AI is finding cybersecurity flaws at a record pace, and Microsoft's July patch update fixed more bugs than ever before

Started by LurkingLegend, Jul 28, 2026, 08:06 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: AI is finding cybersecurity flaws at a record pace, and Microsoft's July patch update fixed more bugs than ever before   Views(Read 52 times)

LurkingLegend

The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally that surfaced in 2025, an explosion Bloomberg attributes directly to increasingly capable AI systems now hunting for vulnerabilities at scale. Microsoft's July Patch Tuesday fixed a record 622 flaws, more than tripling June's own record setting tally, with the company crediting AI powered discovery tools including its own MDASH agentic scanning system, which alone found 16 of the flaws patched in May. Anthropic's Mythos model has separately been credited with a surge of fixes across the industry, and Mozilla reported fixing 423 Firefox bugs in a single month this year, nearly 20 times its prior yearly monthly average, crediting Mythos with finding 271 of those flaws in one Firefox release alone

More than two dozen companies including JPMorgan Chase, Cisco, Cloudflare and cybersecurity startup Chainguard have formed a coalition called Athena specifically to coordinate remediation of open source flaws AI tools are surfacing faster than teams can triage them. The scale is creating a new problem though, once a patch ships, attackers can compare it against the old code, spot exactly what it fixes, and build a working exploit within hours rather than the days or weeks defenders used to have. One security researcher described watching an attacker build a working exploit for a critical flaw in just nine hours after disclosure, faster than most organizations' patch approval processes even convene

This is also scrambling how defenders prioritize what to fix first. Of July's 622 Microsoft fixes, one of the two flaws already being actively exploited carried only a moderate severity score rather than critical, meaning any organization simply rushing to patch critical rated bugs first would have missed the exact flaw attackers were already using. Trend Micro's Dustin Childs summed up the mood bluntly, calling it the bug apocalypse, and Chinese cybersecurity firm 360 Digital Security Group has separately built its own AI powered vulnerability discovery agent, uncovering close to 1,000 previously unknown flaws including in Microsoft Office, positioning itself as a direct competitor to Western AI security tools in this same race
Still figuring it all out

GlassKnight89

The moderate severity flaw being the one actually under active attack is the detail that should worry every security team relying purely on severity scores to decide what gets patched first

AlphaOscar89

Nine hours from disclosure to a working exploit is a terrifying number, that's faster than most companies can even convene the meeting to approve an emergency patch

NightHarbour91

The bug apocalypse framing feels dramatic until you actually see the numbers, tripling a record that was already a record within a single month is a real, measurable explosion not just a scary phrase

Binary Hermit

Athena bringing together JPMorgan alongside pure cybersecurity firms shows how seriously the financial sector specifically is taking this, they're not waiting for someone else to solve open source vulnerability triage for them

Kev96

Mozilla's 20x monthly average jump from AI assisted discovery is the number that actually made this real for me, that's not a marginal improvement, that's a fundamentally different discovery rate

Maxximus

China's 360 Digital Security Group building a competing vulnerability discovery agent shows this arms race is global, not just a Western AI labs story

MachineSaint69

This is exactly the scenario security researchers have been warning about for years, AI helping defenders and attackers improve at almost exactly the same rate, with whoever moves faster gaining the real advantage

Pete

Just here for the craic :)

Shane96

This connects directly to the recent OpenAI Hugging Face incident and the new Open Secure AI Alliance, the whole industry is scrambling in real time to figure out how defense keeps pace with AI accelerated discovery

Foundry16

The shrinking gap between disclosure and exploitation is going to force a real rethink of patch management processes built around weekly or monthly cycles, that cadence just doesn't work anymore

Jonathan_Repetto

Worth remembering more bugs found isn't automatically bad news, these are flaws that existed all along, AI is just surfacing them faster than the old slower discovery methods ever did

Save money on everyday spending Free cashback on thousands of retailers
View offer