TechnologyForget the AI Slowdown—the Vulnerability Explosion Is Already Happening

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening


Welcome to the inaugural edition of Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.

AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade. As AI leaders consider a cooperative slowdown on frontier model development, though, one aspect of the cybersecurity sea change has already arrived thanks to existing, broadly available capabilities in mainstream AI products, including open weight models.

A tidal wave of vulnerabilities uncovered using AI has only accelerated in recent months—piling more pressure on under-resourced, and very human, IT and security teams and straining volunteers who maintain crucial open source software. Researchers found and disclosed a vast array of vulnerabilities before the rise of AI-enhanced bug hunting as well, but the recent surge is clear.

Microsoft said last week that it has issued patches for 974 CVEs so far this month, setting a new record. (CVEs, or common vulnerabilities and exposures, is cybersecurity jargon for confirmed software flaws.) In July, Oracle shipped 1,448 patches compared to 309 in July 2025. Google Chrome’s two major version releases in June included 1,072 patches, more than all of the vulnerability fixes shipped in the prior 23 big releases combined. And Mozilla said in April that it found 271 vulnerabilities in Firefox during one bug hunting sprint using Anthropic’s Mythos model.

Across the board, there have been a stunning 66,401 CVEs recorded as of Wednesday this week, according to Jerry Gamblin, the head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project cve.icu. By September 16 last year, cve.icu had logged a total of 33,512 CVEs—almost half the current total. For all of 2022, the year OpenAI launched its first version of ChatGPT, cve.icu recorded 25,000 CVEs.

Among both security and AI researchers, experts have been divided about whether this spike and other impacts of AI on cybersecurity will be catastrophic or instead magnify existing dynamics and challenges. Some have pointed out that slow patch adoption and lagging investment in cybersecurity broadly already gave attackers many advantages that led to hacking disasters before the rise of AI. But as vulnerability discovery numbers have continued to rise, and the discussion has become less theoretical, the two sides have seemed to move a bit closer.

“I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It’s more known vulnerability, which is mostly the system working.”

The fear, though, is that vast vulnerability discovery will mean developers getting outpaced on patching, software users who can’t patch fast enough, and an array of escalating cyberattacks fueled by more attackers discovering novel vulnerabilities on their own using AI. As Britain’s National Cyber Security Center puts it, “Just finding vulnerabilities does nothing to improve your security.”



Original Source Link

Latest News

EU, Philippines Reach Breakthrough in Free-Trade Talks

The agreement comes as persistent geopolitical shocks and tariffs underscore the need to look for new trade partners. Original...

Onchain Metric Fires New Altseason Signal Amid Flat Bitcoin Dominance

Bitcoin’s (BTC) rise to $86,000 this week has dragged altcoin markets higher as the industry’s market cap reclaimed...

Mamdani Humiliates Trump To His Face On Reporter Ban

Donald Trump and New York City Mayor Zohran Mamdani held a surprise meeting at Gracie Mansion in New...

Channing Tatum Addresses Rumor He’s Behind Alt Instagram Account That S**t Talks Zoe Kravitz & Harry Styles

Channing Tatum has seen all the speculation! Over the weekend, rumors ran wild about a certain finsta (Fake Instagram...

Array Behavioral Care Unveils New Triage Model

Array Behavioral Care launched a new service to help providers assess patients with urgent behavioral health needs and...

First radio waves seen from an exoplanet hint at otherworldly auroras

Senior physics writer Emily Conover has a Ph.D. in physics from the University of Chicago. She is a...

Must Read

‘Of course I am worried’: Live Science readers react to US weapons in space

The idea of weapons in space, once a...

Saudi Arabia Withdraws from mBridge CBDC Project

Saudi Arabia has withdrawn from mBridge, a China-backed...
- Advertisement -

You might also likeRELATED
Recommended to you