SyncAI.news, a Varaisys broadcasting
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
MB

Matt Burgess, Lily Hay Newman

· 1 min read

BusinessWIRED: AI

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

Welcome to the inaugural edition of Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.

AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade. As AI leaders consider a cooperative slowdown on frontier model development, though, one aspect of the cybersecurity sea change has already arrived thanks to existing, broadly available capabilities in mainstream AI products, including open weight models.

A tidal wave of vulnerabilities uncovered using AI has only accelerated in recent months—piling more pressure on under-resourced, and very human, IT and security teams and straining volunteers who maintain crucial open source software. Researchers found and disclosed a vast array of vulnerabilities before the rise of AI-enhanced bug hunting as well, but the recent surge is clear.

Microsoft said last week that it has issued patches for 974 CVEs so far this month, setting a new record. (CVEs, or common vulnerabilities and exposures, is cybersecurity jargon for confirmed software flaws.) In July, Oracle shipped 1,448 patches compared to 309 in July 2025. Google Chrome’s two major version releases in June included 1,072 patches, more than all of the vulnerability fixes shipped in the prior 23 big releases combined. And Mozilla said in April that it found 271 vulnerabilities in Firefox during one bug hunting sprint using Anthropic’s Mythos model.

“I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.”

Original source

This story was published by WIRED: AI and written by Matt Burgess, Lily Hay Newman. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on wired.com

Similar News