惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
V
Visual Studio Blog
雷峰网
雷峰网
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
C
Check Point Blog
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
D
Docker
IT之家
IT之家
博客园 - 聂微东
腾讯CDC
U
Unit 42
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
AI revolution? CVE disclosures jump by up to 500% for som...
david.hollin · 2026-05-15 · via Security

As artificial intelligence comes into its own for vulnerability discovery, some vendors are reporting a sharp increase in disclosures.

Vulnerability disclosures had been rising steadily across the final months of 2025, and that continued into 2026.

Then something changed.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

Disclosure rates jumped sharply, with vulnerabilities reported across GitHub rising by a factor of four in the period between January and March 2026 compared to the previous 90 days.

“The number of unique reporters more than doubled,” Madison Oliver Ficorilli, staff manager at GitHub, said in a 4 April blog post.

“The number of targeted repositories more than doubled. No single reporter accounts for more than ~3 per cent of volume, and no single project accounts for more than ~7 per cent. This isn’t one person or one tool, it’s a systemic shift in how vulnerability reporting is happening across the ecosystem.”

And that’s just on GitHub. According to VulnCheck security researcher Patrick Garrity, this increase in disclosures is happening across a far wider range of companies. For instance, Chrome reported a 563.2 per cent increase in disclosure volumes for the year to date, VMware a 180.9 per cent jump, and Apache 170.3 per cent.

Mozilla, HPE, and F5 all reported similar figures. Initially, the rate of disclosures in early 2026 was made up largely of AI slop, but on 7 April, with the announcement of Claude Mythos Preview and Project Glasswing, Garrity said the conversation “shifted hard”.

“The evidence appears to point to emerging AI models that have enabled software suppliers and security researchers to discover and remediate vulnerabilities that would have likely gone overlooked otherwise,” Garrity said in a 14 May blog post.

Mozilla, according to Garrity, is a perfect example of the impact of AI-assisted vulnerability. The company recently said that since earlier this year, “the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser”. The numbers speak for themselves; in February, Firefox released 61 fixes, and 76 the next month.

In April, however, that number surged to 423 security bug fixes. Mozilla said the jump was due to its close work with Anthropic and its Mythos Preview under the purview of Project Glasswing, of which Mozilla is a member.

Google’s raw numbers of Chrome are similarly illustrative. Across the whole of 2025, Chrome was responsible for 194 CVE disclosures. So far, in 2026, that number has risen to 378 as of mid-May.

“While we haven’t seen concrete confirmation of what tools were used to drive the sudden increase, we suspect it’s related to AI discovery tools, likely some combination of Mythos and Google’s own AI models,” Garrity said.

“The trend points toward AI-assisted discovery as the most likely driver.”

The thing to watch for, according to Garrity, is whether this trend continues or if these increases simply turn out to be an AI-driven blip. Regardless, he believes defenders need to be ready.

“Most defenders are starting to see the initial impact of AI-assisted vulnerabilities in their backlogs and should plan for sustained volumes over time,” Garrity said.

“That reinforces the importance of patching early and often, updating to the latest version when possible, and using threat intelligence to prioritise emerging threats that are being actively exploited or likely to be.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.