BeyondTrust CTO on Code Red and AI Security
21m
Code Red Still Offers Security Lessons
Mike Vizard speaks with Marc Maiffret, CTO of BeyondTrust, about the legacy of the Code Red worm and what it can teach security teams about AI security. Maiffret explains that Code Red was one of the first automated worms to spread widely across Microsoft web server environments. It exposed how quickly an attack could move when organizations lacked visibility, monitoring and strong default controls.
AI Increases Attack Speed
The conversation connects that history to the rise of AI-driven threats. Maiffret says AI is amplifying many of the same risks security teams already know. Attacks can now move faster, adapt more quickly and use automation at a level that was not possible during the worm era. That makes AI security a question of speed, visibility and resilience, not just another set of guardrails.
Shadow AI Expands the Attack Surface
Maiffret also discusses how AI adoption often starts in the shadows. Employees may adopt AI tools before the business has a formal strategy or approved security model. That creates new risks because AI can connect to endpoints, cloud services, code repositories and sensitive data. In some cases, non-developers can now build applications or deploy infrastructure with help from AI systems. That expands the attack surface in ways many organizations may not fully understand.
First Principles Still Matter
The discussion returns to long-standing security principles such as least privilege, secure defaults and attack surface management. Maiffret says those ideas remain essential for AI security. AI agents become more powerful as they gain access to more systems, so organizations need controls that limit blast radius and rightsizing of privileges.
Maiffret’s advice is direct. Security teams need to know their attack surface better than attackers do. If they cannot see where AI exists, what it can access and how it is being used, they cannot secure it. The lesson from Code Red is that waiting for the next major incident is risky. Teams should apply those first principles now before AI-driven attacks move even faster.