Machine Speed
AI-Cyber Intel
The Board
Watchlist
Briefs
Newsletter
About
RSS
☀
Light
Lanes
Capability
86
Policy
56
Defense
82
Attacks
92
Markets
29
AI-found vulnerabilities
AI finding software flaws faster than they are patched, and what that does to disclosure.
Back to the Watchlist
26
Items
Jul 9
First
Sep 28
Latest
Threads in this topic
Vulnerability disclosure at machine speed
26
Sep 28
Sep 28
Capability
GitHub's security team says its open-source AI agent found 24 vulnerabilities in Android apps
GitHub Security Lab ↗
Sep 16
Capability
Cisco says frontier AI models helped find six Identity Services Engine flaws, four of them rated 9.9 or above
Cisco ↗
Sep 16
Attacks
Cisco confirms active exploitation of a maximum-severity authentication bypass in Identity Services Engine
Cisco ↗
Sep 8
Defense
Microsoft ships its largest Patch Tuesday on record, and the analysts counting it say AI discovery is not producing more exploited flaws
SecurityWeek ↗
Sep 8
Capability
Security firm says AI helped it find a WeChat zero-click flaw and write a working remote-code exploit in about two days
Calif ↗
Sep 3
Capability
Most of the flaws Anthropic's model reported have never been checked by anyone outside the lab
Echo Software (via Help Net Security) ↗
Aug 20
Defense
VulnCheck says AI write-ups and placeholders now outnumber working exploits in public proof-of-concept repositories
VulnCheck ↗
Aug 18
Capability
Rapid7 counts 8,539 new high and critical CVEs in the second quarter, double the year before
Rapid7 ↗
Aug 18
Attacks
A SharePoint flaw found with an AI agent enters CISA's exploited-vulnerabilities catalog
Rapid7 ↗
Aug 18
Markets
A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI
Beazley Security ↗
Aug 18
Capability
Google says its agentic vulnerability-discovery system found 100-plus critical flaws in two days
Mandiant / Google Threat Intelligence Group ↗
Aug 17
Capability
Wiz's autonomous red agent found a CI script-injection flaw that GitHub Advanced Security scanned and missed
Wiz ↗
Aug 14
Capability
METR finds vulnerability disclosures rising far faster than confirmed exploitation
METR ↗
Aug 12
Policy
NIST opens a request for information on modernizing the National Vulnerability Database in the age of AI
NIST / Federal Register ↗
Aug 11
Capability
Rapid7 used an AI agent to help chain two SharePoint flaws into unauthenticated remote code execution
Rapid7 ↗
Aug 11
Capability
Security firm says publicly available AI models let it build a zero-click Zoom RCE in under a day
A Security ↗
Aug 6
Capability
Off-by-1 Labs: about three in four AI-generated vulnerability patches are broken or incomplete
Off-by-1 Labs (1Password) ↗
Aug 5
Capability
PortSwigger's HTTP Terminator: an AI-assisted pipeline invents novel HTTP desync attacks and a live Apache zero-day
PortSwigger Research ↗
Aug 4
Capability
Unit 42 says its NOVA system found 14,090 unknown vulnerabilities across 3,915 open-source projects in two months
Palo Alto Networks Unit 42 ↗
Jul 31
Capability
Epoch AI counts about 2,500 high and critical CVEs disclosed in July, five times the pre-Mythos record
Epoch AI ↗
Jul 28
Capability
VulnCheck finds AI-discovered vulnerabilities are exploited in the wild at the same low rate as any other
VulnCheck ↗
Jul 28
Policy
The CVE Program lets two AI labs assign CVE identifiers in a closed six-month pilot
CVE Program ↗
Jul 23
Capability
An autonomous agent found three critical Microsoft remote-code-execution flaws
XBOW (Microsoft credited the findings) ↗
Jul 14
Defense
Microsoft's July Patch Tuesday fixes a record 570 flaws, including multiple Copilot and Azure AI vulnerabilities
BleepingComputer ↗
Jul 14
Policy
White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities
The White House ↗
Jul 9
Capability
Microsoft says AI-driven scanning is changing the pace of vulnerability discovery, and Windows patch volume with it
Microsoft Windows Experience Blog via Krebs on Security ↗
Items, newest week first
Week of Sep 28
1
Sep 28
Capability
GitHub's security team says its open-source AI agent found 24 vulnerabilities in Android apps
Week of Sep 14
2
Sep 16
Capability
Cisco says frontier AI models helped find six Identity Services Engine flaws, four of them rated 9.9 or above
Sep 16
Attacks
Cisco confirms active exploitation of a maximum-severity authentication bypass in Identity Services Engine
Week of Sep 7
2
Sep 8
Capability
Security firm says AI helped it find a WeChat zero-click flaw and write a working remote-code exploit in about two days
Sep 8
Defense
Microsoft ships its largest Patch Tuesday on record, and the analysts counting it say AI discovery is not producing more exploited flaws
Week of Aug 31
1
Sep 3
Capability
Most of the flaws Anthropic's model reported have never been checked by anyone outside the lab
Week of Aug 17
6
Aug 20
Defense
VulnCheck says AI write-ups and placeholders now outnumber working exploits in public proof-of-concept repositories
Aug 18
Capability
Google says its agentic vulnerability-discovery system found 100-plus critical flaws in two days
Aug 18
Capability
Rapid7 counts 8,539 new high and critical CVEs in the second quarter, double the year before
Aug 18
Attacks
A SharePoint flaw found with an AI agent enters CISA's exploited-vulnerabilities catalog
Aug 18
Markets
A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI
Aug 17
Capability
Wiz's autonomous red agent found a CI script-injection flaw that GitHub Advanced Security scanned and missed
Week of Aug 10
4
Aug 14
Capability
METR finds vulnerability disclosures rising far faster than confirmed exploitation
Aug 12
Policy
NIST opens a request for information on modernizing the National Vulnerability Database in the age of AI
Aug 11
Capability
Security firm says publicly available AI models let it build a zero-click Zoom RCE in under a day
Aug 11
Capability
Rapid7 used an AI agent to help chain two SharePoint flaws into unauthenticated remote code execution
Week of Aug 3
3
Aug 6
Capability
Off-by-1 Labs: about three in four AI-generated vulnerability patches are broken or incomplete
Aug 5
Capability
PortSwigger's HTTP Terminator: an AI-assisted pipeline invents novel HTTP desync attacks and a live Apache zero-day
Aug 4
Capability
Unit 42 says its NOVA system found 14,090 unknown vulnerabilities across 3,915 open-source projects in two months
Week of Jul 27
3
Jul 31
Capability
Epoch AI counts about 2,500 high and critical CVEs disclosed in July, five times the pre-Mythos record
Jul 28
Capability
VulnCheck finds AI-discovered vulnerabilities are exploited in the wild at the same low rate as any other
Jul 28
Policy
The CVE Program lets two AI labs assign CVE identifiers in a closed six-month pilot
Week of Jul 20
1
Jul 23
Capability
An autonomous agent found three critical Microsoft remote-code-execution flaws
Week of Jul 13
2
Jul 14
Policy
White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities
Jul 14
Defense
Microsoft's July Patch Tuesday fixes a record 570 flaws, including multiple Copilot and Azure AI vulnerabilities
Week of Jul 6
1
Jul 9
Capability
Microsoft says AI-driven scanning is changing the pace of vulnerability discovery, and Windows patch volume with it