The CyberCall Podcast

When AI Generated Patches Become the New Vulnerability

Andrew Morgan

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 59:07

This week's conversation is one we believe every MSP needs to hear.

 AI-generated vulnerability patches have become the obvious next move for software developers drowning in a tsunami of CVEs. It sounds like a great answer, until you look at the actual data.

 That's exactly why we wanted Keith Hoodlet on the show. Keith just published the inaugural research from 1Password's new security research team, Off-by-1 Labs, and the findings are fascinating: when frontier AI models were tasked with patching six real, recently-disclosed vulnerabilities, they got it fully right without breaking anything else, just 26% of the time. More than half the time, the patch either didn't fix the vulnerability, introduced a new one, or both.

Keith's research can be found here.