The ai-driven vulnerability surge is already transforming cybersecurity
Source: Wired - AI19/09/2026, 13:00
A surge in cybersecurity vulnerabilities, fueled by AI-powered bug hunting, has already begun reshaping the industry. Experts warn that the rise in discovered flaws, rather than indicating a new threat, reflects improved detection methods.
Microsoft reported issuing patches for 974 CVEs this month, a record high, while Oracle saw a 380% increase in patches compared to July 2025. Google Chrome’s June release included 1,072 patches, surpassing all prior combined releases. Mozilla identified 271 vulnerabilities in Firefox using Anthropic’s Mythos model.
By September 16, 2025, cve.icu logged 33,512 CVEs, nearly half of the current total of 66,401. Jerry Gamblin of Empirical Security argues that more CVEs mean more known vulnerabilities, not necessarily greater risk. However, concerns remain that AI could outpace developers in patching, leading to more cyberattacks.
Matthew Olney of Cisco notes that both attackers and defenders are exploring AI’s role in security. While an AI slowdown might mitigate risks of rogue AI, it cannot halt the existing vulnerability surge, which is already underway.