How AI Quietly Multiplies Cybersecurity’s Hidden Dangers

AI lets employees deploy apps without oversight, creating exposures more dangerous than known flaws. CyCognito CEO Rob Gurzeev calls for continuous outside-in mapping that validates real attack paths. Recent White House and ransomware developments show the stakes rising fast. Defenders must adapt or fall behind.
How AI Quietly Multiplies Cybersecurity’s Hidden Dangers
Written by Sara Donnelly

Rob Gurzeev built his career on spotting what others miss. As CEO of CyCognito, he now watches AI reshape that challenge in real time. The tools promising faster code and smarter systems also spawn exposures that traditional defenses overlook. And the gaps grow wider by the day.

Enterprises once tracked assets they could name. Lists of IPs. Known servers. Approved applications. Those days ended with the surge in cloud services, shadow IT and now generative AI. Anyone with access to tools like Claude or similar assistants can launch internet-facing apps. Often without security review. The result? Blind spots more threatening than cataloged flaws.

The Next Web reported on July 19, 2026, how Gurzeev frames the shift. AI no longer sits at the business edge. It threads through core operations. “These systems aren’t adjacent to the attack surface anymore. They are the attack surface,” he said. Short. Direct. A warning backed by years in intelligence work.

Gurzeev’s background informs everything. As a teen he tinkered with computers and IRC channels. Later he joined an intelligence unit focused on reconnaissance. The work demanded starting from almost nothing. A name. A target. Then mapping paths of least resistance. “Honestly, this work chose me more than I chose it,” he recalled. That mindset carried forward. “You never actually know what reality is. You have to go find it. Validate it.”

Contrast that with most security setups. They assume complete knowledge of assets. They scan what appears on internal lists. Yet real attackers operate externally. They probe whatever faces the public internet. CyCognito’s platform starts with only a company’s name. It discovers every exposed application, device and cloud instance. Then it traces connections to internal networks and data. Not every weakness. Only those an attacker could actually chain together.

The numbers stun. A typical large enterprise might expose 100,000 assets. One CyCognito customer faces 100 million potential interaction points from outside. And the surface shifts constantly. Between one and three percent changes daily. Most security spending protects a few hundred or thousand key items. The rest? Left open. “Guarding the front door while you leave the windows open is not a strategy,” Gurzeev observed.

AI accelerates the expansion. Non-technical staff in HR or finance can spin up applications using AI coding assistants. Sometimes on purpose. Sometimes by accident. These tools lower barriers so far that secure development lifecycles get bypassed. Research shows AI-generated code carries higher vulnerability rates than human-written equivalents. Yet measurement remains imprecise. “The honest answer is we’re defending more of something less safe, and we can’t yet measure exactly how much. That uncertainty is itself the risk,” Gurzeev added.

Recent developments underscore the point. Forbes highlighted today how the White House launched the Gold Eagle initiative. It coordinates federal agencies and industry to identify and fix software flaws before AI-powered attackers strike. The effort acknowledges that automation now speeds both offense and defense. Separately, researchers identified JADEPUFFER, the first ransomware strain fully driven by an AI agent. It handled reconnaissance, credential theft, encryption and ransom note creation without human input. The pace quickens.

Other coverage reinforces the pattern. A NordLayer analysis from earlier this month noted AI’s value in vulnerability management and endpoint protection. Yet it also creates new blind spots. Models trained on known patterns can misclassify novel malware as benign. False negatives slip through. Human oversight stays essential. Feedback loops help models improve, but over-reliance invites trouble.

CyCognito takes a different tack. Its latest capabilities emphasize continuous testing. Full external discovery first. Then AI validates complex attack paths that simple scanners miss. The system runs over 100,000 automated checks on known issues. That frees advanced reasoning for high-impact chains. Once validated, those paths turn into repeatable tests. Coverage widens over time.

Gurzeev sums up the requirements. Three things must run without pause. Know current exposures. Understand which an attacker could truly breach across the entire surface, not just samples. Remediate priorities in hours. Periodic scans no longer cut it. Attackers adopt AI too. Defenders must match that tempo.

His optimism rests on efficiency. Organizations won’t win by outspending rivals on compute. They will prevail by directing resources with precise context. “The winners won’t be the ones who spend the most. They’ll be the ones who use it most efficiently, getting the most out of every dollar of compute by pointing it with context instead of running it blind. Do that, and defenders catch up.”

Industry voices echo parts of this view. A KuppingerCole webinar last October featured Gurzeev discussing continuous, ownership-aware discovery. It helps close gaps that surface scans miss. Attacker-first thinking shapes future approaches. Meanwhile, Trend Micro’s guidance on attack surface management stresses ongoing discovery, assessment and mitigation. The consensus builds. Visibility precedes protection.

Yet challenges persist. Dynamic IPs complicate inventories. Forgotten cloud instances linger. Shadow AI deployments multiply. Traditional tools focused on known lists fall short. Outside-in mapping, paired with validation that mimics adversary logic, offers a counter. Not perfect. But grounded in how breaches actually occur.

Look at recent incidents. AI agents now automate entire intrusion sequences. Ransomware evolves faster. Critical infrastructure faces coordinated threats, prompting White House action through Gold Eagle. Financial institutions watch governance lag even as AI adoption in security hits 78 percent, per recent reports. The gap between capability and control widens.

Gurzeev’s message lands clearly. Stop assuming you know your assets. Go find them as an outsider would. Test what matters. Fix fast. In an era where AI lets anyone deploy code, that discipline separates those who manage risk from those who merely catalog it. The blind spots don’t vanish on their own. They demand constant scrutiny. And the tools to address them exist. If security teams choose to use them.

Subscribe for Updates

AISecurityPro Newsletter

A focused newsletter covering the security, risk, and governance challenges emerging from the rapid adoption of artificial intelligence.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us