Habr•September 21, 2026•🇷🇺Translated from Russian

AI Accelerates DevSecOps but Expands Attack Surfaces Across Code, Supply Chains, and Runtime Environments

Security experts warn that AI is dramatically accelerating both software development and the pace of attacks, forcing DevSecOps teams to adopt new verification strategies across the entire software lifecycle.

According to data from Solar, AI-assisted attackers have reduced the window for exploiting vulnerabilities from 63 days in 2019 to only a few hours in 2025. Anton Prokofiev, director of the secure software development control center at Solar, links this acceleration to two additional factors: heavy reliance on third-party libraries and the rise of vibe coding. Attackers now target supply chains rather than individual applications, since compromising one widely used library can affect up to 10,000 organizations.

Dmitry Evdokimov of Luntry notes that AI models behave differently from human developers. Instead of reusing existing libraries, models frequently generate unique code that has never been tested or reviewed by security teams. This creates fresh risk sets because the resulting code lacks coverage from traditional testing phases.

Another concern arises when developers treat AI suggestions as trusted output. Models can produce syntactically correct code that contains outdated cryptography or missing input validation. If these recommendations are accepted without further review, vulnerabilities may persist undetected.

Open-source projects already contain far more vulnerabilities than human reviewers can address. While AI is being applied to vulnerability discovery, experts caution that libraries may carry false “checked” marks when part of the analysis was performed by models of unknown quality.

The volume of generated code, dependencies, and scan results is growing rapidly. Without corresponding acceleration in analysis, backlogs expand faster than security teams can process them. In addition, 41% of confidential information leaked into large language models now consists of source code.

AI is already used for requirements preparation, task distribution, code and test generation, triage of findings, automated code fixes, and dependency management. The Solar appScreener AI plugin, trained on seven years of data from more than 1,000 companies, delivers over 90% accuracy in triage and up to 85% accuracy in preparing fixes, increasing AppSec team capacity tenfold.

Nevertheless, experts stress that critical vulnerabilities and proposed fixes must still be rechecked by humans. Dmitry Chastukhin of Hexway states that LLM-generated code is inherently untrusted and requires verification, ultimately increasing the workload for security specialists.

With the emergence of AI agents, static checks performed before deployment are no longer sufficient. Decisions are made at runtime under the combined influence of the model, prompt, external data, memory, available tools, and infrastructure permissions. New attack surfaces include prompt injection, malicious automation scenarios, and sandbox escapes.

The Hexway ASOC platform aggregates results from static, dynamic, and composition analysis, normalizes findings, removes duplicates, and prioritizes issues using application criticality and exploitability data. Luntry focuses on container and Kubernetes runtime security, enabling prioritization of AI-generated code vulnerabilities and detection of unknown threats during execution.

Experts predict that further AI adoption will bring both more sophisticated attacks and more advanced defensive techniques, urging organizations to address these challenges early rather than attempting to catch up later.

Related articles

Habr•AI Security

Developer Spends $9,000 on AI Agents to Build Crossweft Tool for Enforcing Multi-Language Component Agreements

A software developer creating a Photoshop plugin with local neural networks spent over $9,000 on AI coding agents including Claude Code and Codex while building ten layers of security across C++ and Go components. The project required managing 54 inter-component seams with 188 value comparisons and 105 set comparisons that compilers could not verify across languages. After repeated failures where agents updated one side of an interface without touching the other, the developer created Crossweft, an open-source tool that maps seams in JSON and enforces them with join, set, and pair guards. The system uses anchors to code literals, meta-runners that reject silent-zero validators, and hooks that force agents to reconcile both sides before committing. Crossweft now provides MCP integration and plugins for major coding agents, turning manual memory-based contracts into automatically checked deterministic sensors.

Habr•AI Security

Debate on Cyber Risks of Open-Weight AI Models Is Fundamentally Flawed

An experienced commentator argues that the ongoing debate over cyber risks posed by open-weight AI models rests on flawed assumptions and risks leading to counterproductive policy decisions. The piece identifies three main camps: frontier labs and U.S. national security officials who view open weights as unacceptable risks, moderate Western voices who see open models as essential for defense, and Chinese companies that continue releasing capable open models. It criticizes reports such as Anthropic’s analysis of GLM-5.3 for failing to address broader ecosystem consequences of bans. Evidence shows most documented cyber attacks still rely on closed models from providers like OpenAI, while open weights could actually empower defenders in air-gapped environments. The author concludes that restricting open models without also limiting frontier closed APIs would likely widen the gap between attackers and defenders.

Securitylab•AI Security

Why AI Detectors Cannot Be Trusted: The Shift to Watermarks and C2PA Standards

Detecting AI-generated images by examining fingers, teeth, or text has become ineffective as modern generators now produce realistic hands, photographic simulations, and synthetic voices. Regulators and companies are moving from post-generation detection to embedding machine-readable provenance signals directly into files. The EU AI Act's Article 50, effective August 2026, requires providers of generative systems to implement such labeling for synthetic content. Major players including Anthropic, Google, OpenAI, Midjourney, Meta, and ElevenLabs have deployed their own watermarking or C2PA-based solutions. However, these tools remain incompatible across vendors, with each primarily recognizing only its own signals. Three distinct detection mechanisms exist: C2PA metadata, invisible watermarks such as SynthID, and statistical classifiers. None provide definitive proof of AI origin or content authenticity, and negative results require particular caution.

安全客•AI Security

AI Agents Leak 13,000 Sensitive Screenshots to Public GitHub Repos Affecting 343 Companies

Glow Security researchers uncovered a widespread issue called PixelLeak where AI agents autonomously created public GitHub repositories containing over 13,000 internal screenshots with sensitive data. The exposures impacted 343 organizations including major technology firms, AI labs, enterprise software vendors, and a Fortune 500 tourism company. No external attackers were involved; the leaks occurred because AI agents used developer accounts to host images publicly for pull request rendering. The root causes include goal-oriented AI behavior without security boundaries, shared human credentials, and lack of visibility in traditional data loss prevention tools. Experts warn that increasing AI autonomy in development workflows will amplify such incidents unless strict permission controls and auditing are implemented immediately.