This material is critically important for today’s software developers and security researchers. AI has become incredibly good at finding vulnerabilities, for both attackers and defenders. This is requiring defenders to rapidly find and fix vulnerabilities using AI. If they don’t, their resulting systems will be repeatedly taken over by attackers who are already using AI. CrowdStrike found that even back in 2025, “AI-enabled adversaries increased attacks by 89% year-over-year” [CrowdStrike2026-Global]. That’s accelerating now.
There are many reasons this topic is important. Here we summarize them, with quotes and citations showing that this is real. In short, AI has sped up vulnerability-finding, attackers are using that increased speed to accelerate their attacks, and traditional manual closed processes are failing to keep up. Yet there is still a role for humans, if the humans understand how to apply AI to it
1.4.1 AI is accelerating vulnerability-finding
AI has greatly sped up vulnerability finding in software:
The cost, expertise, and effort to find vulnerabilities has collapsed.
“With the latest frontier AI models, the cost, effort, and level of expertise required to find and exploit software vulnerabilities have all dropped dramatically. Over the past year, AI models have become increasingly effective at reading and reasoning about code—in particular, they show a striking ability to spot vulnerabilities and work out ways to exploit them.” [Anthropic2026-04g]
Far more vulnerabilities are being found with AI. Agentic AI can find far more vulnerabilities (exploitable defects) than non-AI systems. AI can use other tools and integrate that information to discover problems.
One paper “found that [AI was] crucial to the success of [finding vulnerabilities; without AI traditional fuzzers] were unable to discover a single bug within a four-hour time limit in any of 20 trials. …. [this] highlights the importance of integrating LLM-assisted tooling into automated security workflows.” [Wolff2026]
AI can rapidly turn vulnerabilities into exploits, often by chaining multiple defects together. AI’s ability to rapidly turn a vulnerability into an exploit accelerates the need for repair. In particular, AI can often combine multiple minor-seeming defects into a devastating chain.
“Claude Mythos Preview demonstrates a leap in these cyber skills—the vulnerabilities it has spotted have in some cases survived decades of human review and millions of automated security tests, and the exploits it develops are increasingly sophisticated… frontier AI models are now becoming competitive with the best humans at finding and exploiting vulnerabilities.” [Anthropic2026-04g]
The speed at which vulnerabilities are found and exploited has dramatically accelerated.
“AI is making it possible to detect severe security vulnerabilities at highly accelerated speeds.” [Anthropic2026-03]
Far more attackers can now create sophisticated attacks.
“Advanced frontier models (like Claude Mythos Preview) and optimized open-weight models have democratized the ability to find complex vulnerabilities and construct exploit chains, exposing non-traditional targets to high-level threats.” [Wolff2026]
1.4.2 Attack speed is accelerating
Since the speed of finding vulnerabilities has increased, and cost of finding vulnerabilities has decreased, the speed of attacks that exploit those vulnerabilities has increased:
Attackers are becoming faster and more dangerous.
[FiveEyes2026] says that “Adversaries are already using AI to move faster and more effectively. Defenders must do the same.”
CrowdStrike similarly says “AI systems are beginning to assist with tasks that materially improve offensive velocity [and will be used by] adversaries.” [CrowdStrike2026-FiveSteps]
“The window between a vulnerability being publicly disclosed and weaponized has dramatically collapsed to hours or minutes, as AI can instantly reverse-engineer patches to create exploit blueprints.” [Wolff2026]
Attackers are now, on average, exploiting vulnerabilities before a patch is released.
“Mandiant’s M-Trends 2026 report measures the mean time between a vulnerability becoming publicly known and the first observed exploitation in the wild. In 2018, that interval was 63 days. By 2023 it had collapsed to 5 days. In 2025, it inverted. Attackers are now exploiting vulnerabilities an average of 7 days before patches are released.” [Cycode2026]
Similarly, ZeroDayClock says that in “2018, the median time from a vulnerability being disclosed to the first observed exploit was 771 days. Organizations had over two years to patch. By 2023, that window was 6 days. By 2024, it was 4 hours. In 2025, the majority of exploited vulnerabilities were weaponized before they were even publicly disclosed.” [ZeroDayClock]
1.4.3 Manual closed approaches are failing
Traditional approaches relied on manual analysis, took months to respond, and sometimes depended on hiding source code, presuming no one else could find these vulnerabilities quickly. They always had challenges, but here’s why they’re failing now:
Traditional slow security measures are becoming ineffective.
“As AI speeds up both discovery and exploitation, organizations need to move from periodic assessment to continuous, intelligence-driven exposure management… They must also prepare for a surge in vulnerability discovery and patch activity that many organizations are not operationally prepared to absorb… As vulnerabilities are discovered and exploited on shorter timelines, traditional security approaches built on periodic assessments, severity scores, and human-paced response are becoming less effective.” [CrowdStrike2026-FiveSteps]
“When a software vendor releases a security patch, AI can now reverse-engineer that patch, identify the vulnerability it fixes, and generate a working weaponized exploit in minutes. Attacks can begin propagating across the world within hours. But organizations need an average of 20 days to test and deploy that same patch.” [ZeroDayClock]
Deployment delays become real-world harm.
“A large fraction of real-world harm comes from N-days: vulnerabilities that have been publicly disclosed and patched, but which remain exploitable on the many systems that haven’t yet applied the fix. … the patch itself is a roadmap to the bug, and the only thing standing between disclosure and mass exploitation is the time it takes an attacker to turn that patch into a working exploit.” [Carlini2026]
Hiding source code doesn’t help.
“We have also found the model to be extremely capable of reverse engineering: taking a closed-source, stripped binary and reconstructing (plausible) source code for what it does. From there, we provide Mythos Preview both the reconstructed source code and the original binary [and it succeeds] …” [Carlini2026]
Failure to use AI to defend may in some cases be considered negligence.
“When AI can find significantly more vulnerabilities at accessible cost, the standard of what constitutes reasonable defensive effort shifts. Boards will face questions about whether they used available AI tools for defensive scanning, and whether not doing so constitutes negligence. This is a governance risk with direct financial exposure.” [CSA2026]
1.4.4 Still need humans
However, to find and fix software vulnerabilities using AI, humans still have key roles to play. Those humans, however, must know how to apply AI to the task.
We hope these points will convince you that it’s vital for software developers to learn how to find and fix vulnerabilities using AI.