LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
vulnerability

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.

zeroday.news ·

The cybersecurity landscape is experiencing a significant surge in reported software vulnerabilities, a phenomenon that experts attribute to the increasing use of artificial intelligence in bug discovery. This "vulnerability explosion" is already underway, driven by broadly available AI tools, even as discussions continue about a potential slowdown in AI development.

Recent data highlights this trend. Microsoft confirmed last week that it released patches for 974 Common Vulnerabilities and Exposures (CVEs) in the current month, setting a new record for the company. Oracle's July patch release included 1,448 fixes, a substantial increase compared to 309 in July 2025. Google Chrome's two major version releases in June collectively contained 1,072 patches, surpassing the total number of vulnerability fixes in the preceding 23 major releases combined. Mozilla also reported in April that a single bug-hunting sprint using Anthropic’s Mythos AI model identified 271 vulnerabilities in Firefox.

Overall, the number of recorded CVEs has seen a dramatic increase. As of Wednesday this week, 66,401 CVEs have been logged. This figure is nearly double the 33,512 CVEs recorded by September 16 of the previous year. For the entirety of 2022, the year OpenAI launched its initial version of ChatGPT, approximately 25,000 CVEs were recorded.

While some experts initially debated whether AI's impact on cybersecurity would be catastrophic or merely amplify existing challenges, the escalating numbers suggest a growing consensus on the significance of this trend. The head of research at Empirical Security and founder of RogoLabs, which operates the CVE analysis project cve.icu, stated that the apparent explosion in vulnerability findings is not overblown. He emphasized that an increased number of CVEs indicates more known vulnerabilities, which can be seen as the system working to identify flaws.

However, concerns persist that the rapid pace of vulnerability discovery could outstrip the ability of developers to issue patches and software users to implement them promptly. This imbalance could potentially lead to an increase in cyberattacks, as more attackers leverage AI to discover novel vulnerabilities. The British National Cyber Security Center has noted that simply finding vulnerabilities does not inherently improve security.

For the time being, many researchers observe a delicate balance between AI accelerating bug discovery and AI aiding defensive measures. Threat intelligence directors note that both malicious actors and the cybersecurity industry are actively exploring how to best utilize AI.

Despite any potential future AI slowdowns, whether through regulation or industry agreements, the current wave of vulnerability discoveries driven by existing AI tools is already here. The challenge lies in the disparity between the scalability of discovery, which can be enhanced with computational power, and the scalability of remediation, which relies on human resources that cannot be easily expanded.

vulnerabilityaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]