I'm pretty optimistic that not only does this clean up a lot of vulns in old code, but applying this level of scrutiny becomes a mandatory part of the vibecoding-toolchain.
The biggest issue is legacy systems that are difficult to patch in practice.
The biggest issue is legacy systems that are difficult to patch in practice.
I'm looking at you, Android phone makers with 18 months of updates.
Bruce Scheier made a comprehensive analysis of the pros and cons and forces at play for adversary and defenders [1].
I think it's safe to predict yet more money previously directed to us techies will find its way to the Anthropics of this world.
[1] https://www.schneier.com/blog/archives/2026/04/cybersecurity...
I am thinking of situations where one of those aren't true - where testing a proposed update is expensive or complicated, that are in systems that are hard to physically push updates to (think embedded systems) etc