AI automates vulnerability discovery, compressing exploit timelines to days
CERT-EU says the discovery window for software flaws has collapsed to negative seven days, meaning attacks now occur before patches are released.
Source: CERT-EU · August 6, 2026 at 3:47 PM · AI-assisted report
Single-source
KUALA LUMPUR, 6 AUGUST 2026 —
CERT-EU says the discovery window for software flaws has collapsed to negative seven days, meaning attacks now occur before patches are released.
Anthropic disclosed in April 2026 that its unreleased cybersecurity model, Claude Mythos Preview, autonomously found thousands of high- and critical-severity vulnerabilities, including previously unknown zero-days in decades-old code. Instead of a public release, Anthropic distributed the model through Project Glasswing to twelve launch partners and more than forty critical-infrastructure organisations for defensive work only.
HackerOne suspended new submissions to its Internet Bug Bounty programme that same month after AI-generated reports overwhelmed triage pipelines across the open-source ecosystem. The cURL project had already shut its bug bounty programme in January 2026 for similar reasons.
Google’s M-Trends 2026 report shows the mean time to exploit newly disclosed vulnerabilities fell to negative seven days, compared with 63 days in 2018.
The traditional discover-disclose-patch-deploy cycle was built for slower adversaries, CERT-EU says. That adversary no longer exists.
AI also opens the fastest defensive opportunity in years for organisations that embed analysis into development pipelines and software lifecycles. For commercial software, defenders can use the same tools to identify vulnerabilities, report them through coordinated disclosure, and build compensating controls while awaiting patches.
Anthropic benchmarked Claude Mythos Preview against Firefox 147’s JavaScript engine and generated working shell exploits 181 times out of several hundred attempts, compared with two successes by its predecessor, Claude Opus 4.6.
OpenAI’s GPT-5.3-Codex achieved 92% recall on seeded benchmark repositories and has evolved into Codex Security. The company later released GPT-5.4-Cyber, a defensive variant fine-tuned for binary reverse engineering and distributed through its expanded Trusted Access for Cyber programme to verified defenders.
Google DeepMind’s CodeMender autonomously identified and fixed 72 security issues in open-source projects. In January 2026, AISLE’s autonomous cyber reasoning system discovered all twelve CVEs in the OpenSSL coordinated release, plus historical vulnerabilities in one of the most heavily audited codebases.
Commercial tools are already proving themselves. In the first half of 2025, XBOW—an autonomous penetration testing platform—ranked first on HackerOne’s US leaderboard, submitting 1,060 vulnerability reports with 130 confirmed and resolved. Aikido Security’s AI-powered testing uncovered a high-severity cache deception flaw in SvelteKit applications deployed on Vercel with default configurations.
CVE-Bench, a real-world benchmark, initially recorded a 13% end-to-end exploitation rate for the best autonomous agents. Less than a year later, OpenAI reported its GPT-5.3-Codex model reached 90% on the same benchmark.
Even modest success rates tilt economics decisively toward AI because agents probe thousands of vectors per hour. Today’s models also chain findings into multi-step attack paths, a capability once reserved for elite specialists. This transforms isolated flaws into functional compromises.
Responsible use adds new burdens for defenders. Models hallucinate vulnerabilities, mischaracterise severity, or propose flawed patches. Validating every finding, reviewing proposed fixes, and testing before production remains labour-intensive even when discovery is instantaneous.
Operational costs are falling rapidly—each new generation cuts analysis costs by roughly an order of magnitude—yet the asymmetry persists. Attackers need only one working exploit and face no quality-control overhead, while defenders must triage every alert and remediate correctly.
CERT-EU warns that EU institutions, bodies, offices and agencies must reassess their exposure to internet-facing and third-party attack surfaces. The same AI systems that empower defenders can erode decades of security assumptions in months if ignored.
The window to act is shrinking. Those who integrate AI-augmented defensive workflows today will gain ground. Those who wait risk conceding the advantage entirely.
Related: Google
Malaysia Impact
Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.