Experts in cybersecurity are raising alarms about artificial intelligence, though not for the usual reason of machines turning against humans. Their concern is that AI tools are actually improving the ability to discover software defects, which has created a pressing question: how can these flaws be repaired more quickly.
A newsletter from the Kernel, penned by Lily Hay Newman and Matt Burgess, says that firms are releasing more security patches than ever before, driven by AI that hunts bugs faster. The consequence is a growing heap of flaws that human crews cannot manage.
Patch Numbers Are Breaking Records
Last week Microsoft announced that it has released fixes for 974 CVEs so far this month, which sets a new record for the company. CVEs stand for common vulnerabilities and exposures, the official tally of confirmed software flaws.
The patch rush is not confined to a single company. Oracle released 1,448 updates in July, up from 309 in July 2025. Meanwhile, Google Chrome pushed two major version releases in June, which came with 1,072 fixes — more than the total number of vulnerabilities addressed across all 23 previous big releases put together.
In April, Mozilla announced that it discovered 271 flaws in Firefox during a single bug hunting sprint, thanks to the use of Anthropic’s Mythos model.
The Numbers Keep Growing
The head of research at Empirical Security and founder of RogoLabs, Jerry Gamblin, spoke to the newsletter about the CVE analysis project cve.icu. He said that there have been a stunning 66,401 CVEs recorded as of Wednesday this week.
By September 16 last year, cve.icu had logged a total of 33,512 CVEs — almost half the current total. For all of 2022, the year OpenAI launched its first version of ChatGPT, cve.icu recorded 25,000 CVEs.
There are many faults to be found, and the issue at hand is whether uncovering them does more good than harm.
Discovery Scales With Compute
The surge is real, according to Gamblin, who argues that a larger figure is not necessarily the problem. He pushed back against the idea that a bigger number is itself the harm when speaking to the newsletter, saying: “More CVEs is not more vulnerability. It’s more known vulnerability, which is mostly the system working.”
He cautions that correcting them presents its own challenge. “Discovery scales with compute. Remediation scales with people—and people are the part you can’t buy more of in a quarter.”
There is worry that developers will fall behind when it comes to fixing security flaws. People who use software that cannot be patched quickly could find themselves exposed. At the same time, a growing number of attacks could be driven by more attackers finding new vulnerabilities for themselves with the help of artificial intelligence.
The National Cyber Security Center in Britain makes its position clear: “Just finding vulnerabilities does nothing to improve your security.”
Defenders Are Using AI Too
The newsletter spoke with Matthew Olney, who leads threat intelligence at Cisco Systems, and he said there is at least a tenuous balance between AI speeding up bug discovery and AI helping those on the defensive side. “Actors, just like industry, are trying to figure out, ‘where do I use AI?'”
Many researchers think the spike and other effects of AI on cybersecurity will either be catastrophic or merely amplify existing problems and challenges. Some have noted that slow patch adoption and a general lack of investment in cybersecurity already gave attackers numerous advantages prior to the arrival of AI, leading to hacking disasters.
As vulnerability discovery counts keep rising, and the talk has moved beyond theory into practical matters, the two sides have appeared to draw nearer to each other.
What This Means for Users
The newsletter suggests that an AI slowdown, whether through regulation or an industry agreement, might avert an AI-driven mass extermination of humanity. Yet such a slowdown would do nothing to halt the wave of vulnerabilities unleashed by today’s AI systems.
| Company | CVEs Shipped |
|---|---|
| Microsoft | 974 this month |
| Oracle | 1,448 in July |
| Google Chrome | 1,072 in June |
| Mozilla Firefox | 271 via Anthropic’s Mythos |
The contrast reveals just how fast the figures have shifted: firms now ship thousands of patches within months that once produced only hundreds.
What makes this issue hard is the cost difference between identifying a flaw and correcting it. Finding errors is inexpensive, while fixing them is costly, and there simply aren’t enough skilled workers to handle all the necessary repairs.
The Uneasy Truth
The Kernel newsletter documents a true acceleration in discovered software vulnerabilities. The record-breaking patch counts are real. The numbers themselves attest to this. The warning from Gamblin about remediation scaling with people is also real.
The unease stems from the space between spotting a problem and fixing it. Discovery is simple. Response is difficult. There is no sign that AI will narrow that distance any time soon.
The newsletter argues that the surge in vulnerabilities is already underway. The real issue is whether the field can match the speed — and whether there is any way to gauge that progress at all.
Source material: “Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening,” WIRED.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

