Security News

Cybersecurity news aggregator

INFO News Dark Reading

AI’s Vulnerability Surge May Be More Manageable Than First Feared

  • What: Research suggests AI is accelerating vulnerability discovery but enterprises may be better prepared than expected.
  • Impact: Organizations need to improve validation and prioritization of security fixes.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY CYBER RISK THREAT INTELLIGENCE VULNERABILITIES & THREATS NEWS AI’s Vulnerability Surge May Be More Manageable Than First Feared New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies. Jai Vijayan,Contributing Writer September 2, 2026 4 Min Read SOURCE: FOTOFIELD VIA SHUTTERSTOCK A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed. The key is their ability to quickly validate findings, prioritize risk and get available fixes into production. Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic's Claude Mythos. AI Has Accelerated One Side of the Equation The results, detailed in a report titled Mythos Readiness Report, show how AI is transforming vulnerability discovery and exploit development — something that security teams have been encountering firsthand over the past year. Monthly CVE disclosures rose 145% in two years, from 3,173 in June 2024 to 7,765 in June 2026, partly due to the expansion of the CVE program and increasingly because of AI-assisted vulnerability discovery. On an annual basis, CVE disclosures shot up from 30,949 in 2023 to 49,979 in 2025 and, based on the numbers so far, 2026 is on track to surpass even that number. Related:Attackers Pounce on Critical Artifactory Bug Following Disclosure Echo discovered the same pattern with container base images, of which Node and Python are the most frequently used. Between January and June 2026, the number of known CVEs in Node base images surged 338%, from around 16,000 to 70,000, while for Python the numbers went from 17,500 to 45,000 in the same period. "Vulnerabilities are now being discovered at machine speed, while remediation remains largely manual," Echo wrote in its report. "In essence AI has dramatically accelerated once side of the equation, but the other has yet to catch up." Echo found that Claude Mythos has fundamentally changed the economics of exploit development and made it possible for researchers and bad actors to develop a working exploit for a known vulnerability in less than one day and for under $2,000. A More Nuanced Reality for Security Teams While the raw data might suggest a situation that is quickly spiraling out of control for organizations, Echo found some reasons for optimism. For one thing, a lot of the vulnerabilities that AI tools are discovering are not yet vetted and often turn out to be less serious than initially assumed. For example, over the period that Echo studied, Mythos discovered some 23,019 potential vulnerabilities. But fewer than 10% had been external validated, or independently checked. Of the 27 vulnerabilities that Anthropic publicly disclosed, Mythos initially classified eight of them as being of critical severity. But after researchers independently reviewed the eight flaws, only one retained the critical rating. Related:'HTTP Terminator' Hunts for Novel Desync Attacks "One of the biggest surprises was that being ready for Mythos is actually much more achievable than expected," Eylam Milner, chief technology officer (CTO) and co-founder at Echo, tells Dark Reading. "Mythos is really good at finding real vulnerabilities, but it’s much less reliable at determining how serious those vulnerabilities actually are, which is a really important distinction for security teams trying to decide what requires their attention." Rather than completely rethinking everything they’re doing around vulnerability management, he says, organizations need to focus on infrastructure for quickly validating a larger number of vulnerabilities, understanding what matters and then remediating them efficiently. Self-Inflicted Exposures? Echo also found that at least some of the vulnerability management challenges that organizations might be facing are the result of their own doing. A notable 89% of the vulnerabilities that Echo examined had a fix, for example. The numbers were even higher for critical and high severity vulnerabilities. Yet, Echo found nearly 40% of fixable vulnerabilities remained unresolved for more than six months Related:OWASP Flags Top AI Skill Risks in New Security Blueprint The numbers indicate that fix availability isn't actually the biggest problem rather it's getting those fixes into production, Milner says. "A fix being available doesn't mean it's easy to deploy. Applying it can require upgrading dependencies, testing for compatibility and breaking changes, and moving the change through an organization's normal development and release process." When security teams need to apply that process across thousands of vulnerabilities, remediation can become a massive prioritization/resource problem. Engineering teams have limited time, and security fixes compete with product work and other priorities, so vulnerabilities that have a fix available can sit in the backlog for months. "That's why we think the answer is to remove as much of that manual work as possible — continuously delivering patched software rather than relying on engineering teams to chase and deploy every fix themselves," he says. Echo uncovered another problem: Many organizations, even those that assessed themselves as having mature security practices, often had self-inflicted vulnerability exposures. Nearly 6 in 10 (56%) of container vulnerabilities stemmed from packages, utilities, development tools and other software not needed in production. "Before worrying about how to keep up with every new vulnerability AI finds, organizations should focus on reducing the attack surface they already have," Milner advises. "Build with less vulnerable software to begin with, remove the dependencies they don’t need, and focus on getting available fixes into production much faster." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? LOADING... HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Worki

Share this article