Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Security through obscurity is dead, and AI delivered the fatal blow

The Register ·
Security through obscurity is dead, and AI delivered the fatal blow

The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden.

It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency.

Now it’s obsolete.

Don’t believe us? Here’s proof.

Software vendors and independent researchers alike are now using AI agents to find bugs – some very obscure and decades old – across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers.

“You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,” Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register.

“The latest models were able to break those and say, ‘yeah, there’s significant vulnerabilities in here.’” Whether or not security through obscurity is dead “isn't even an opinion question,” Trend Micro’s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft’s record-breaking Patch Tuesday addressed 974 CVEs.

“When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,” Childs said.

“Telnet client – is this even still used in any secure environment? Windows RNDIS – the USB-networking protocol Microsoft has been trying to deprecate for years.

NFS Portmapper – 1980s Unix tech.

And Link Layer Topology Discovery – the Vista-era network-map protocol nobody's thought about since Vista – just to name a few.” Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours.

In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the “patch-gap” window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch – but before the downstream stable release was pushed to users.

What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS).

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›