is not a real security strategy”. Even though it is definitely true and everyone agrees with this, we have to admit to ourselves that we’ve long secretly relied on obscurity to protect us.
Why do most vulnerabilities, misconfigurations, and overly broad access paths not get exploited? There are plenty of reasons, but one of the most obvious is that nobody finds them. We like to talk about the fact that defenders have limited resources, but attackers, too, have a finite number of people, infrastructure, and attention. Think about what it takes for attackers to break into an organization and to actually achieve their malicious goals: they have to spend time doing reconnaissance and investigation, find potential ways in, prioritize them, decide which one they’ll pursue, execute the attack without getting detected, then find a way to maintain their persistence… It sounds terrible to say it, but this has to be a lot of work, and so aside from the “spray and pray” approaches (which I must admit have been pretty effective, too, because so many companies lack the basics), the true targeted attacks have been less common even though when they happen, they tend to also be much more successful for bad actors and much more damaging for the victims.
Attackers always had an economics problem
At its core, this is an economics problem of resource allocation. Similar to how security teams have to prioritize what they focus on defending against, attackers had to prioritize which companies, industries, tech stacks, vulnerabilities, types of environments, etc., to go after.
This investment requirement created what I can only describe as a natural upper limit on how much of the internet, or even how much of an enterprise, they can meaningfully investigate at scale. The choice bad actors have has always been between going focused and deep but having to spend a lot of effort and time, or taking the spray-and-pray approach and going broad but shallow, knowing that plenty will still fall for it.
In all our conversations about attackers, we tend to focus on how sophisticated they are (which is why there’s so much focus on zero days and nation states), when the question that matters almost as much is how many things can they afford to investigate. In the past, this was all a part of the same question, but now it is not the case. This brings us to AI.
AI is completely changing the economics of attacks
AI is completely changing the economics of attacks by reducing the marginal cost of reconnaissance, investigation, and attack preparation. AI agents don’t get tired of checking the 50,000th domain, API endpoint, GitHub repo (when GitHub isn’t down :), or cloud service. With AI, attackers can now scale what they’d do manually by investigating thousands of attack paths in parallel and correlating information from dozens of sources. What wasn’t possible to investigate before AI because of a lack of resources now suddenly makes sense to focus on because the cost of that investigation is approaching zero.
The other issue that is becoming more and more serious is that at times it feels like security is working against itself. Companies are (understandably) putting controls around AI, with all the model restrictions, data governance, and limits on autonomous action. Attackers have none of these constraints - they can use the most powerful models available and let agents go loose. They don’t care about the risks of using some Chinese open-source LLM; what they care about is the cost. Defenders may spend months figuring out where agents should be allowed to operate and what access they should get, while attackers can optimize entirely for effectiveness. This is creating a dangerous transition period where offensive automation is advancing much faster than defensive capabilities.
The biggest shift I am seeing today is not that AI enables new types of attacks (as much as that’s captivating everyone’s imagination), it is that it makes existing techniques massively scalable. A single attacker can now do what a team of attackers had to be focused on in a fraction of the time. Meanwhile, enterprise security teams are dealing with even more limited resources, broken processes, tight budgets, and organizational boundaries.
What this means for security teams
We have to accept the fact that security by obscurity is dead. If something is misconfigured, eventually someone will find it. We can no longer rely on the fact that attackers don’t have unlimited resources because with AI agents and open-source models, they now kind of do. Security architectures built around the assumption that attackers won’t notice something will become increasingly fragile.
As things are evolving quickly, the question is - what does all this mean for security teams? In my mind, three things.
First, we need to invest in reducing exposure. This means embracing threat-informed defense and security by design. This means investing in foundational security disciplines - design reviews, asset management, vulnerability management and patching automation, and so on. This also means continuously interrogating defenses the company is relying on with tools like continuous pentesting.
Second, we need to amplify our advantages. In the world where AI makes analysis faster than ever before, the main advantage defenders have is information, which includes telemetry and knowledge about the environment. Unlike attackers, who have a limited amount of data to operate off of, defenders have access to a wide variety of signals that can all be correlated in a single interface. Moreover, they know (or ought to know) how to interpret what they are looking at because they know the processes and procedures the company operates on.
Third, we need to invest in enterprise resilience. While it is critical that we are putting in the effort to reduce the likelihood of a successful attack, we have to assume that despite our best efforts, some attacks will succeed. That means designing organizations that can absorb disruption, contain the blast radius, recover quickly, and continue operating through an incident. Redundancy, tested backups, incident response, disaster recovery, and clear operational procedures all become increasingly important (and the startups solving these problems will do well).
The point here is that AI is indeed changing cyber, but the most impactful of the changes are systemic changes, and not some magic tools.



