The Internet Was Held Together by Duct Tape, Vibes, and One Guy Named Greg
Turns out the most important piece of critical digital infrastructure on the planet wasn’t fiber optic cable or billion-dollar server farms. It was Greg. Greg in Finland. Greg who hasn’t slept since 2003 and survives entirely on black coffee, passive-aggressive GitHub comments, and the grim satisfaction of knowing that if he ever takes a vacation, your bank stops working.
Welcome to the era of AI cybersecurity, where machines are now doing in forty-five minutes what took human hackers months — and discovering that everything we thought was protected was basically held together by collective squinting and wishful thinking. A dentist somewhere in Ohio is now responsible for maintaining a patient portal he described to his IT vendor as “I want it calming… with mint tones… and no hackers, please.” Nobody told him the hackers now have the same AI assistant he uses to write his Yelp responses.
AI Found a 27-Year-Old Bug Like It Was Cleaning Behind the Fridge
Here’s what happened, and try not to panic: AI systems are now finding security vulnerabilities that have been hiding in code since 1999. Not metaphorically hiding. Actually hiding. Sitting in the digital equivalent of your grandmother’s attic, wrapped in a Blockbuster Video bag, waiting patiently for the right maniac to come along.
One research group, AISLE, has been running an AI-powered vulnerability discovery system since mid-2025 and found fifteen CVEs in OpenSSL alone — including twelve in a single security release, covering bugs dating back more than twenty-five years. One of them rated a 9.8 out of 10 on the severity scale, which in cybersecurity terms is the equivalent of discovering your fire escape is actually just a painting someone did of a fire escape.
Somewhere, a line of code written by a sleep-deprived programmer in Clinton’s first term just whispered, “I thought I got away with it.” It did not get away with it. The AI found it. The AI finds everything now. The AI is basically the world’s most unsettling garage sale inspector, lifting every dusty box and saying “oh, this is bad” in a calm, robotic voice while you stand there pretending you knew about it.
Vibe Coding Sounds Like How I Fixed My Wi-Fi Last Tuesday
We’ve entered the age of vibe coding, which is exactly what it sounds like and somehow worse. Instead of learning actual programming, people now describe their feelings to an AI and hope it produces working software. “I want it fast. Kind of energetic but also trustworthy. Maybe with a teal accent color.” And somewhere, an AI dutifully builds them a customer management system that controls access to patient records.
According to NPR, the head developer behind cURL — a 30-year-old open-source data transfer tool used in everything from cars to medical devices — started noticing AI-generated bug reports flooding his inbox early 2026. The reports were four hundred lines long for problems a human would explain in fifty. The AI writes bug reports the way your uncle writes birthday emails: technically covering the subject, but also somehow going off on three tangents about Vietnam.
He stopped paying bug bounty rewards. He couldn’t tell the real issues from the AI-generated slop. Which is fine, totally fine, because cURL only powers the data transfer infrastructure for, you know, cars and medical devices. Nothing critical. Everything is fine.
Big Tech Got $100 Million in AI Credits. Greg Got a Thank-You Sticker
Let’s talk about the economics of this situation, because they are spectacular in the specific way that a barn fire is spectacular — impressive to look at, terrible to be inside.
DARPA’s AI Cyber Challenge pulled in Google, Microsoft, Anthropic, and OpenAI, each donating $350,000 in AI credits. The winning team took home four million dollars. The competition’s AI models discovered 77% of vulnerabilities tested and patched 61% of them in an average of forty-five minutes. DARPA called internet infrastructure “ancient digital scaffolding” and said the problem is “beyond human scale.” These are not the words of people who are confident about the structural integrity of the bridge you drive on every morning.
Meanwhile, the open-source volunteer community — the actual people holding Greg’s metaphorical duct tape in place — received community appreciation, a GitHub star, and the spiritual reward of knowing they matter. As the Open Source Security Foundation has documented, around 97% of all software applications use open-source code, and 82% of those open-source components are considered risky due to poor maintenance, outdated code, or security flaws. The entire digital world is a potluck dinner where most of the dishes were made by volunteers who are also tired and slightly resentful about the whole potluck concept.
Hackers Now Have the Same Tools as Your Local Bakery Owner
Nothing says the future is here like giving both a neighborhood bakery owner and a state-sponsored cybercriminal the exact same AI assistant and wishing them both the best of luck. It’s like handing out lockpicks at a neighborhood watch meeting and then being surprised when someone picks a lock.
The AI hacking boom produced over 70 new offensive security tools in eighteen months. One Chinese AI offensive tool went from GitHub upload to confirmed attack campaign in under two months. A research team gave an undergraduate student with zero cybersecurity experience access to an AI security framework and enrolled him in a national competition. He performed at the level of intermediate competitors who had spent months training. The kid had been at it for a weekend. Your daughter’s science fair project has a steeper learning curve than becoming a cyberattack operator in 2026.
The technical capability rankings reshuffled completely, with research showing that small open models outperformed most frontier models from major labs on basic security reasoning tasks. Cybersecurity used to be pay-to-win. Now it’s pay-to-win AND free-to-lose at the same time, which is a new category of unfairness that economists haven’t named yet.
The Internet’s Security Strategy Was “Don’t Look Too Closely,” and It Worked Until It Didn’t
Here is the most honest sentence anyone has ever written about internet security: the bugs stayed hidden for twenty-seven years because nobody could find them. That’s not security. That’s just everyone, collectively, squinting and hoping. It’s the digital equivalent of not looking under the bathroom sink because you don’t want to know what’s under the bathroom sink.
The open-source AI Cybersecurity framework CAI has already proven itself in real-world bug bounty programs and security competitions. AI systems can now plan and sequence known attack techniques, adapt within a defined scope, and complete multi-step tasks without human guidance at each step. The researchers who built the taxonomy describe current AI systems as sitting at Level 3 to 4 on a five-level autonomy scale. Level 5 is “fully unsupervised, goal-directed autonomous operation.” We are one upgrade away from an AI that decides, entirely on its own, that your hospital’s medication dispensing system has an interesting architectural flaw worth exploring.
Firefox, bless its honest heart, announced it fixed most of its bugs. Meanwhile, AI security tools are in the back row, leafing through Firefox’s homework like it’s a magazine in a waiting room. “Oh, here’s a nice one. And this one. Oh, they didn’t even know about this one.”
Your Local Shop Owner Is Now a Full-Stack Cybersecurity Professional Against Her Will
She just wanted to track inventory. She went to a website builder, clicked some buttons, picked a template that looked “clean and professional,” and now she is personally defending a database containing 4,000 customer credit card numbers against automated attacks originating from three continents and a teenager in Minsk who goes by xXDarkByteXx.
Nobody told her any of this was part of the deal. She thought “website” meant “website.” She did not realize “website” meant “publicly accessible server running software maintained by volunteers who are also working their day jobs, containing code written in 2004, connected to payment processors using certificates she doesn’t understand, while nation-states probe her contact form looking for injection vulnerabilities.” If someone had explained all of this at the beginning, she would have kept the paper ledger.
The Détente Is Over, and That Phrase Is Way Too Dramatic for What It’s Actually About
Anthropic’s Project Glasswing announced in April 2026 that their Mythos AI model had found “high-severity vulnerabilities, including some in every major operating system and web browser.” Every major operating system. Every major browser. This is the sentence that contains the word “every” and the phrase “high-severity” and is followed by people in press releases talking about “exciting opportunities.”
The CEO of the Linux Foundation noted that the foundation is part of Project Glasswing, and that a core group of Linux kernel maintainers have started experimenting with the technology. Linux powers all 500 of the world’s most powerful supercomputers and the Android phone in your pocket. When the Linux Foundation says it’s “experimenting,” that’s the polite way of saying “we built the highway and now we’re learning for the first time whether it has brakes.”
The good news is that patching a vulnerability in most industries takes sixty to ninety days. The bad news is that patching one in healthcare takes an average of 491 days — and the AI found 500 of them in an afternoon. Healthcare systems “must maintain 24/7 uptime and they don’t get to reboot,” as one HHS official put it. So if you have a surgery scheduled, maybe ask them to do a quick restart first. Just as a precaution.
We Democratized Creation But Forgot to Democratize Defense
The real punchline — and it’s a good one, in the way a car crash in a movie is good — is that we gave everyone the tools to build and nobody the tools to protect. Vibe coding let a dentist build a patient portal. The same AI let someone else find the seventeen ways into that patient portal before the first appointment was scheduled.
We made everything easy. Writing code: easy. Finding flaws in code: also easy. Weaponizing those flaws: apparently a weekend project for a motivated undergraduate. The only hard thing left is explaining to your parents why their bank app is now requesting permission to “access contacts, camera, microphone, and your childhood memories.” The answer is that nobody actually knows, and the AI that approved the update isn’t talking.
The internet is a public road maintained by volunteers with a hammer while corporations drive tanks on it. That’s the infrastructure model. We built it this way because it was cheaper. It worked because everyone was squinting hard enough. Now the squinting stops, and Greg in Finland is going to need a much bigger hammer.
He still won’t sleep, though. The sticker wasn’t worth it, but the principle definitely is.
Auf Wiedersehen, amigo!
Background: Anthropic’s April 2026 launch of Project Glasswing and its Mythos AI model revealed that artificial intelligence systems can now find and exploit software vulnerabilities in hours that previously took security researchers months or years to uncover. The model found high-severity vulnerabilities in every major operating system and web browser. At the same time, open-source cybersecurity AI frameworks — freely available online — have lowered the barrier to conducting cyberattacks so dramatically that an undergraduate student with no prior security training can now perform at a competition level, while the volunteer developers who actually maintain the internet’s foundational software continue to work with minimal resources. The DARPA AI Cyber Challenge, backed by Google, Microsoft, Anthropic, and OpenAI, awarded $4 million to the top team whose AI systems patched discovered vulnerabilities in an average of 45 minutes. Meanwhile, 82% of open-source software components — which underpin 97% of all applications — are considered risky due to poor maintenance and outdated code. DARPA Director Stephen Winchell described the situation as “ancient digital scaffolding” presenting a problem “beyond human scale.”
