• 3 min read
AI made shadow apps a bigger security risk
CyCognito CEO Rob Gurzeev says AI is flooding companies with internet-facing apps outside normal controls, creating attack-surface blind spots.

Image: TNW
AI has made it dramatically easier for employees across a company to launch internet-facing applications, and CyCognito CEO and co-founder Rob Gurzeev argues that this has turned cybersecurity’s biggest blind spot into a more urgent problem than many known vulnerabilities.
His core point is simple: security teams often focus on assets they already know about, while attackers look for everything exposed to the internet — especially the forgotten, unmanaged, or accidentally published systems that sit outside standard processes.
Gurzeev traces that view back to his own background in cybersecurity and intelligence, where he worked on reconnaissance and attack-surface operations.
“Honestly, this work chose me more than I chose it.”
He said those roles often started with little more than a name and required finding “the path of least resistance into something that mattered.” That experience still shapes how he thinks about defense.
“I was taught you never actually know what reality is. You have to go find it. Validate it.”
Outside-in attack surface mapping
CyCognito’s approach starts with a company’s name, then maps what is exposed to the internet from the outside in. That includes unmanaged or forgotten assets, before testing those systems to see which weaknesses are actually exploitable.

Recommended reading
Joomla extension bugs hit CISA’s exploited list
As Gurzeev puts it, the platform maps everything a company has exposed online and traces the paths that could lead into internal networks and sensitive data. Rather than stopping at a vulnerability scan, it tries to validate what an attacker could really use.
“If I had to name the one thing that makes us unique, it’s that our platform thinks like an attacker. That should be obvious. It isn’t.”
The scale is large. Gurzeev estimates a large enterprise typically has about 100,000 applications, devices, and cloud assets exposed to the internet. He said CyCognito’s biggest customer has around 100 million externally reachable assets, and that external attack surfaces shift by 1% to 3% every day.
AI is accelerating the exposure problem
Gurzeev said AI-powered coding tools are making the problem worse by letting non-developers build and deploy software without going through established security reviews.
“Today, anyone and everyone can deploy an app. Someone in HR or finance can spin up an application with a tool like Claude Code or Lovable and expose it to the internet, on purpose or by accident.”
He argues that AI is no longer sitting at the edge of the business. In the last six months, he said, it has moved into core infrastructure, meaning these systems are now part of the attack surface itself.
He also pointed to research suggesting AI-generated code introduces vulnerabilities at higher rates than code written entirely by humans, while much of that software bypasses secure development practices organizations spent years building.
That is why, in his view, periodic testing is no longer enough. He says security teams now need three things continuously:
- know what is exposed right now
- know what across that full environment is actually exploitable
- fix the issues that matter within hours
CyCognito’s latest release is aimed at that model, combining full attack-surface discovery with AI-powered validation. Gurzeev said the platform continuously runs more than 100,000 automated checks for known issues, while using AI for the more complex attack paths that standard scanners tend to miss.
“The winners won’t be the ones who spend the most. They’ll be the ones who use it most efficiently, getting the most out of every dollar of compute by pointing it with context instead of running it blind.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TNW


