
What happened
A wave of AI-assisted vulnerability discovery has hit the software industry. Microsoft issued patches for 974 CVEs in one month, a new record, while cve.icu has logged 66,401 CVEs so far this year.
Why it matters
AI is surfacing more known flaws, not necessarily more total flaws, which is putting pressure on under-resourced IT and security teams and open source volunteers to keep pace with patching.
What to watch
The balance hinges on whether defenders can use AI as effectively as attackers, says Cisco's Matthew Olney. Watch whether patch adoption keeps up with discovery.
WHO IT HITSEnterprise IT and security teams are being pushed to patch faster than ever, while the volunteers maintaining critical open source software face a growing backlog of fixes.
Summaries like this, in your inbox every morning.
The newsletter Kernel Panic debuts with a focus on how AI is reshaping digital security. For years, AI doomers worried about a software vulnerability apocalypse, but the article notes that concern has shifted toward rogue AI causing mass human death. Meanwhile, the vulnerability wave from existing AI tools has already arrived.
The numbers back this up. Microsoft's 974 CVE patches in one month set a record. Oracle shipped 1,448 patches in July, compared to 309 in July 2025. Google Chrome's two major June releases included 1,072 patches, more than all fixes in the prior 23 big releases combined. Mozilla found 271 vulnerabilities in Firefox in one sprint using Anthropic's Mythos model. Overall, cve.icu has logged 66,401 CVEs this year, nearly double the 33,512 recorded by September 16 last year.
Experts are divided on whether this is catastrophic or just magnifying existing dynamics. Jerry Gamblin of Empirical Security argues more CVEs means more known vulnerabilities, which is mostly the system working. But the fear is that patching cannot keep up. As Gamblin puts it, discovery scales with compute, while remediation scales with people. The stakes hinge on whether defenders can use AI as effectively as attackers, and whether under-resourced security teams can close the gap.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
NYU professor Tristan Buckmaster accused OpenAI of learning his Navier-Stokes work was near a solution, then d…

During a May "Capture the Flag" exercise run by security firm Irregular, Google's Gemini hacked three real com…

OpenAI introduced the Australian Youth Safety Blueprint, a six-pillar roadmap covering AI literacy, age-approp…

A Special Operations Command analyst queried a chatbot to synthesize open source data with classified signals…

Anthropic said Accenture's AI division, Faculty, will begin working inside the company to evaluate and red-tea…

Anthropic confirmed to TechCrunch it runs a wet biology lab in the Bay Area where its AI models drive physical…
