Urgent.News

What's breaking now, across thousands of outlets.

AI

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI proponents have recently shifted focus from the potential software vulnerability apocalypse to the possibility of rogue AI causing mass human death within the next decade. Despite AI leaders considering a cooperative slowdown on frontier model development, the cybersecurity implications of AI have already taken shape due to accessible AI capabilities in mainstream products.

A deluge of vulnerabilities uncovered using AI has surged in recent months, placing additional strain on IT and security teams, as well as volunteers maintaining crucial open-source software. While AI-enhanced bug hunting was not entirely new, the recent surge is undeniable.

Microsoft disclosed 974 CVEs this month, setting a new record, while Oracle shipped 1,448 patches in July compared to 309 in July 2025. Google Chrome's recent version releases included 1,072 patches, more than all of the vulnerability fixes shipped in the prior 23 releases combined. Mozilla reported 271 vulnerabilities in Firefox during a bug hunting sprint using Anthropic’s Mythos model.

As of Wednesday, 66,401 CVEs had been recorded, nearly double the 33,512 logged just a year prior and more than the 25,000 logged during 2022 when OpenAI launched its first version of ChatGPT. Experts remain divided on whether this escalation and other AI impacts on cybersecurity will be catastrophic or merely magnify existing challenges.

Some argue that patch adoption and cybersecurity investment lag have long given attackers an advantage, but as vulnerability discovery numbers rise, the focus has shifted from fear to pragmatism.

Security researchers emphasize that more CVEs do not equate to more vulnerability; rather, they represent more known vulnerabilities, benefiting the system's security. However, the concern remains that the rapid discovery of vulnerabilities may outpace developers' patching efforts, leaving software users unable to patch quickly enough and creating a myriad of escalating cyberattacks as more attackers uncover novel vulnerabilities using AI.

While it is acknowledged that AI aids both attackers and defenders, a delicate balance exists between the acceleration of bug discovery and the aid it provides to security professionals. Ultimately, the vulnerability tsunami has already arrived as a result of existing AI tools, and although an AI slowdown could potentially prevent a mass human extermination event, it cannot halt the ongoing vulnerability surge.

Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at wired.com →

More in AI

More from Saturday 19 September →