All corrections
1
Claim
The lag time between "patch shipped" and "patch reverse engineered and weaponized by a criminal organization" was already so long that most people didn't notice new bugs when they came out.
Correction

Patch-to-exploit delays were often short, not generally "so long." Google/Mandiant reported that in 2023, 12% of n-day flaws were exploited within one day, 29% within one week, and over half within one month of patch availability.

Full reasoning

Official threat-intelligence reporting contradicts the idea that the gap between a patch shipping and criminal weaponization was generally very long.

Google/Mandiant's 2024 analysis of vulnerabilities exploited in 2023 says n-day exploitation was most likely to occur within the first month of a patch being available: 12% of n-days were exploited within one day, 29% within one week, and 56% within one month. The same report says the average time-to-exploit in 2023 was five days.

Google/Mandiant had also previously reported that for non-zero-day vulnerabilities there was often only "hours or a few days" between patch release and the first observed attacker exploitation.

Some vulnerabilities do take longer to weaponize, but this sentence states the lag was already broadly so long that people mostly did not notice new bugs when they came out. The available threat-intelligence data shows the opposite trend: many patched vulnerabilities were exploited very quickly after disclosure or patch release.

2 sources
2
Claim
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
Correction

Historical botnets did considerably more than DDoS, spam, or simple credential scraping. DOJ records show botnets were already being used to steal banking credentials, execute fraudulent transfers, and distribute ransomware.

Full reasoning

This sentence materially understates what botnet operators were already doing before current AI systems.

Older Justice Department releases describe botnets being used for bank-account takeover and wire fraud, not just DDoS or spam. For example, DOJ said the Bugat/Dridex botnet was used to steal banking credentials and then initiate fraudulent electronic funds transfers of millions of dollars from victims' accounts. DOJ also said Coreflood was used to monitor users' banking sessions and cause fraudulent transfers of funds.

And botnets were also used to spread ransomware well before the current AI wave. DOJ's 2017 Kelihos takedown said the botnet was used for harvesting login credentials, sending spam, and installing ransomware and other malicious software.

So the claim that the "worst thing" botnet operators used to do was DDoS/spam/crypto-or-card scraping is contradicted by official records showing large-scale bank fraud and ransomware distribution.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0