Key Takeaways

  • Anomalous volume: Mozilla discovered 271 vulnerabilities in Firefox through AI, AISLE found 12 zero-days in OpenSSL including a CVSS 9.8 flaw dating back to 1998.
  • Key technology: Anthropic's Claude Mythos and the disclosure project Project Glasswing generate working exploits autonomously, without human guidance.
  • Operational impact: Microsoft's July bulletin brought 570 fixes, Oracle's over 1,400; CISOs speak of a window between discovery and exploitation compressed into hours.

The numbers behind a storm

Major labs are discussing a pact to slow down frontier model development. On the cybersecurity front, there's no slowdown at all: AI-driven vulnerability discovery is already an anomalous wave that the world's security system isn't equipped to handle, as documented by Wired's Kernel Panic newsletter.

The arrival of Anthropic's Claude Mythos triggered the phenomenon. The model finds thousands of critical vulnerabilities in every major operating system and browser, generating working exploits without human intervention. The connected project, Project Glasswing, made the impact public.



AI Uncovers Thousands of Flaws: Systems Under Siege - Foto 1

Mozilla discovered 271 vulnerabilities in Firefox using Mythos, of which only 3 were serious enough to warrant a CVE. Linux kernel maintainers saw reports climb from 2 to 10 per week: initially almost all hallucinations, now verified as real bugs. The curl project, which had suspended its bug bounty due to excessive hallucinated reports, is now receiving increasingly solid reports. AISLE identified 12 zero-days in OpenSSL, including a CVSS 9.8 vulnerability dating back to 1998.

The problem isn't finding the flaws: it's patching them

Cybersecurity used to be a problem of scarcity: finding a bug cost weeks of expert work. It has become a problem of speed. The UK's NCSC had predicted a "patch wave": Microsoft's July bulletin brought 570 fixes, Oracle's exceeded 1,400.



AI Uncovers Thousands of Flaws: Systems Under Siege - Foto 2

The Cloud Security Alliance describes the window between discovery and weaponization as compressed "into hours," with organizations set to be "crushed by the volume of patches." Only about 1% of AI-discovered vulnerabilities actually end up exploited in attacks, but that figure offers little comfort: the attacker only needs to win once, the defender must win every time.

The asymmetry worrying CISOs

Google CISO Heather Adkins and Gadi Evron had predicted back in September 2025 a "singularity moment" for autonomous attacks roughly six months out. That distance has now passed. The CSA defines the current scenario as a structural asymmetric advantage: AI lowers the cost and skill threshold needed to discover and exploit vulnerabilities faster than organizations can fix them.

Sysdig documented an AI-based attack that achieved administrator access in eight minutes. A startup released MOAK, a site that uses public frontier models to autonomously generate exploits starting from a simple CVE. Code is being removed from the Linux kernel to reduce the attack surface exposed to LLM-guided vulnerability hunting.

What to do before it's too late

The CSA proposes finding your own bugs before someone else does: continuous discovery powered by AI-native AppSec, automated patching, baseline hardening with segmentation, MFA and egress filtering, plus a review of downtime tolerance. Experts estimate an 18-month gap: businesses preparing now will have a structural advantage by 2027; those who wait will face the same work under siege, at higher costs.



AI Uncovers Thousands of Flaws: Systems Under Siege - Foto 3

The debate over slowing frontier models concerns the future. The already multiplied workload for system administrators concerns the present.