We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
In this interview from Black Hat 2026, David Weston, corporate vice president of AI security at Microsoft Corp, joins theCUBE's Krista Case to discuss how AI is collapsing the scarcity economics that cybersecurity has long relied on. Weston explains that traditional defenses assume security boundaries — network, kernel, hypervisor — hold firm because exploits are rare and expensive. AI is erasing that scarcity: Microsoft's Patch Tuesday vulnerability count is doubling every six weeks, and one internal tool has already found 66% of the vulnerabilities discover...Read more
exploreKeep Exploring
What does the rise of AI-enabled vulnerability discovery—and the resulting end of "scarcity economics" in cybersecurity—mean for security teams?add
Is faster patching an adequate defense against AI-accelerated attackers, and if not, what defensive strategy should be used instead?add
What three recommendations did the speaker give for improving security against AI-driven attackers?add
>> Welcome back to theCUBE. We are live here at Black Hat 2026. It's day 2. We've got a lot of really great coverage for you today. And in this next conversation, we're going to be talking about how AI is changing the cost economics of the adversarial perspective. So our attackers are using AI to really elevate their level of expertise to move faster and at a greater scale than we've ever seen before. And for security teams, that means that they don't have as much time to respond and react. In fact, in some cases, they might have almost no time. So they're trying to find new ways to rethink the fundamentals of their security practices and maybe even fight fire with fire a little bit and find ways to use AI to try to keep up. I have a really exciting guest today, David Weston, CVP of AI Security with Microsoft. David, welcome to theCUBE. Thanks for sitting down with us.
David Weston
>> Excited to be here.
Krista Case
>> Yeah, absolutely. So David, you actually were on the main stage here at Black Hat yesterday. You were giving a talk called "The End of Rare: Defending When Offense is Cheap." And I know before we went live, we were talking about considering this concept of offense is cheap, it can come across as a little bit doomsday. And when we're all walking around here this week thinking about the potential implications of adversaries plus AI, it's easy to kind of fall into that, for sure, that potentially the sky is falling, right? So can you talk about what this Offense Is Cheap, what this concept means for practitioners and why there actually might be some optimism there?
David Weston
>> Yeah, for sureSo the basic concept of the talk is, first of all, cybersecurity, in my estimation, is built on a concept of scarcity, scarcity economics, which is a lot of the way we protect our networks is using what I call security boundaries. That's network, kernel, hypervisor, right? You're segmenting and then creating policies through authorization, encryption, et cetera, on where you wanna let people in. So you can think of that as the walls of the foundation. And the presumption is like those walls hold up. So you can focus on other things like credential theft, et cetera, because hey, this is the place I'm secure. And then, There's a place I have to man the door of people coming in. I don't have to worry about the wall getting busted down. The problem with that is that scarcity economics has been based on, hey, this zero-day vulnerability might go for $20 million on a mobile phone. A single vulnerability that hasn't even been exploited might cost $200,000 or $300,000, maybe a few million depending on the surface. So those are, the scarcity is baked in there. You can tell just by the prices of the bounties. And that's in the realistic markets. In the gray markets, it's completely different, and even
David Weston
>> higher.So we've baked this
David Weston
>> in.We said we're safe because this is rare and it costs a lot. Unfortunately, AI's changed this. It's no longer rare. And I went into some of the data. So for example, MSRC sort of runs our Patch Tuesday program of vulnerabilities. We are doubling the vulnerabilities we're patching every 6 weeks.
David Weston
>> Wow.
David Weston
>> Wow. For another example, we use an internal tool to find vulnerabilities in Windows. We found since April 1st, 66%, just this one tool, of the vulnerabilities found all last year through bounties and every source. So there's a spike. Now we don't know if that spike will hold, but I wouldn't bet against it.
Krista Case
>> Right, exactly, exactly. So what does this mean for security teams? we've kind of really optimized for patching and defense as you're alluding to. And you're almost alluding to the fact that we need more resilience these days, but can you talk through kind of what's the impact to security teams?
David Weston
>> Yeah, so I think the intuitive thing you wanna do here is you wanna say, well, they're finding more bugs, so let's patch faster. Unfortunately, even if we could patch as fast, that's still a fundamentally reactive strategy. In a world where I can weaponize a vulnerability fast, patching fast is not a really great strategy, 'cause patching fast is still a day or two, right? Maybe a few hours, but you— the attacker— you're still giving the attacker that window. And so my argument is attackers have a couple things going for them. One is asymmetry. They only have to be right once.
Krista Case
>> Yes.
David Weston
>> The second thing they have going for them is they are the first movers here on AI. They're very agile. They don't have to deal with compliance or auditing, etc. So they can just pick up a tool and start using it. We don't want to play the game where the asymmetry favors them. What my argument is, is fundamentally what AI is doing is making everyone more productive, particularly engineers. Let's invest that productivity in changing the physics. So I argue for more safety by construction. Which is pretty similar to CISA's Secure by Design push over the last several years. I argue for using formal methods and verification of software so we can mathematically prove the software is safe. And then I gave gobs and reams of data on projects that are actually doing this to sort of prove that. Because I think there is some skepticism, like, that sounds pretty radical. But I think this is, in my opinion, we need to have radical acceptance of the circumstances we're in and convert that into positive energy for things that are going to work.
Krista Case
>> And again, I think that there's a lot that we can do, right? I think there's a lot of opportunity there. So you're talking about maybe secure code by design. Can you talk to engineering software design folks involved in resilience? How are they becoming part of that security team almost these days?
David Weston
>> So what we've seen, and I gave some pretty stunning stats from Google where they invested heavily in Rust, which is one of these safer languages. And about 75% of their vulnerabilities back in 2019 were memory safety issues, the kind that are now being spit out at astonishing rates, right? In Patch Tuesday, et cetera. And now in 2025, they're reporting less than 20% of the same types of vulnerabilities. And for the 5 million new lines of code they've written, not a single new memory safety issue. So they've brought down the total number of vulnerabilities and the stuff that they actually rebuilt safely is safe. So for practitioners, I said, look, the only reason you wouldn't follow Google is it's expensive or you don't know how to do it. This is where AI can make it cheaper to convert your code bases or write new code bases, right? That's one thing AI is really good at, is helping you write code. And number two, you can also even convert existing code into Rust.
Krista Case
>> So David, I know you've also talked about potentially trying to eliminate classes of vulnerabilities. I know that that was one part of your talk and your thesis there. So what are some of the engineering practices that you think we're going to need to at least work towards that goal?
David Weston
>> Yeah, I think the first thing is, we need to start leveraging AI to build code that's constructed in safer languages that just by design doesn't have memory safety issues. Now the problem with that is even if the 70-75% of the issues are memory safety, even if you got there, you're still leaving a quarter of the issues unfixed. So the next thing I want software security teams to do is get their specifications in order and figure out those boundaries where code matters the most and start working with a technology called formal verification. Formal verification is a set of tools that essentially turns your program's logic into a mathematical representation, and then you can test it either symbolically or in abstract math and say, can it ever fail? And I gave two good examples of both Microsoft and Apple who took their core encryption libraries and formally verified them using this. And in the Microsoft case, which I can talk about, we were able to get massive productivity increase by using agents to do this. So we'd basically give it the documented specs.
Krista Case
>> Yeah.
David Weston
>> And they would convert that into this formalized proof language. And then we could test for the existence of any violations around encryption. And we found one that would have been pretty catastrophic had we shipped it. And it passed all the tests. It passed all the analysis of human experts. And Apple had a similar case. So in my talk, I argue you're seeing two of the most important software libraries on the planet having good experiences here and using agents to get there. This is my call to action to everyone, you have to start experimenting with this in your codebase.
Krista Case
>> so that makes sense at a company of the scale of Microsoft and Apple and kind of where you are creating this software. What should our kind of security practitioners take away from this in terms of maybe some tactical things they can do for their own organization?
David Weston
>> I think the whole industry seems to be shifting left a bit and saying, I now have to care about application security. Even SOC practitioners now are getting tools and getting more focused on software security. I think what I'm advocating is shifting left even a little further and having practitioners advocate that it's going to help them, and making sure that some of these new tools, memory-safe languages and formal verification, are in that SDLC. So practitioners making sure that they're thinking about how to integrate that. Maybe 5 years ago, I think people had a similar viewpoint around Rust, which has gone pretty mainstream, and people said, oh, that's too complicated. No one wants to write that. I don't have the expertise. Now we're seeing so many startups, so many mainstream companies adopting that. I predict the same thing for formal methods and formal verification.
Krista Case
>> Yeah, yeah, that makes a lot of sense. So for a CISO that's really looking to not just build the prevention up front, but also really build their overall resilience. What are maybe a couple of steps that you would recommend that they take?
David Weston
>> So 3 things I called out in my talk. First is start picking your most critical code bases and start picking the AI tools that are going to convert them to safer languages.
Krista Case
>> Yep.
David Weston
>> Step 2, once you've got it converted, figure out how you're going to take the specifications and have agents formally verify it. Number 3, stop focusing so much on detection. You will lose the detection battle against AI agents, even with the help of AI. Again, it's asymmetric, and I tried to argue that in my talk. But if you start converting more of your infrastructure to code, IaC, and you start using agents to reason about that, similarly, you can actually change the economics of attackers. And I sort of showed through statistics, if you combine memory safety, formal verification, and infrastructure validation, you've basically taken away most of the places that attackers are successful today. And if we achieve this, we could actually be looking at disrupting attacks over time. I know everyone thinks I'm wild for that, but look, I've lived this at hyperscale in Windows at Microsoft. I know it can be done.
Krista Case
>> Yeah. And so I guess talk through some of that pushback that you maybe are hearing and I guess how you're countering that.
David Weston
>> Well, the pushback— I'll use an analogy. It's kind of like if someone came to you and said, I need to get in shape. And you went, there's a fad diet or someone tells you eat less and work out more. You never want to hear that, right? But the truth is the AI era is calling in all the tech debt and the bad habits.
Krista Case
>> Yeah.
David Weston
>> It's now time for us to drink our smoothies, manage our calories.
Krista Case
>> I've had that conversation countless times.
David Weston
>> And so I'm really laying that out. Memory safety, that is just eating your vegetables. Formal verification, that's really working out, getting those six packs and then moving towards prevention. They're just— if you play this forward, This is the only way in my opinion.
Krista Case
>> Yeah, and so David, hopefully we have the chance to sit down again at Black Hat next year.
David Weston
>> Sure
Krista Case
>> . Right? What do you think we'll have learned over the next 12 months? Because it's changing rapidly as your research has shown.
David Weston
>> Yeah, I think the curve will continue to bend in the wrong direction.
Krista Case
>> Yeah.
David Weston
>> There'll be more vulnerabilities.
Krista Case
>> Yeah
David Weston
>> . And I showed in our talk that not just vulnerabilities, but converting those to exploits, which is really gonna start bringing down those boundaries. And I think that the industry will be forced to grapple with how to deal with this. I think that will push us to eating our vegetables, et cetera. So here's what I predict a year from now is we will have more projects moving towards memory safety. We will have more experimentation with things like formal methods and having agents write that. And I definitely think we'll see more focus on prevention and using infrastructure as code to get really clean and clear deterministic understanding of where the problems are and using agents to fix them.
Krista Case
>> Absolutely. And I'm curious, are you more concerned about novel attacks, or are you more concerned about the speed and scale that these vulnerabilities can be exploited? I'm trying to—
David Weston
>> Yeah, both. I think speed and scale will be main factors, but I think the sophisticated actors will quickly understand I can actually find vulnerabilities that were really not accessible to me before with AI agents. And so I think there's a lot of things happening below the surface.
Krista Case
>> Yeah.
David Weston
>> Across various threat actor groups that are only now going to play out in the next 6 to 9 months.
Krista Case
>> Mm-hmm. That makes sense.
David Weston
>> And I think that that will put more pressure on defenders. And I think we'll be faced with the choice of, do we try to play their game and just move faster? I think that's a losing strategy.
Krista Case
>> Yes.
David Weston
>> Or do we play a different game that favors us that might be slower and more expensive, but will get us to the right place?
Krista Case
>> Absolutely. And David, where do you think humans are going to have the most critical areas of expertise? Because we are going to have to lean on AI in order to do this.
David Weston
>> Yeah. YeahI look at AI as the Iron Man suit, so to speak. there's still going to be someone at the center. You're just getting more superpowers that you can direct, right? If you're not a code writer, you can now direct agents to do that. But you have the security subject matter expertise. So I find this very empowering. And so I think we're going to look at trying to make Practitioners more holistic in the set of tools that they have available, and that'll increase the scale of projects and the ambition of the projects we can achieve. And I'm really hopeful that we'll see more investment in those places.
Krista Case
>> Yeah, that makes sense. Well, David, thank you so much for sitting down with us today. It's been really interesting. We appreciate it.
David Weston
>> All right. Thank you.
Krista Case
>> All right. Thanks so much.
David Weston
>> Thanks.
Krista Case
>> Bye-bye. Thank you for watching. We'll be back in just another minute with more of our coverage live from Black Hat 2026.