AI-Powered Vulnerability Discovery Is Reshaping Cybersecurity
Welcome to the first issue of Kernel Panic! A weekly newsletter from Lily Hay Newman and Matt Burgess about the new world of privacy and digital security. Sign up to receive this newsletter in your inbox every week.
AI doomsayers have recently replaced one worst-case scenario with another. Instead of focusing on a potential software vulnerability apocalypse, many are warning that rogue AI could cause mass human death over the next decade. But while AI leaders consider a collaborative slowdown in frontier model development, one part of the cybersecurity revolution is already here: widely available AI capabilities in mainstream products, including open-weight models, are accelerating vulnerability discovery.
The number of vulnerabilities discovered with AI has surged in recent months. That increase is putting additional pressure on resource-strapped, heavily human-dependent IT and security teams, while also straining volunteers who maintain critical open-source software. Researchers were already discovering and publishing billions of vulnerabilities before the rise of AI bug hunting, but the recent acceleration is clear.
AI-assisted security research drives record vulnerability numbers
Microsoft announced last week that it had patched 974 CVEs so far this month, setting a new record. CVE, or common vulnerabilities and exposures, is a cybersecurity term for a confirmed software flaw.
In July, Oracle shipped 1,448 patches, compared with 309 in July 2025. The two major Google Chrome releases in June included 1,072 patches—more than all the vulnerability fixes shipped in the previous 23 major releases combined.
In April, Mozilla announced that it had discovered 271 vulnerabilities in Firefox during a single bug-hunting sprint using Anthropic’s Mythos model.
Reported CVEs have nearly doubled in a year
As of Wednesday this week, 66,401 CVEs had been recorded overall, according to Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project. The figures are tracked by cve.icu.
By September 16 of last year, cve.icu had recorded 33,512 CVEs—nearly half of the current total. In all of 2022, the year OpenAI released the first version of ChatGPT, the project recorded 25,000 CVEs.
More vulnerability discoveries do not automatically mean more risk
Security and AI researchers remain divided over whether the proliferation of AI-related vulnerabilities will be catastrophic or whether it will amplify existing cybersecurity challenges. Some point out that slow patch deployment and inadequate investment in cybersecurity already gave attackers significant advantages and contributed to major hacking disasters before the rise of AI.
However, as vulnerability discoveries continue to increase and the debate becomes less theoretical, the relationship between AI and cybersecurity appears to be moving closer to a critical point.
“I don’t think it’s an exaggeration,” Gamblin says of the apparent explosion in vulnerability discoveries across the industry. He cautions against assuming that high numbers alone are harmful: “More CVEs do not make you more vulnerable; in fact, it just makes you more aware of known vulnerabilities and how the system operates.”
The patching gap could become the next cybersecurity crisis
The concern is that a massive increase in vulnerability discoveries could overwhelm developers with patching work, leaving software users unable to update quickly enough. At the same time, cyberattacks could escalate as more attackers use AI to discover vulnerabilities independently.
As the UK’s National Cyber Security Centre put it: “Finding vulnerabilities alone does not improve security.”
Source: www.wired.com


