And can right now’s surge in AI-driven vulnerability discovery finally make tomorrow’s software program safer?
13 Aug 2026
•
,
3 min. learn

The accelerated discovery of beforehand unknown software program vulnerabilities has been making headlines for months. It’s a difficulty that has even led the US authorities to create a vulnerability clearing home named Gold Eagle to coordinate analysis efforts in vulnerability discovery, mitigation and fixes.
A sign of the broader stress dealing with cyber-defenders might be drawn from the sheer variety of patches being delivered in Microsoft’s Patch Tuesday by the final 4 months: 169 CVEs in April, 118 CVEs in Might, 571 CVEs total in June (together with 208 direct Microsoft CVEs) and one other 622 vulnerabilities in July that included zero-days below lively exploitation.
A keynote at Black Hat USA 2026 detailed analysis by affiliate professor Yan Shoshitaishvili and his undergraduate college students at Arizona State College on the increasing use of AI fashions for vulnerability discovery. Mr. Shoshitaishvili referred to a Washington Submit article from June that acknowledged that Anthropic’s next-generation mannequin Claude Mythos had found 479 vulnerabilities within the Linux kernel, which the college group used as a benchmark. Utilizing earlier generations of GPT fashions, in the meantime, the group had found ‘simply’ round 300 flaws.
The distinction was attributed to the usage of workflows in Mythos, so the group set about integrating comparable workflows into three GPTs, which resulted within the discovery of round 600 vulnerabilities. The group then educated the GPTs utilizing the properties of beforehand recognized vulnerabilities and found roughly 1,000 vulnerabilities. They hit the barrier of discovering vulnerabilities at such pace that they may not hold tempo reporting them; for readability, reporting means detailed analysis and proposed fixes, relatively than simply the problem itself. The size calls into query the entire technique of accountable disclosure, which within the group’s view was already damaged as disclosure usually creates elevated danger.
Patching software program in a well timed vogue in manufacturing environments was already a stress level for a lot of cybersecurity groups. Exponential progress like this may very well be the breaking level that causes both extra unpatched software program and larger alternatives for cybercriminals or patching with out testing, which, in flip, may trigger compatibility points in lots of environments.
If I take a logical view of this situation and undertake an optimistic mindset, then it may very well be that we’re heading in the direction of a peak in discovery – and that someplace over this peak is a meadow of peace and calm with an improved normality. People researching vulnerabilities has historically been a resource-intensive course of, producing a gentle stream of discoveries which were rising yr on yr. That is doubtlessly as a result of there being extra researchers, extra software program and extra motivation to find the vulnerabilities for monetary achieve by bug bounty applications and such like. Change from people to AI, and it’s like a quantum method to discovery, however notice that AI continues to be in a studying section: as detailed by the Arizona group, tweaking the mannequin and its workflow doubtlessly uncovers extra vulnerabilities.
Then there’s additionally legacy software program. Take into account the big quantity of software program written over the previous 30 years – no quantity of human effort may probably uncover all of the vulnerabilities within the present and again catalogues of software program. The size of AI-assisted discovery, nevertheless, may doubtlessly attain the top of {the catalogue} at some stage, after which new discoveries would solely be by enhancements to the mannequin getting used to unearth the vulnerabilities.
Let’s not overlook that new software program is being developed on a regular basis, after all. Right here, too, after all, logic ought to counsel that any improvement group right now would use the identical obtainable AI capabilities to take away any potential vulnerabilities previous to releasing their software program. And because the fashions enhance, the prospect of just about flaw-free software program may change into a actuality.
If this logic prevails, we could attain the calm and peaceable meadow with only a few new vulnerabilities being discovered. This view may, after all, be only a dream, or my misplaced optimism.


