Artificial intelligence tools are accelerating software vulnerability discovery, leading to a record spike in tracked flaws and pressuring security teams, according to data from security researchers and tech firms. Empirical Security’s cve.icu logged 66,401 Common Vulnerabilities and Exposures (CVEs) as of mid-September, nearly doubling the total logged by the same time last year and far exceeding the 25,000 recorded in all of 2022.

Major enterprise software vendors are issuing security fixes at an unprecedented rate. Microsoft released patches for 974 CVEs in a single month, set against Oracle’s 1,448 patches in July. Similarly, Mozilla uncovered 271 Firefox vulnerabilities during a single bug-hunting sprint using Anthropic’s Mythos model. The surge highlights how broadly available capabilities in mainstream AI products, including open-weight models, are being weaponized or utilized for automated vulnerability discovery.

Industry experts remain divided on the long-term impact. While an increase in CVEs represents known vulnerabilities rather than newly created flaws, security researchers warn that automated discovery risks outpacing human-led patching capabilities. Without proportional automated remediation tools, security organizations face growing operational strain as attackers leverage similar AI capabilities to uncover zero-day flaws.

Why it matters

  • Security teams must adopt AI-driven patching and remediation tools to keep pace with automated vulnerability discovery.

  • Open-source maintainers face mounting pressure, increasing supply chain risks for enterprises relying on unpatched dependencies.

  • Model developers should anticipate heightened regulatory scrutiny around open-weight models capable of automated exploit discovery.

Source: wired.com