惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
I
Intezer
K
Kaspersky official blog
L
LINUX DO - 热门话题
B
Blog RSS Feed
Recorded Future
Recorded Future
Simon Willison's Weblog
Simon Willison's Weblog
G
GRAHAM CLULEY
博客园_首页
T
The Blog of Author Tim Ferriss
T
Tor Project blog
雷峰网
雷峰网
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - Franky
Recent Announcements
Recent Announcements
W
WeLiveSecurity
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
News and Events Feed by Topic
Google DeepMind News
Google DeepMind News
大猫的无限游戏
大猫的无限游戏
S
Security Affairs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
MyScale Blog
MyScale Blog
Last Week in AI
Last Week in AI
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
N
News and Events Feed by Topic
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Scott Helme
Scott Helme
L
LINUX DO - 最新话题
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX - 技术
腾讯CDC
The Cloudflare Blog
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Security Archives - TechRepublic
N
News | PayPal Newsroom
D
DataBreaches.Net
H
Hackread – Cybersecurity News, Data Breaches, AI and More
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cloudbric
Cloudbric
S
Security @ Cisco Blogs
Latest news
Latest news
V
V2EX
博客园 - 聂微东

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
The 2026 Vulnerability Forecast Update: Navigating the AI Epoch
jruohonen · 2026-06-16 · via Hacker News - Newest: "AI"

By FIRST Forecasting team: Jerry Gamblin and Eireann Leverett
Monday, June 15, 2026

2026 Vulnerability Forecast Update

Introduction: A Structural Shift in the Vulnerability Landscape

The cumulative drift is currently +46.3% above the original forecast (an excess of 6,420 CVEs), leading to a revised 2026 projection of ~66K CVEs. There were many questions earlier this year when we produced prediction intervals as wide as 100k. Still, an important feature of a forecast is that it encompasses unlikely but realistically possible outcomes. AI-assisted discovery has increased the chances that we see what many people would consider an extreme number of vulnerabilities this year, and we take such things into account when producing the strategic forecast.

As we look toward the second half of 2026, the vulnerability coordination domain is undergoing an unprecedented transformation. With the recent deployments of highly autonomous AI discovery tools, such as Anthropic’s Mythos (a specialized, unreleased agent in the Claude family) and OpenAI’s GPT-5.4-Cyber, the volume of identified software flaws has accelerated massively. However, as we will explore in this mid-year update, a spike in raw discovery volume does not equate to an unmanageable security crisis. In sharp contrast, there is evidence that version cadences are remaining static amongst the rising tide of new CVEs. This is clearly visible in the lower graph, where the interval per product release is slightly increasing. In other words, we think more CVEs are being shipped with each version update, but the version updates remain the same cadence.

2026 Vulnerability Forecast Update

We thus advocate for calm growth in your vulnerability exposure management teams and processes, rather than a panic-driven narrative. Prepare to double the work you do if you maintain software, but we actually expect the work you do patching live systems to remain steady, at least through the end of 2026. The growth we see in CVE volumes is often attributed to more eyes, more bug bounties, and more AI-generated results. However, we think this ignores the growth of Open Source projects receiving attention for the first time, as well as the raw growth of software worldwide. As we can see below, this is a significant factor in CVE growth, not mentioned elsewhere.

2026 Vulnerability Forecast Update

Part 1: The 'Epochal' Shift and the Discovery Surge

Historically, the FIRST vulnerability forecast relied on time-series models to predict the organic growth of CVEs. The 2017 structural change in CVE data represented a major shift, and we carefully chose models to either avoid or accept it. That internal history is relevant today because everyone believes we are going through another transformational period. Forecasters have to make important choices about when and where to switch tools.

2026 has introduced an entirely new paradigm: the capability-triggered model.

  • The AI Discovery Era: We are currently witnessing the first major wave of AI-assisted bug hunting. For instance, there was a 164 % spike in Q1 disclosures at Mozilla, directly attributable to Anthropic's Project Glasswing, which uses the unreleased Mythos Preview agent and Claude Opus 4.6 to autonomously find legacy bugs within the Firefox engine. As detailed in the recent report "Behind the Scenes Hardening Firefox with Claude Mythos Preview" by Mozilla's Brian Grinstead, Christian Holler, and Frederik Braun, the team built an agentic harness on top of their fuzzing infrastructure to successfully identify and fix 271 bugs for the Firefox 150 release. This activity clarifies the relationship between the more general "Claude models" and the specialized "Mythos" agent mentioned throughout this forecast.

2026 Vulnerability Forecast Update

  • Structural Volume Drivers: Beyond AI, structural expansions are inflating the numbers. Specifically, GitHub Security Advisories (GHSA) volume is up 449% YoY due to an expanded curation team and CVE ID backfill campaign, and VulnCheck is up 3,119% YoY as a CNA of Last Resort absorbing the unassigned backlog. These expansions have dramatically increased aggregate volume. Growth in software will also naturally drive growth in CVEs, but we are still learning how to distinguish between the two.
  • The Real Bottleneck: In an era where AI can find significantly more flaws than human analysts, the constraint is no longer discovery; it is the human capacity to verify, coordinate, and patch. We also believe a crucial bottleneck will be in writing detection signatures for exploitation. The issue often comes down to the difference between identification and true risk detection.

Part 2: The Exploitability Overlay (Rain vs. Floods)

If we look only at the total volume of vulnerabilities, the forecast appears daunting. However, applying an "exploitability overlay" reveals a much more actionable reality. We refer to this as the "Rain vs. Flood" analogy.

  • Heavy Rainfall (Total Volume): The aggregate number of CVEs and disclosures is surging due to AI discovery and broader cataloging.
  • Stable Flood Lines (Actionable Risk): When filtering the massive volume surge for actual exploitability—specifically vulnerabilities present in the CISA KEV (Known Exploited Vulnerabilities) catalog or possessing an EPSS (Exploit Prediction Scoring System) score above 10%—the actionable patching burden remains completely flat. This 10% threshold is chosen to align with organizational risk appetites, targeting the highest-leverage, smallest subset of vulnerabilities for immediate action. The critical takeaway for defenders in 2026 is th Mitchellat, while total rainfall is up significantly, the actual flooding risk has not changed. The challenge lies entirely in separating the patchable signal from the unpatchable noise.
Metric Trend (1H 2026) Driver
Total reported disclosures (Volume) Massive Increase AI Bug Hunting (Mythos/Claude) & Structural CNA Expansion
Actionable Exploitability (EPSS >10% / KEV) Flat / Stable Structural complexity of reliable exploit development vs. legacy bugs.

2026 Vulnerability Forecast Update

As adversarial capabilities expand, so do defensive mechanisms. The release of specialized defensive AI models, such as OpenAI's GPT-5.4-Cyber for "Trusted Access," provides a counterbalance to the rapid generation of exploits.

  • Poachers Turning Gamekeepers: Historical data strongly suggests that offensive capabilities are rapidly adapted for defensive purposes. Defensive AI offers the potential to severely compress the Mean Time To Remediate (MTTR).
  • The Race: The defining security dynamic of late 2026 will not just be AI finding bugs, but the race between AI-accelerated exploit development and AI-accelerated automated patching generation, or AI-assisted exploitation signature creation.

This is a crucial time for software maintainers to lean into automated tooling to find and remediate within their remit. That advantage may not last long, and so should be seized. Vulnerabilities are becoming easier to find, so more work can be done on verifying and applying learning constructively in the secure software development lifecycle. We could be eliminating entire classes of CWE rather than continuing the death-by-a-thousand-cuts approach.

Part 4: Ephemeral Software and Micro-Vulnerabilities

Traditional vulnerability forecasting focuses heavily on vendor and product breakdowns. However, 2026 demands that we account for "ephemeral instant software"—code generated and deployed on demand by AI assistants.

  • The Shadow Registry: These AI-generated, bespoke applications often contain flaws that will never be reported to a traditional CVE registry.
  • Systemic Risk: While these "micro-vulnerabilities" are not tracked in aggregate national databases, they pose a significant localized systemic risk that modern vulnerability management programs must learn to catalog and assess dynamically.

To address this, vulnerability programs must evolve toward dynamic cataloging, using AI-BOMs (Bills of Materials) and runtime monitors to detect, inventory, and continuously assess these ephemeral components as they are deployed.

Conclusion: Analysts are Humans (For Now)

The foundational constraint of the Coordinated Vulnerability Disclosure (CVD) ecosystem is human capacity. The NVD team takes vacations. Security analysts get sick. When we see a drop in published vulnerabilities or a delay in processing, we are often seeing reduced human headcount rather than a safer internet.

We believe that those of you managing assets should advocate for a budget not based on CVE growth, but rather on software growth. This is evident in the graphs below, which show that the number of distinct CPE or software products with vulnerabilities has grown by two orders of magnitude. It is the growth in the asset register's diversity, not the growth of CVEs, that is driving heavy workloads.

2026 Vulnerability Forecast Update

On the other hand, if you work for a software company, the growth in CVEs is directly relevant to your workload and release cycles. You simply must learn to ship more patches per security release.

As we navigate the AI Epoch, our defense strategies must pivot away from merely tracking the total volume of flaws. We must rely on exploitability overlays, contextual asset mapping, and defensive AI tools to ensure our human analysts focus only on the water threatening to flood the house.

Full Data and Methodology

The full methodology of this forecast, live data reports, and the Python scripts (cve_forecast_halftime.py and exploitability_overlay.py) used to generate these models are available in the companion GitHub repository: https://github.com/jgamblin/FirstForecast

The historical yearly forecast was written with a SARIMAX model, and in the mid-year cycle we switched to examining monthly forecasts with the monthly forecast code above. We discussed both, and made some judgements, and we think the monthly data shows different interesting stories that allows for better strategic decision making.

That yearly model can be found here: https://github.com/FIRSTdotorg/Vuln4Cast