Nobody wants to look backwards because AI companies are acting like they just discovered cybersecurity and software bugs, but for some reason InfoSec now also has a really short memory.
Just as a reminder, there was a time with no ASLR, no browser sandboxing, no AMSI, and far fewer exploit mitigations. Browser exploits regularly showed up in Metasploit. Java, Flash, ActiveX, Adobe Reader, and browsers were routinely exploited. Exploit kits were cheap, plentiful, and industrialized. Retailers got absolutely destroyed through POS systems. We’ve lived through waves of 0day and mass exploitation over and over again. There are tons of other examples if anyone cared enough to dig into how we got here over the last 20+ years.
None of this is to say AI isn’t a major shift. It is. But acting like cheap, scalable offense or a massive imbalance between attackers and defenders is some entirely new concept requires ignoring a whole lot of InfoSec history.