Particle.news

AI Tools Drive Record Surge in Reported Software Flaws

Shorter windows between public disclosure and exploitation are forcing vendors to speed testing and rollouts.

Overview

  • A VulnCheck report found 1,061 vulnerabilities attributed to AI-assisted discovery in the first half of 2026, with 14 confirmed exploited in the wild, a 1.3% rate that matches the overall exploitation rate for the period.
  • The National Vulnerability Database logged about 45,207 vulnerabilities between January and late July 2026, putting the year on pace to roughly double 2025’s total and driving record monthly patch volumes.
  • Average time from CVE publication to exploitation fell from roughly 120 days in 2025 to about 80 days in H1 2026, a shift that shortens defenders’ response windows.
  • Major firms rolled out cyber‑AI scanners in April and May 2026—including Anthropic’s Glasswing/Mythos, Microsoft’s MDASH, OpenAI’s Daybreak, and Google offerings—and those tools are now used by companies and some government agencies for defensive and offensive work.
  • Security teams and vendors are urging faster patch tooling, rigorous testing and rollback plans, and capacity increases for patch management because the higher finding cadence and faster exploitation are straining operational processes and increasing dual‑use risk.