Microsoft Vice President David Weston argues that AI-driven cyberattacks necessitate a shift from reactive patching toward proactive, memory-safe software construction to counter the increasing abundance of digital vulnerabilities.
Key Points
- Microsoft executive David Weston warned at Black Hat USA that AI has ended the era of rare software vulnerabilities by lowering the cost of offensive cyber capabilities.
- Security teams are urged to prioritize memory-safe programming languages like Rust and formal verification methods to eliminate entire classes of software failures.
- Google successfully reduced memory-safety vulnerabilities from 75% in 2019 to under 20% by 2025 by adopting safer coding practices across millions of lines of code.
- The industry must leverage AI-driven productivity gains to fundamentally change software architecture rather than relying on traditional, reactive patch-management cycles.