Palo Alto Networks shipped an unusually large batch of security advisories this week. Twenty-six advisories covering 75 vulnerabilities, roughly fifteen times the company's normal monthly cadence. According to The Register, most of the bugs were discovered not by human researchers but by frontier AI models, including Anthropic's Mythos and OpenAI's GPT-5.5-Cyber.
The company's own writeup is more measured but no less striking. In a May 13 blog post, Palo Alto CTO Lee Klarich described AI-assisted bug hunting as having fundamentally shifted the economics of vulnerability research, and warned that defenders have a window of three to five months before AI-driven exploitation, not just discovery, becomes the norm. After that, he wrote, anyone running unpatched infrastructure should assume an automated attacker will find a way in.
Microsoft sees the same pattern
Microsoft is reporting similar internal numbers. The Microsoft Security Response Center has been quietly running its own large language models against its source code for months, and a recent SecurityWeek piece describes a surge in self-reported issues across Windows, Azure and Office driven by the same technique. Across the two vendors, the volume of newly disclosed bugs is rising fast enough that The Register dubbed the moment the vulnpocalypse.
The defensive read
There is a read on this that is genuinely encouraging. If the same AI tools that attackers will eventually wield are being pointed at code by the companies that wrote it, the result is more bugs found and patched before they reach the wild. CNBC, in a May 13 piece, quotes Klarich saying the goal is to spend the next year getting ahead of attackers while the asymmetry still favours defenders.
The harder read is what happens after that. Almost everything in modern software, from kernel drivers to cloud orchestration, has decades of accumulated code that no human team has ever fully audited. The bet behind frontier-AI security research is that defenders can sweep through that backlog before attackers do. There are reasons to think it will work. There are also reasons to be uneasy about what a six- or twelve-month gap between sides actually looks like when both have the same tools.
For most organisations the immediate takeaway is mundane. Patch faster. Inventory what is running. Treat the next year of vendor advisories as larger and more frequent than usual. The vulnpocalypse, if that label sticks, is not a single event. It is a sustained surge that rewards defenders who are already operating well and punishes those who are not.
Sources
- i. www.cnbc.com
- ii. www.axios.com
- iii. www.paloaltonetworks.com
- iv. www.securityweek.com
- v. www.theregister.com
Commentarii · 0