LmCast :: Stay tuned in

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

Recorded: Sept. 19, 2026, 11:08 a.m.

Original Summarized

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening | WIREDSkip to main contentTHE WIRED APP IS HEREDOWNLOAD NOW »MenuWIREDSECURITYPOLITICSTHE BIG STORYBUSINESSSCIENCECULTUREREVIEWSMenuWIREDAccountAccountNewslettersSecurityPoliticsThe Big StoryBusinessScienceCultureReviewsChevronMoreExpandThe Big InterviewMagazineEventsWIRED InsiderWIRED ConsultingNewslettersPodcastsVideoLivestreamsWIRED StoreSearchSearchMatt BurgessLily Hay NewmanSecuritySep 19, 2026 7:00 AMForget the AI Slowdown—the Vulnerability Explosion Is Already HappeningAI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.Photo-Illustration: WIRED Staff; Getty ImagesCommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyWelcome to the inaugural edition of Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade. As AI leaders consider a cooperative slowdown on frontier model development, though, one aspect of the cybersecurity sea change has already arrived thanks to existing, broadly available capabilities in mainstream AI products, including open weight models.A tidal wave of vulnerabilities uncovered using AI has only accelerated in recent months—piling more pressure on under-resourced, and very human, IT and security teams and straining volunteers who maintain crucial open source software. Researchers found and disclosed a vast array of vulnerabilities before the rise of AI-enhanced bug hunting as well, but the recent surge is clear.Microsoft said last week that it has issued patches for 974 CVEs so far this month, setting a new record. (CVEs, or common vulnerabilities and exposures, is cybersecurity jargon for confirmed software flaws.) In July, Oracle shipped 1,448 patches compared to 309 in July 2025. Google Chrome’s two major version releases in June included 1,072 patches, more than all of the vulnerability fixes shipped in the prior 23 big releases combined. And Mozilla said in April that it found 271 vulnerabilities in Firefox during one bug hunting sprint using Anthropic’s Mythos model.Across the board, there have been a stunning 66,401 CVEs recorded as of Wednesday this week, according to Jerry Gamblin, the head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project cve.icu. By September 16 last year, cve.icu had logged a total of 33,512 CVEs—almost half the current total. For all of 2022, the year OpenAI launched its first version of ChatGPT, cve.icu recorded 25,000 CVEs.Among both security and AI researchers, experts have been divided about whether this spike and other impacts of AI on cybersecurity will be catastrophic or instead magnify existing dynamics and challenges. Some have pointed out that slow patch adoption and lagging investment in cybersecurity broadly already gave attackers many advantages that led to hacking disasters before the rise of AI. But as vulnerability discovery numbers have continued to rise, and the discussion has become less theoretical, the two sides have seemed to move a bit closer.“I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.”The fear, though, is that vast vulnerability discovery will mean developers getting outpaced on patching, software users who can’t patch fast enough, and an array of escalating cyberattacks fueled by more attackers discovering novel vulnerabilities on their own using AI. As Britain’s National Cyber Security Center puts it, “Just finding vulnerabilities does nothing to improve your security.”For now, many researchers tell us that there is at least a tenuous balance between AI accelerating bug discovery and AI aiding defenders. “Actors, just like industry, are trying to figure out, ‘where do I use AI?’” says Matthew Olney, director of threat intelligence at Cisco Systems.As the situation continues to evolve, an AI slowdown of whatever form—be it regulation or an industry accord—could perhaps/hopefully prevent AI from carrying out a mass human extermination event, but it cannot stop the vulnerability tsunami that has already arrived as a result of existing AI tools.As RogoLabs Gamblin puts it, “Discovery scales with compute. Remediation scales with people—and people are the part you can't buy more of in a quarter.”CommentsBack to topJoin the discussionCommentsBack to topTriangleYou Might Also LikeIn your inbox: Upgrade your life with WIRED-tested gearMcDonald’s built a 515-page dossier on meBig Story: AI is dead—organoids are aliveThe manosphere is a multibillion-dollar grievance industryHow to find us: Add WIRED.com to your preferred sources in GoogleMatt Burgess is a senior writer at WIRED focused on information security, privacy, and data regulation in Europe. He graduated from the University of Sheffield with a degree in journalism and now lives in London. Send tips to [email protected]. ... Read MoreSenior writerXLily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate, and was the staff writer for Future Tense, a publication and partnership between Slate, the New America Foundation, and Arizona State University. Her work ... Read MoreSenior WriterXTopicsKernel Panicvulnerabilitiesartificial intelligencecybersecuritysecurityhackingRead MoreWhy AI Isn’t Likely to Wipe Out Humanity With BioweaponsOf all the threats presented by uncontrollable artificial intelligence, scientists say death by plague ranks low.Kate KnibbsWhy So Many AI Researchers Think the Machines Could Kill EveryoneA combination of rapid advances, recursive self-improvement, and agentic swarms are genuinely “spooking people” inside big labs.Will KnightI Let an AI Agent Hack All My Gadgets—and I’d Do It AgainAfter I removed the safety guardrails from a powerful open-source model, it found vulnerabilities in my household devices and hacked into a PC. But it also told me how to make everything a lot more secure.Will KnightATM Flaws Reveal Key Weaknesses in the Software Supply ChainA security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.Lily Hay NewmanOpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber AbilitiesThe company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.Maxwell ZeffMathematicians Hate AI. They Can’t Quit ItPowerful AI models have created an existential risk to the field, but researchers can’t stop relying on them because they’re too useful.Isabella WardAn OpenAI Agent Tried to Jailbreak ItselfThe company also disclosed previously unreported incidents in which its AI models behaved in misaligned ways, including uploading files to the internet without being asked.Maxwell ZeffNvidia’s Hugging Face Acquisition Is a $12.9 Billion Bet on Open-Source AIThe long-rumored deal will give the chip giant access to—and help it promote—a huge repository of open-source AI models and data sets.Lauren GoodeOpenAI Wants to Know if an AI Industry Slowdown Would Even Be LegalAI leaders worry antitrust law could stand in the way of what they view as an increasingly urgent push to coordinate a slowdown in AI development.Maxwell ZeffIt Still Feels Like Summer in Parts of the US. Blame El NiñoHeat records are being shattered thanks to a boost from the natural climate pattern—and burning fossil fuels, of course.Dennis MersereauWhat We Still Don’t Know About OpenAI’s Hugging Face HackThe AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.Maxwell ZeffOpenAI Is Developing a ‘Persistent’ AI AgentCode reviewed by WIRED reveals the company is developing a feature that enables Codex to continue working proactively until it is “put to sleep.”Maxwell ZeffWIRED is obsessed with what comes next. Through rigorous investigations and game-changing reporting, we tell stories that don’t just reflect the moment—they help create it. When you look back in 10, 20, even 50 years, WIRED will be the publication that led the story of the present, mapped the people, products, and ideas defining it, and explained how those forces forged the future. WIRED: For Future Reference.More From WIREDSubscribeNewslettersDownload the WIRED AppLivestreamsTravelFAQContact UsWIRED StaffWIRED EducationEditorial StandardsArchiveRSSSite MapAccessibility HelpReviews and GuidesReviewsBuying GuidesStreaming GuidesCouponsAdvertiseManage AccountJobsPress CenterCondé Nast StoreUser AgreementPrivacy PolicyYour California Privacy Rights© 2026 Condé Nast. All rights reserved. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast. Ad ChoicesSelect international siteUnited StatesLargeChevronItaliaJapónCzech Republic & SlovakiaFacebookXPinterestYouTubeInstagramTiktok

AI labs are engaging in discussions about slowing down the development of frontier models, while simultaneously, widely accessible AI chatbots are already facilitating the discovery of a massive number of security flaws, signaling an immediate cybersecurity change. This situation introduces complexity to the broader concerns regarding rogue artificial intelligence, shifting focus from a potential software vulnerability apocalypse to the immediate reality of AI-driven security issues arising from existing, deployed capabilities. The recent surge in vulnerability disclosures, uncovered using AI tools, has placed significant pressure on IT and security teams and the volunteers maintaining open source software.

The volume of reported flaws is substantial, demonstrating the impact of AI-enhanced bug hunting. For instance, Microsoft reported patching 974 CVEs in a single month, and Oracle shipped 1,448 patches in July, while Google Chrome's major June releases included 1,072 fixes, surpassing all fixes from the previous twenty-three major releases combined. Mozilla also documented finding 271 vulnerabilities in Firefox during one bug hunting sprint using Anthropic’s Mythos model. Overall, as of the time of reporting, there were 66,401 CVEs recorded, according to Jerry Gamblin of Empirical Security and founder of RogoLabs, which tracks the CVE analysis project cve.icu. This number represents an acceleration in vulnerability discovery, as cve.icu had logged 33,512 CVEs by September 16 of the previous year, and 25,000 CVEs were recorded during the year OpenAI launched its first version of ChatGPT in 2022.

Experts remain divided on whether this explosion in vulnerability findings represents a catastrophic event or merely amplifies pre-existing dynamics. Some argue that the fear is overstated, suggesting that slow patch adoption and inadequate cybersecurity investment had already provided attackers with advantages prior to the rise of AI. However, the continuing increase in vulnerability discovery raises serious concerns about the ability of developers and users to keep pace with remediation efforts. The core danger lies in the potential for more attackers to discover novel vulnerabilities using AI, fostering escalating cyberattacks.

The practical challenge highlights a crucial scaling disparity: while vulnerability discovery scales with compute power, remediation scales with human capacity, which cannot be scaled quickly enough. As Matthew Olney, director of threat intelligence at Cisco Systems, notes, finding vulnerabilities does not inherently improve security. The tension now exists between the potential for an AI slowdown—whether through regulation or industry accords—to prevent existential risks associated with advanced AI development and the inescapable reality of the vulnerability tsunami already manifesting from existing AI tools. Researchers suggest a tenuous balance where AI assists both bug discovery and defense, prompting the industry to determine how to responsibly integrate these tools, as reflected in discussions about where actors should deploy artificial intelligence within the security landscape.