Opinion: AI-driven vulnerability discovery surges as tools expose thousands of flaws
AI‑enhanced bug hunting is already reshaping cybersecurity, according to researchers. Microsoft reported issuing patches for 974 CVEs in September, a record for a single month. Oracle shipped 1,448 patches in July, up sharply from 309 in July 2025, while Google Chrome’s two major releases in June contained 1,072 patches, more than the total fixes in the previous 23 major releases combined.…
Key points
- Microsoft patched 974 CVEs in September, a new monthly record.
- Oracle released 1,448 patches in July, compared with 309 in July 2025.
- cve.icu logged 66,401 CVEs as of this week, up from 33,512 a year earlier.
Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, says the rise in CVE numbers reflects more known flaws rather than more inherent risk, but warns that remediation cannot keep pace with discovery. Matthew Olney of Cisco notes that both attackers and defenders are still figuring out where to apply AI. The article argues that any AI slowdown aimed at preventing existential threats will not halt the ongoing vulnerability tsunami driven by existing AI tools.
The story so far
2 episodes →- Opinion: AI-driven vulnerability discovery surges as tools expose thousands of flawsthis story
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Society & Work
All →- WIRED hosts World Fair in Miami on November 4 with AI, biotech, and art · 1 src
- Particle6's AI actress Tilly Norwood malfunctions during press tour interviews · 1 src
- Opinion: computer scientist dismisses LLMs as uninteresting · 1 src
- Beginner builds Interview Cheat Sheet tool with ChatGPT and Claude, publishes on Netlify · 1 src
- MIT Reads reimagined for AI era on 10-year anniversary · 1 src
Comments
via GitHub Discussions