AI has accelerated the discovery of software vulnerabilities, creating a surge in confirmed security flaws. Microsoft reported issuing patches for 974 CVEs this month, a new record for the company.
The rise in vulnerabilities is attributed to the use of AI tools like Anthropic’s Mythos model, which has helped researchers uncover 271 flaws in Firefox during a single bug hunting sprint. This trend has led to a dramatic increase in the number of reported vulnerabilities across the industry.
According to Jerry Gamblin, head of research at Empirical Security, the number of CVEs recorded as of Wednesday this week is 66,401, compared to 33,512 as of September 16 last year. The spike in vulnerabilities has raised concerns about the ability of developers and users to keep up with patching.
"I don’t think it’s overblown," Gamblin said. "What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability.
It's more known vulnerability, which is mostly the system working."
The surge in vulnerability discovery has sparked debate among cybersecurity experts about whether it signals a catastrophe or simply magnifies existing challenges. Some argue that slow patch adoption and underinvestment in cybersecurity have already given attackers an advantage.
The situation remains complex, with a balance between AI aiding both attackers and defenders. As the industry evolves, an AI slowdown could help prevent mass human harm but cannot stop the vulnerability tsunami already in motion.
Source: wired