Forget the AI Slowdown—Vulnerabilities Are Rapidly Increasing

Welcome to the first edition of Kernel Panic! A weekly newsletter crafted by Lily Hay Newman and Matt Burgess, exploring the evolving landscape of privacy and digital security. To have this newsletter delivered to your inbox every week, sign up here.
Recently, AI pessimists have shifted from one dire prediction to another, moving from worries over a software vulnerability apocalypse to concerns about rogue AI potentially leading to mass casualties in the coming decade. However, as leaders in AI contemplate a collaborative slowdown in the development of advanced models, one particular change in cybersecurity has already begun, driven by the availability of mainstream AI tools, including open weight models.
The number of vulnerabilities identified through AI tools has seen a significant increase lately, putting additional strain on underfunded IT and security teams, while also burdening volunteers who maintain essential open-source software. Even before the emergence of AI-driven bug hunting, researchers were actively discovering and disclosing numerous vulnerabilities, yet the recent uptick is undeniable.
Last week, Microsoft announced it had released patches for 974 CVEs this month alone, setting a new record. (CVEs, or common vulnerabilities and exposures, refer to confirmed software flaws in cybersecurity terms.) In July, Oracle delivered 1,448 patches compared to just 309 in July 2025. Google Chrome’s two major releases in June included 1,072 patches, surpassing the total of all vulnerability fixes from the previous 23 significant releases combined. Moreover, Mozilla reported in April that it uncovered 271 vulnerabilities in Firefox during a bug hunting initiative utilizing Anthropic’s Mythos model.
Overall, a remarkable 66,401 CVEs have been recorded as of this Wednesday, as stated by Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, which administers the CVE analysis project cve.icu. By September 16 last year, cve.icu had documented 33,512 CVEs—nearly half of the current tally. In all of 2022, the same year OpenAI launched its first ChatGPT version, cve.icu recorded 25,000 CVEs.
Among security and AI researchers, opinions are divided on whether this surge and the broader implications of AI in cybersecurity will be disastrous or merely amplify existing issues and challenges. Some argue that slow patch adoption and inadequate cybersecurity investment have long given attackers significant advantages leading to prior hacking debacles well before AI’s emergence. However, as vulnerability discovery rates climb and discussions become more concrete, viewpoints have started to converge.
“I don’t think it’s exaggerated,” Gamblin remarks concerning the noticeable increase in vulnerability findings across the sector. “What I would contest is the notion that a larger number signifies harm. More CVEs do not equate to greater vulnerability. It’s simply more known vulnerabilities, which largely indicates that the system is functioning correctly.”
The concern, however, is that extensive vulnerability discovery may lead developers to fall behind on patching, software users unable to update swiftly enough, and a range of escalating cyberattacks driven by attackers leveraging AI for the discovery of new vulnerabilities. As highlighted by Britain’s National Cyber Security Center, “Simply identifying vulnerabilities does nothing to enhance your security.”
