Home
  • Contact
  • Work
  • Insights
  • About
  • Contact

London.

65 Leadenhall Street
London EC3A 2AD
View map
  • LinkedIn
  • Instagram
  • YouTube
  • Creative Pool

© 02.03.04 – Dusted Design Partners (trading as “Dusted” in the UK) is part of Dusted Group Limited. The Dusted name, Dusted logo and “D.” device are registered trademarks (in the UK) of Dusted Design Partners.

  • Privacy policy
  • Cookies policy
Accreditation
Home
September 22, 2026 • 7 min read

AI is making vulnerability discovery easier. Your website needs to be harder to break.

by Matt
Digital

LLMs are lowering the effort required to find and exploit weaknesses in your website. The risk facing a modern digital presence is less about sophisticated AI attacks and more about relentless, scalable discovery of exposed plugins, weak authentication, misconfigured APIs and predictable code patterns.

Security testing is no longer scarce or slow

Historically, searching for software vulnerabilities was constrained by time, expertise and manual effort. Penetration tests were scheduled annually, security audits were expensive and malicious actors had to carefully choose which targets were worth probing.

Generative AI and automated LLM-based security tools have completely inverted this dynamic. What used to require a skilled security analyst hours of custom scripting can now be executed extremely quickly across several IP addresses simultaneously. AI agents can continuously crawl web applications, analyse client-side JavaScript, map out API endpoints and test for known exploits with marginal costs.

Security testing is no longer a scarce or slow resource reserved for annual compliance checks. Because vulnerability discovery is now fast and relentless, any online asset, regardless of size, is subject to perpetual probing.

As an example, Wordpress has had to release six security updates to its core codebase between May and September 2026 (one of which was released while I was writing this article). The same time period in 2025 saw only two updates. This isn’t because it has become less secure, it’s just getting existing vulnerabilities highlighted more frequently and they are releasing fixes before they can be taken advantage of.

The vulnerabilities most likely to be exposed faster

Attacker scripts and automated discovery tools do not need to invent novel zero-day exploits to breach a system. Instead, AI-driven scanners efficiently identify mundane, well-understood security gaps that humans frequently overlook:

  • Outdated Dependencies and Plugins: Modern web platforms rely heavily on third-party packages, libraries and Content Management System (CMS) plugins. When a public vulnerability (CVE) is disclosed, automated tools instantly scan millions of sites to locate unpatched versions before administrators can apply updates.
  • Leaked Keys and Credentials: Hardcoded API keys, database credentials and internal tokens left in public code repositories, client-side bundles, or publicly accessible configuration files are scraped and validated within minutes of exposure.
  • Weak Access Controls: Flaws in authorisation logic—such as Broken Object Level Authorisation (BOLA) or unauthenticated admin pathways—allow attackers to bypass interface controls and access restricted data directly.
  • Unprotected Form and API Endpoints: Contact forms, search inputs and API routes that lack rate limiting, input validation, or CAPTCHA protection are vulnerable to credential stuffing, spam injection and automated data scraping.
  • Misconfigured Cloud Storage: Publicly readable S3 buckets, exposed staging servers, or incorrectly configured storage permissions remain prime targets for automated discovery tools searching for sensitive business data or backups.

Why small and mid-sized organisations are still targets

A common misconception among small and mid-sized enterprises (SMEs) is the belief: "We are too small to be targeted by sophisticated hackers."

In the era of AI-driven vulnerability discovery, this logic no longer holds. Automated tools do not evaluate the target’s value or a company’s reputation before scanning; they scan everything systematically.

SMEs are frequently targeted not because of who they are, but because they are reachable and often lack dedicated, round-the-clock security teams. When automated scripts discover an unpatched plugin or open storage bucket, the breach or automated exploit is executed instantly without human hesitation. For smaller businesses, the operational disruption, financial consequences and reputational damage from such automated attacks can be severe. According to the UK Government, 43% of UK businesses reported a breach or attack in the preceding year.

What a sensible defence looks like

To build resilience against relentless, automated vulnerability scanning, organisations must focus on fundamental security hygiene, proactive architecture and continuous risk management:

  • Headless Architecture and Minimised Attack Surface: Consider decoupling your frontend presentation layer from the backend content management system (a headless CMS approach, like Sanity). Decoupling eliminates many traditional CMS plugin vulnerabilities and hides administrative interfaces and database endpoints away from public-facing web servers.
  • Secure Infrastructure and Cloud Hosting Platform: Host web applications on modern cloud infrastructure that provides isolated build and runtime environments, such as Upsun, that include edge-level threat mitigations like automated DDoS protection and Web Application Firewalls.
  • Patch Ownership and Dependency Monitoring: Establish clear internal ownership for software maintenance. Implement automated dependency tracking to identify and apply critical security patches as soon as vendors release them.
  • MFA and Least-Privilege Access: Enforce Multi-Factor Authentication (MFA) across all corporate accounts, CMS administrative portals and server access points. Apply the principle of least privilege to ensure users and applications only hold permissions strictly necessary for their function.
  • Secure Development and Code Review: Incorporate security reviews and static code analysis (SAST) directly into deployment pipelines. Ensure API inputs are validated, sanitised and explicitly authorized on every server-side request.
  • Web Application Firewall (WAF), Rate Limits and Bot Protection: Deploy a WAF to filter malicious traffic, enforce rate limits on sensitive endpoints to prevent brute-force attacks and utilise bot protection measures to block automated discovery agents.

Security as an ongoing service, not a pre-launch checkbox

For years, security was treated as a milestone step at the end of a web project—a final penetration test or sign-off before launch.

In today's threat landscape, launch day is merely day one. Software environments evolve, dependencies age, new vulnerabilities are disclosed daily and AI tools continuously probe live applications. Treating security as a one-time project leaves applications increasingly exposed over time.

Effective digital security must be managed as an ongoing operational service. Continuous monitoring, regular audits, proactive dependency management and iterative hardening are essential to keeping websites and applications resilient in an environment where vulnerability discovery is faster and cheaper than ever before.

Get secure

Dusted's Managed Services offer regular security updates and continuous support to ensure your website remains as hard to break as possible as well as protected as possible against modern, automated threats. Additionally, we offer all our clients headless CMS solutions and secure cloud-based hosting platforms to mitigate even more risk.

Don't wait for automated scanners to discover your vulnerabilities first. Protect your digital assets, safeguard your reputation and build a resilient web presence with our proactive security solutions.

Get in touch with our team today to fortify your website.

FAQs

Digital
Share

Related insights

Software defines mobility. Brand defines the experience.

Challenging the codes of convention: Why tech brands must break the modernist spell.

When the car becomes an ecosystem, brand architecture must move with it.

Share

Inbox insights.Gain competitive edge.

Sign up for insights and curated thought leadership direct to your inbox. Every month.
Submit

Loading preset...