Depending on vendors for security will not protect you


Table of contents
Subscribe to our newsletter
Get insights to help move your business forward.
What we heard at Black Hat—& what leaders should do next
Increase the speed at which your organization can delegate valuable work to agents without increasing unmanaged risk.
That objective framed many of our conversations at Black Hat USA 2026. Modus Create attended the conference to understand how AI is changing cybersecurity and what organizations must do in response.
Our central takeaway was clear: Depending on vendors for security will not protect you.
Cloud, software, model, and security-tool providers remain essential partners. But they cannot understand every business process, customization, integration, data flow, or AI agent operating in your environment. They also cannot assume responsibility for how your organization assembles and uses their technology.
The question is no longer simply whether your vendors are secure. It is whether your code and environment remain secure when those technologies are connected, customized, and given permission to act.
The economics of an attack have changed
Advanced exploitation once required scarce expertise, significant time, and specialized tooling. AI is lowering all three barriers.
The 2026 Verizon Data Breach Investigations Report examined more than 31,000 incidents and over 22,000 confirmed breaches across 145 countries. Its findings illustrate the growing gap between attackers and defenders:
- Vulnerability exploitation is now the leading initial-access method, responsible for 31% of breaches.
- Only 26% of critical vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated during 2025.
- Median remediation time increased from 32 to 43 days.
- Organizations faced 50% more critical vulnerabilities than in the previous reporting period.
- Third parties were involved in 48% of breaches—a 60% year-over-year increase.
The gap is difficult to ignore: organizations take a median of 43 days to remediate critical vulnerabilities while AI agents can increasingly develop working exploits in hours.
Scale will tip the balance
The problem is not only that individual attacks are becoming more sophisticated. Scale is changing the entire equation. In 2025, HUMAN saw AI-driven traffic increase by 187%, while traffic from AI agents and agentic browsers grew 7,851% year over year. At the same time, fake account creation attacks increased 89%, and carding attacks increased by more than 20%.
Organizations are producing and publishing more code than ever. AI-assisted development will continue to accelerate that growth, with 84% of developers stating that they use or plan to use AI tools in the 2025 Stack Overflow Survey.
That scale creates three compounding risks:
- The attack surface expands. More code creates more opportunities for vulnerabilities, unsafe interactions, and configuration errors.
- Remediation becomes more difficult. A vulnerability rarely affects one isolated component. Teams must determine where the code is running, what depends on it, which business processes it supports, and whether changing it will create another failure. As environments grow, the dependency graph becomes harder to understand and the time required to remediate increases.
- Attackers benefit from the accumulated data. Public code, vulnerability reports, patches, exploit examples, and security research create an expanding dataset from which AI systems can learn. Attackers can use that information to recognize patterns, adapt known techniques, and test more pathways than a human team could ever hope to examine manually.
The existing asymmetry between attackers and defenders will continue to be amplified where defenders must understand and protect their complete environment. Attackers need only find one viable path to exploitation.
ExploitGym shows what is becoming possible
ExploitGym asks a consequential question: Can an AI agent turn a known vulnerability into a working attack?
The benchmark gives an agent vulnerable source code, an input that triggers the vulnerability, and a test environment. The agent must transform that starting point into unauthorized code execution.
The published ExploitGym research evaluated 898 instances drawn from real-world vulnerabilities in applications, the Google V8 JavaScript engine, and the Linux kernel.
Here are some findings that stand out:
- Leading models produced working exploits for 157 and 120 vulnerabilities.
- Agents sometimes found easier attack paths instead of using the assigned vulnerability.
- Different models found different exploits, suggesting that ensembles of agents can expand coverage.
- Conventional protections reduced successful exploitation but did not eliminate it.
- In one experiment, an agent converted a five-line V8 crash into a 229-line working exploit in 71 minutes. Some protections were disabled, an important caveat, but the agent still demonstrated sustained reasoning that previously required specialized human expertise.
The point is not that every vulnerability is now immediately exploitable. It is that exploit development is becoming less rare, less expensive, and more scalable.
Attackers can examine more code, test more targets, retry more approaches, and learn from a growing body of examples. Defenders must be able to operate at comparable speed.
Your providers secure their platforms—not your complete environment
Hyperscalers and technology providers invest heavily in security; their scale also makes them valuable targets. As we all know, a weakness in a widely used platform, service, or tool can have a ripple effect on downstream organizations.
More importantly, providers do not control or have insight into the system architecture you may have created.
Your risk exists in the combination of:
- Vendor platforms and proprietary code
- Configurations, permissions, and machine identities
- Third-party components and APIs
- Data moving between systems
- Development and deployment workflows
- AI agents with access to tools and sensitive information
A cloud provider can and will secure its infrastructure. It cannot determine whether your agent has excessive authority, whether a custom integration exposes sensitive information, or whether several individually permitted actions can be combined to create an unacceptable outcome. This is why the operative question is shifting from who performs an action to whether that action is authorized. Agents complicate identity in ways human-centric access models were never built for.
This matters across industries. In healthcare and life sciences, an exposed pathway may reach patient information, research data, clinical operations, or connected devices. In financial services, it may reach identities, payments, trading information, or lending decisions. In automotive, it may cross embedded software, supplier components, manufacturing systems, connected vehicles, and over-the-air updates.
Security remains a shared responsibility, but the consequences remain yours.
Periodic testing cannot match continuous change
Traditional penetration testing remains valuable in understanding the attack surface and where organizations need to focus mitigation efforts.
However, a penetration test conducted a few times each year provides a point-in-time view of an environment that will likely change each day. Code is updated, dependencies change, APIs are connected, and agents receive new tools, skills, and permissions.
The answer is more than simply shifting security left. Organizations need continuous agent assurance: measuring agent performance, bounding authority, detecting changing risk, and increasing delegation deliberately as evidence accumulates.
That means bringing security throughout design, development, deployment, and production:
- Threat-model systems and agent workflows during design.
- Test code automatically as it changes.
- Challenge agent permissions, tools, and data access.
- Validate whether findings are genuinely reachable and exploitable.
- Retest after fixes, configuration changes, and model updates.
- Monitor production behavior and maintain the ability to contain and reverse harmful actions.
- Use independent testing to challenge the automated system and uncover blind spots.
Modus Create is bringing security testing into the SDLC
Everything above points to our conclusion that the gap between attacker speed and defender speed is structural, not incidental. It won't close by hiring faster, testing more often, or trusting vendors more. The gap closes by building assurance into how software and agents are developed from the beginning.
Modus Create has been building an agentic framework that brings penetration testing and security testing capabilities directly into the software development lifecycle. Rather than waiting for a scheduled assessment or the next release cycle, agents examine code and system behavior more often, identify attack paths, validate which findings are actually reachable and exploitable, and hand developers actionable context while software is still being built.
The goal isn't to create more alerts. Security teams already handle more than they can reasonably act on. The goal is fewer, better findings, delivered early enough that fixing them is cheap rather than urgent.
No organization is working through this alone. Thanks to AI, the current landscape has moved faster than most existing assurance models were designed for. It's a shared problem that's worth working through together—assessing code, agent architecture, and delivery pipelines—and building a practical path toward continuous security testing rather than periodic snapshots.
Depending on vendors for security will not protect you. Understanding your environment, continuously challenging it, and building security into how your software and agents operate will.
Build secure AI from the start. Explore our security services →

Michael Hodgdon is VP, Product Engineering Services at Modus Create.
LET'S GET STARTED
Talk to Modus Create
Big challenges need bold partners. Let’s talk about where you want to go — and start building the path to get there.
Related Posts
Discover more insights from our blog.


