The Intersection of Sapiens, Software and Security.

5–8 minutes

TLDR; 2 things which totally changed the course of cybersecurity in 2026: a. LLM escaping the test lab setup and taking over Huggingface site and german equivalent of wikepedia. b. 6 times increase in critical bugs reported in H1’26 as compared to last 6 years. In this short blog let see how a single 0 day vulnerability can bring the global financial and supply chain to its knees. What can we as sapiens do to protect our software while we still have limited opportunity window from ”We found the bug” to ”Oops our data got hacked”


Some Stats for Context setting:

  • Top 100 software companies across the globe (FAANG among all others) reported 6 times more critical software bugs in H1’26 then altogether in last 6 years. (see pic1 from a16z.news site)

  • Out of these reported bugs and vulnerabilities – Staggering 87% of them are exploited on same day they are exposed on CVN site. This is up from 23% then last year.(see pic 2 from a16z.news site)

Let this sink for a second.

These are 0 day vulnerabilities which used to days and months to be exploited once exposed in the past. Now the exploit codes are up for grab and sale on dark web the same day.


Guess the common denominator among all this?

What changed in last 5 years to have these FAANG companies suddenly report 6 times the spikes in vulnerabilities?

Yes AGI(Artificial general intelligence) has not only fast tracked the development of all good things and race to solve all the universal problems faced by humanity but also supercharged the usage and exploit via wrong hands.

There is always a flip side to all the good things in life.

There are always tradeoffs in choosing A over B.

Its not even a century when first computer was created in mid 20th century and less then 50 years the very first software program was written by sapiens.

The speed with which this vulnerabilities are exploited in critical infrastructure is alarming and should be a concern for all.

The whole world and global economy is much tightly connected then we can think of. Lemme explain how:

For eg. the global financial system is pegged upon US$. All global trades and global supply chain highly depends on the US financial markets for this supply chain to complete. Many countries across the globe are highly dependent on this stability for them to import daily food and basic items for survival. In many countries the supply and stocks only last for days before they declare SOS. Hence millions of lives depends on this financial stability.

Imagine a singly 0 day vulnerability in one of the big financial institutions in NY if exposed and exploited some moments before they are patched can bring the whole system down to its knees.

Patching windows (for those who work in technology and familiar with the term) has drastically reduced. It used to be called as weekly or monthly patching or ‘Patch thursday’ etc. is pretty much dead. Gone were the days when companies can wait for their pre determined rythm or cycle for taking safety precautions.

Imagine now when 87% of the vulnerabilities are ready for exploitation same day, the window between companies from ‘We found a security bug’ to ‘Someone has exploited it already’ is narrowing down very close.

It’s not matter of IF but when these vulnerabilities will be exploited and bring the whole system crashing down.


Next few years.

Will be really difficult for most of the critical organizations who have critical infrastructure and software dependent systems eg. financial, healthcare and critical defence systems.

The speed at which new base LLM are release and along with bring the deadliest of technologies to be used by both sides is alarming. The new Astra model from OPENAI and Anthropic is one eg. of that. Within days of them being released most of the functionality was rolled back or kept for internal or government usage.

To quote Sam altman on a post after OpenAI’s 10,000-agent swarm claimed a result on a Millennium Prize math problem that stood for two centuries

 “I did not expect a result of this magnitude to happen so soon.”

This is much alarming as this sounds. When creator of such technologies are astonished with the capabilities it bring to the table, a lay man with limited knowledge of such should definitely panic.

The problem is; LLM’s not take sides. They dont distinguish between good and bad usage.

Only thing they care about is token supply and who is providing them. The same amount of tokens can be used to find cure for cancer and same ones can be used to develop the most deadly biological weapons for sapiens.

My take;

1. Cutting the attack surface or totally removing it.

Lemme explain. Most of the security vulnerabilities reported above are memory safety bugs caused by buffer overflows, overstack memory heaps etc. As reported by Microsoft in CVE and recently by google, majority of code written across the globe is in C, C++ or similar set of family.

Perhaps those were the best choice of programming language during those decades when compute was scarce resource and all programs revolved around optimization of memory resource.

I myself started by career in 2007 and gues what was the first language i started coding in (after FORTRAN in college)? C, C++ and C#.

All these memory stack issues are not present in current set of latest languages eg. RUST. The problem to rewrite the whole code written in last 5 decades are economical rather then intentional.

AGI does solve this problem and one way out is to rewrite the whole code bases and migrate to RUST et. al. In fact google recently migrated millions of lines of code to RUST using AGI.

2. Security by design.

Until very recently CISO (Chief information security officer) was a position somewhere down the IT landscape if it did existed in organzations.

Security was never considered as priority 1 or hardly discussed in board rooms. It was a priority number 1 (from the last) in the organizational roadmaps where each item should justify a business case.

Cybersecurity budgets of organizations has to be increased X times and priority should not be on just the Business value it brings but rather on the business value it protects.

3. Alignment problem of AGI.

To quote OpenAI’s Chief Scientist Jakub Pachocki who published an essay titled “An Alien Mind” that included this sentence:

“Currently I believe that no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.”

One of the biggest problems with all the AGI models being launched is alignment. They are based trained(most of the times) on whole of internet and sometimes on specific type of information sets.

Meaning they more or less can infer the next token on all knowledge ever created by sapiens. So they suffer from the same problem of knowlede as we do.

We only know what we know.

Humans can think of things which do not exist today based on the vast amount of knowledge which exists today and make new things.

AGI as of today cannot think and build new knowledge base upon this. Once ASI or singularity (a point of no return when Artificial intelligence becomes Super intelligence and technology advances with leaps and bounds we can ever think of) evolves we do not know what side will AI be aligned.

What do you think are the biggest threats from AGI? Curious to hear your thoughts.

Stay tuned!
Love & Peace,
//Chakshu arora.




Discover more from Welcome to chakshu scribbles | Food for thought, Beyond the NOISE.

Subscribe to get the latest posts sent to your email.


Leave a Reply

Discover more from Welcome to chakshu scribbles | Food for thought, Beyond the NOISE.

Subscribe now to keep reading and get access to the full archive.

Continue reading