Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Briefly

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
"Palo Alto Networks usually finds five vulnerabilities a month, but on Wednesday said it scanned its entire codecase using the latest frontier models, including Anthropic's Mythos, and found 75 security holes, covered in 26 CVEs."
"Microsoft said it used its new agentic bug hunting system called MDASH to find 17 vulnerabilities across its products - on a record-setting Patch Tuesday that saw Redmond disclose a whopping 30 critical CVEs."
"Mozilla said it fixed 423 Firefox bugs in April, which is more than five times higher than the 76 fixes issued in March and almost 20 times higher than its 21.5 monthly average last year. The browser maker previously said Mythos found 271 flaws in Firefox 150."
""At first, yes, this means more patches and thus more work for admins," he told The Register. "The goal over time would be to eliminate as many as possible, and, over time, that monthly number goes down." "Many customers don't trust patches as it is, so if AI-related patches break things, they are less likely to apply as time goes on," Childs added."
Palo Alto Networks scanned its entire codebase using frontier models, including Anthropic’s Mythos, and found 75 security holes covered in 26 CVEs. Microsoft reported using an agentic bug hunting system called MDASH to find 17 vulnerabilities across its products during a record-setting Patch Tuesday that disclosed 30 critical CVEs. Mozilla reported fixing 423 Firefox bugs in April, far above prior monthly levels, and previously said Mythos found 271 flaws in Firefox 150. Security vendors have warned that attackers can use AI, pushing defenders to operate at AI speed. AI scanning can uncover flaws before attackers, leading to more patches and more work for administrators. The main risk is patch reliability, since broken patches reduce customer trust and adoption.
Read at theregister
Unable to calculate read time
[
|
]