Second is what my startup specializes in: the offensive part of security needs to become widely available. Asking if your system is patched tells you nothing about whether someone on the open internet with a model can break in. We have a few articles around SIEM evasion + new defensive methods and it's not pretty. An LLM in a good harness now are smart enough that you can get the equivalent of $50k human pentest from a few years ago for a few hundred dollars now.