LIVE · cybersecurity feed
Live wire
aihigh

Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

Researchers at Arizona State University have demonstrated the significant impact of AI on vulnerability discovery, using advanced models like Anthropic's Claude Mythos to find hundreds of flaws in the Linux kernel. The team found that AI models, especially when enhanced with workflows and trained on past vulnerabilities, can discover vulnerabilities at a rate that outpaces human reporting capabilities. This rapid discovery raises concerns about responsible disclosure and the ability of organizations to patch systems effectively, potentially leading to increased cybercrime or system instability.

zeroday.news ·

The cybersecurity community is grappling with an unprecedented surge in software vulnerability discoveries, largely driven by advancements in artificial intelligence. This rapid increase has prompted the U.S. government to establish Gold Eagle, a new clearinghouse designed to coordinate research, mitigation, and fixes for vulnerabilities. The scale of the problem is evident in recent Microsoft Patch Tuesday releases, which included 169 CVEs in April, 118 in May, a total of 571 in June (with 208 directly from Microsoft), and 622 in July, some of which were zero-days under active exploitation.

A keynote presentation at Black Hat USA 2026 highlighted research by Associate Professor Yan Shoshitaishvili and his undergraduate students at Arizona State University, focusing on the expanding role of AI models in vulnerability discovery. The team used a June Washington Post article as a benchmark, which reported that Anthropic's Claude Mythos model had identified 479 vulnerabilities in the Linux kernel.

The Arizona State team's own research demonstrated the significant impact of AI. While earlier GPT models yielded around 300 flaws, integrating workflows similar to those used by Mythos into three GPTs boosted their discovery count to approximately 600 vulnerabilities. Further training these GPTs with properties of known vulnerabilities led to the identification of roughly 1,000 flaws.

This accelerated rate of discovery has created a bottleneck in the responsible disclosure process, which the research team believes is already strained. Reporting a vulnerability involves detailed research and proposing fixes, a process that cannot keep pace with AI-driven discovery. The sheer volume of new vulnerabilities threatens to overwhelm cybersecurity teams, potentially leading to more unpatched software, increased opportunities for cybercriminals, or patches deployed without adequate testing, which could introduce compatibility issues.

The shift from human-centric vulnerability research, which has traditionally been resource-intensive and produced a steady, albeit increasing, stream of discoveries, to AI-driven methods is akin to a quantum leap. AI models are still in a learning phase, and as the Arizona team demonstrated, refining models and workflows can uncover even more vulnerabilities.

This new paradigm also raises questions about legacy software. The vast amount of code written over the past three decades contains an unknown number of vulnerabilities that human effort alone could never fully uncover. AI-assisted discovery, however, could potentially exhaust this "back catalog" of flaws, leading to a future where new discoveries are primarily driven by improvements in the AI models themselves.

Looking forward, there is an optimistic view that this surge in discovery could eventually lead to a peak, followed by a period of greater stability. As AI models improve, they could also be integrated into the software development lifecycle to proactively identify and eliminate vulnerabilities before products are released. This could theoretically lead to the creation of virtually flaw-free software, significantly reducing the number of new vulnerabilities found. However, this remains a speculative outcome, and the immediate challenge is managing the current explosion of discoveries.

aivulnerability discoverycybersecurityresponsible disclosurepatching
ShareXLinkedInWhatsAppFacebook

More News

view all →
aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

cloud

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi