{"id":17738,"date":"2026-08-14T17:06:11","date_gmt":"2026-08-14T17:06:11","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17738"},"modified":"2026-08-14T17:06:11","modified_gmt":"2026-08-14T17:06:11","slug":"will-vulnerability-discovery-decline-within-the-ai-period","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17738","title":{"rendered":"Will vulnerability discovery decline within the AI period?"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">And can right now\u2019s surge in AI-driven vulnerability discovery finally make tomorrow\u2019s software program safer?<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/tony-anscombe\/\" title=\"Tony Anscombe\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2017\/05\/MFE_5108-BW.png\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2017\/05\/MFE_5108-BW.png\" alt=\"Tony Anscombe\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>13 Aug 2026<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>3 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2026\/08-26\/black-hat-vulnerability-discovery.png\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2026\/08-26\/black-hat-vulnerability-discovery.png\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2026\/08-26\/black-hat-vulnerability-discovery.png\" alt=\"Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p class=\"MsoNormal\">The accelerated discovery of beforehand unknown software program vulnerabilities has been making headlines for months. It\u2019s a difficulty that has even led the US authorities to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/releases\/2026\/07\/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination\/\">create a vulnerability clearing home<\/a> named Gold Eagle to coordinate analysis efforts in vulnerability discovery, mitigation and fixes.<\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">A sign of the broader stress dealing with cyber-defenders may be drawn from the sheer variety of patches being delivered in Microsoft\u2019s Patch Tuesday by the final 4 months: 169 CVEs in April, 118 CVEs in Might, 571 CVEs total in June (together with 208 direct Microsoft CVEs) and one other 622 vulnerabilities in July that included zero-days underneath lively exploitation. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">A keynote at Black Hat USA 2026 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blackhat.com\/us-26\/features\/schedule\/index.html?track%5b%5d=keynotes#keynote-vulnerability-research-in-the-agentic-age-55627\">detailed analysis<\/a> by affiliate professor Yan Shoshitaishvili and his undergraduate college students at Arizona State College on the increasing use of AI fashions for vulnerability discovery. Mr. <\/span>Shoshitaishvili referred to a Washington Publish article from June that acknowledged that Anthropic\u2019s next-generation mannequin Claude Mythos had found 479 vulnerabilities within the Linux kernel, which the college group used as a benchmark. Utilizing earlier generations of GPT fashions, in the meantime, the group had found \u2018simply\u2019 round 300 flaws.<\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">The distinction was attributed to the usage of workflows in Mythos, so the group set about integrating comparable workflows into three GPTs, which resulted within the discovery of round 600 vulnerabilities. The group then educated the GPTs utilizing the properties of beforehand identified vulnerabilities and found roughly 1,000 vulnerabilities. They hit the barrier of discovering vulnerabilities at such velocity that they might not maintain tempo reporting them; for readability, reporting means detailed analysis and proposed fixes, relatively than simply the problem itself. The dimensions calls into query the entire means of accountable disclosure, which within the group\u2019s view was already damaged as disclosure usually creates elevated danger. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">Patching software program in a well timed vogue in manufacturing environments was already a stress level for a lot of cybersecurity groups. Exponential progress like this may very well be the breaking level that causes both extra unpatched software program and better alternatives for cybercriminals or patching with out testing, which, in flip, may trigger compatibility points in lots of environments. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">If I take a logical view of this situation and undertake an optimistic mindset, then it may very well be that we&#8217;re heading in the direction of a peak in discovery \u2013 and that someplace over this peak is a meadow of peace and calm with an improved normality. People researching vulnerabilities has historically been a resource-intensive course of, producing a gentle stream of discoveries which have been rising yr on yr. That is doubtlessly attributable to there being extra researchers, extra software program and extra motivation to find the vulnerabilities for monetary acquire by bug bounty packages and such like. Swap from people to AI, and it\u2019s like a quantum method to discovery, however observe that AI continues to be in a studying part: as detailed by the Arizona group, tweaking the mannequin and its workflow doubtlessly uncovers extra vulnerabilities. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">Then there\u2019s additionally legacy software program. Take into account the large quantity of software program written over the previous 30 years \u2013 no quantity of human effort may probably uncover all of the vulnerabilities within the present and again catalogues of software program. The dimensions of AI-assisted discovery, nevertheless, may doubtlessly attain the tip of {the catalogue} at some stage, after which new discoveries would solely be by enhancements to the mannequin getting used to unearth the vulnerabilities. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">Let\u2019s not overlook that new software program is being developed on a regular basis, after all. Right here, too, after all, logic ought to counsel that any growth group right now would use the identical accessible AI capabilities to take away any potential vulnerabilities <em>previous to <\/em>releasing their software program. And because the fashions enhance, the prospect of nearly flaw-free software program may develop into a actuality. <\/span><\/p>\n<p class=\"MsoNormal\"><span lang=\"EN-US\">If this logic prevails, we could attain the calm and peaceable meadow with only a few new vulnerabilities being discovered. This view may, after all, be only a dream, or my misplaced optimism.<\/span><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>And can right now\u2019s surge in AI-driven vulnerability discovery finally make tomorrow\u2019s software program safer? 13 Aug 2026 \u00a0\u2022\u00a0 , 3 min. learn The accelerated discovery of beforehand unknown software program vulnerabilities has been making headlines for months. It\u2019s a difficulty that has even led the US authorities to create a vulnerability clearing home named [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17740,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10166,3726,585,1061],"class_list":["post-17738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-decline","tag-discovery","tag-era","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17738"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17738\/revisions"}],"predecessor-version":[{"id":17739,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17738\/revisions\/17739"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17740"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-15 08:49:11 UTC -->