OpenSSF Finding and Fixing Vulnerabilities Using AI

1.4 Why this is important

This material is critically important for today’s software developers and security researchers. AI has become incredibly good at finding vulnerabilities, for both attackers and defenders. This is requiring defenders to rapidly find and fix vulnerabilities using AI. If they don’t, their resulting systems will be repeatedly taken over by attackers who are already using AI. CrowdStrike found that even back in 2025, “AI-enabled adversaries increased attacks by 89% year-over-year” [CrowdStrike2026-Global]. That’s accelerating now.

There are many reasons this topic is important. Here we summarize them, with quotes and citations showing that this is real. In short, AI has sped up vulnerability-finding, attackers are using that increased speed to accelerate their attacks, and traditional manual closed processes are failing to keep up. Yet there is still a role for humans, if the humans understand how to apply AI to it

1.4.1 AI is accelerating vulnerability-finding

AI has greatly sped up vulnerability finding in software:

1.4.2 Attack speed is accelerating

Since the speed of finding vulnerabilities has increased, and cost of finding vulnerabilities has decreased, the speed of attacks that exploit those vulnerabilities has increased:

1.4.3 Manual closed approaches are failing

Traditional approaches relied on manual analysis, took months to respond, and sometimes depended on hiding source code, presuming no one else could find these vulnerabilities quickly. They always had challenges, but here’s why they’re failing now:

1.4.4 Still need humans

However, to find and fix software vulnerabilities using AI, humans still have key roles to play. Those humans, however, must know how to apply AI to the task.

We hope these points will convince you that it’s vital for software developers to learn how to find and fix vulnerabilities using AI.