AI & TechArtificial IntelligenceBigTech CompaniesCybersecurityNewswire

AI Slowdown Myth: Cyber Vulnerability Crisis Is Here

▼ Summary

– A surge in AI-driven vulnerability discovery has led to record-breaking numbers of software patches issued by major tech companies like Microsoft, Oracle, and Google.
– The total number of recorded CVEs has nearly doubled in less than a year, reaching over 66,000, highlighting the accelerating pace of security flaw identification.
– Experts are divided on whether this spike represents a catastrophic threat or simply a more effective detection system revealing previously unknown flaws.
– Researchers utilized AI tools such as Anthropic’s Mythos model to find hundreds of vulnerabilities during specific bug hunting sprints, demonstrating AI’s current utility in cybersecurity.
– Despite fears of rogue AI causing mass harm, the immediate impact is a strain on IT teams managing the influx of disclosed vulnerabilities rather than an existential AI risk.

The Reality Behind the AI Vulnerability Surge

The narrative surrounding artificial intelligence has shifted dramatically, with critics moving from fears of immediate software collapse to dystopian scenarios involving rogue models and mass casualties. While industry leaders debate the need for a cooperative pause in frontier model development, a different crisis is already unfolding in the realm of digital security. Thanks to widely accessible tools, including open weight models, mainstream AI products are actively driving a massive increase in discovered software flaws. This surge is placing immense strain on under-resourced IT departments and the volunteers who maintain critical open-source infrastructure.

While researchers had identified significant vulnerabilities before AI-assisted bug hunting became prevalent, the recent acceleration is undeniable. Major technology firms are reporting unprecedented numbers of patches required to address confirmed software flaws, known as Common Vulnerabilities and Exposures (CVEs). Microsoft issued patches for 974 CVEs in a single month, setting a new record. Oracle shipped 1,448 patches in July, a stark contrast to the 309 released in July 2025. Google Chrome’s June updates alone contained 1,072 patches, exceeding the total fixes from the previous 23 major releases combined. Additionally, Mozilla reported discovering 271 vulnerabilities in Firefox during one bug-hunting sprint using Anthropic’s Mythos model.

The scale of this phenomenon is quantifiable across the entire industry. According to Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, which operates the cve.icu analysis project, there have been 66,401 CVEs recorded as of this week. To put this in perspective, cve.icu logged only 33,512 CVEs by September 16 last year,less than half the current volume. For comparison, the entire year of 2022, when ChatGPT was first launched, saw just 25,000 CVEs recorded.

Interpreting the Data: Risk vs. Visibility

Experts remain divided on whether this spike represents a catastrophic shift or merely an amplification of existing cybersecurity challenges. Some analysts argue that attackers already held significant advantages due to slow patch adoption and insufficient investment in security measures long before AI entered the equation. However, as vulnerability discovery numbers continue to climb, the theoretical debate is giving way to practical concerns about the gap between finding flaws and fixing them.

Gamblin offers a nuanced perspective on these rising figures. “I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It’s more known vulnerability, which is mostly the system working.”

This distinction is crucial. The primary fear is not the existence of flaws, but the inability of developers and users to keep pace with their disclosure. If AI enables attackers to discover novel vulnerabilities faster than they can be patched, the resulting cyberattacks could escalate significantly. The challenge lies in translation of knowledge into action. As Britain’s National Cyber Security Center emphasizes, “Just finding vulnerabilities does nothing to improve your security.”

(Source: Wired)

Topics

ai cybersecurity impact 95% vulnerability statistics 90% industry response 85% expert debate 80% newsletter introduction 75%
Show More