conv.

All stories
SecurityQuiet 2d · day 5

AI-assisted bug hunting drives record surge in software vulnerabilities

Wired's new Kernel Panic newsletter documents a sharp rise in disclosed CVEs as AI tools accelerate vulnerability discovery across major software vendors.

What to know

  • Disclosed CVEs in 2026 have nearly doubled the pace of 2025, reaching 66,401 by mid-September versus 33,512 a year earlier.
  • Major vendors — Microsoft, Oracle, Google Chrome, Mozilla — all report record or sharply elevated patch volumes tied to AI-assisted bug hunting.
  • Researchers are split on whether the surge signals a genuine security crisis (patch teams outpaced, attackers using AI to find novel flaws) or mainly reflects healthy, more thorough vulnerability disclosure.
  • The trend is presented as a near-term, already-occurring AI risk, distinct from the more speculative long-term 'rogue AI' scenarios prompting talk of a development slowdown among AI labs.

Jerry Gamblin Head of research, Empirical Security; founder of RogoLabs (cve.icu)Lily Hay Newman Wired security reporter, co-author of Kernel Panic newsletterMatt Burgess Wired security reporter, co-author of Kernel Panic newsletterMicrosoft Software vendorOracle Software vendorMozilla Software vendor (Firefox)

AI-assisted bug hunting drives record surge in software vulnerabilities
wired.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 2 pieces in two hours at Sep 21, 4 AM; 4 pieces over 5 days (1 article · 3 posts) Sep 19, 6 AM — 1 piece · 1 article — Google News 1Sep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — quietSep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — quietSep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — 2 pieces · 2 posts — Mastodon 2Sep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — 1 piece · 1 post — Mastodon 1Sep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — quietToday, 12 AM — quiet 12
Sep 20Sep 21Sep 22yesterdaynow · 2:56 AM ET
  1. 2

    Story circulates widely via social reposts

    The Kernel Panic article was reshared across Mastodon/Flipboard accounts including Top Stories in Tech, Tech Longreads, and PrivacyDigest, spreading the vulnerability-explosion framing further.

    “I don't think it's overblown…”
    — Jerry Gamblin, Head of research, Empirical Security · source
  2. 1 day quiet
  3. 1

    Wired launches Kernel Panic newsletter framing the vulnerability surge

    Wired's Lily Hay Newman and Matt Burgess published the inaugural edition of their security newsletter arguing that an AI-driven vulnerability explosion is already underway, even as AI leaders discuss slowing frontier model development over separate, longer-term risks.

    “AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade.”
    — Wired (Kernel Panic newsletter)
    1. first by wired.com, 4d ago

  4. background

    Total CVEs recorded in 2026 reach 66,401, nearly double 2025's pace — Jerry Gamblin of Empirical Security/RogoLabs, who runs the CVE tracking project cve.icu, reported 66,401 CVEs recorded so far this year, versus 33,512 by the same date in 2025 and 25,000 for all of 2022.

  5. background

    Microsoft sets monthly record with patches for 974 CVEs — Microsoft said it issued patches for 974 CVEs in the month, described as a new record for the company.

  6. background

    Oracle's July patch count jumps nearly fivefold year over year — Oracle shipped 1,448 patches in July 2026, compared with 309 in July 2025.

  7. background

    Chrome releases include more patches than prior 23 combined — Google Chrome's two major version releases in June included 1,072 patches, exceeding the total from the previous 23 major releases combined.

  8. background

    Mozilla finds 271 Firefox bugs using Anthropic's Mythos model — Mozilla disclosed that it found 271 vulnerabilities in Firefox during a single bug-hunting sprint using Anthropic's Mythos model.