Skip to content
DomainFork
Markets
MarketsCompaniesCryptoCommoditiesIslamic FinanceEconomicsGreen
Money
MoneyProperty
Malaysia
MalaysiaPoliticsNews by stateASEANAsiaWorld
Society
Crime & CourtsHealthEducationHistoryCulture & HeritageTrending Online
Civic
Government & LeadershipCauses & CampaignsESGEntertainment
Tech
TechStartupsOpinion
Intelligence
Daily BriefingFilings & Disclosures
More
LiveIn depthWeekend issueGraphicsSentiment indexExplainersNews quizWatchlistSend us a tipHelp centre
Media
VideoAudioLifestyleSports
Breaking
F1 surge in hotel demand sees Sepang accommodation searches spike 1,600-fold ahead of 2026 race, Chuah Chee Hwai saysMalaysia vs Singapore: Where to watch, TV channel, live stream & kick-off time | FIFA ASEAN CupPalace defends BSKE postponement, prepared for Supreme Court challengeFirst flight, orphan creates sweet memory Sofia Nasir Oct 1 2026Tiny image sparks big backlash in Nikon photo contestIndonesia, Brunei, Malaysia, Singapore Propose Zapin Dance for UNESCO Cultural HeritageAustralia's Lynas makes takeover bid for Brazil's Meteoric ResourcesHow Marilyn Manson’s Alleged Abuse Scandals Fade Into Obscurity Despite His Anthemic StatusKim So-hyun and Choo Young-woo discuss their new drama Between Steps, their confidence in the director, and more[DECODED] No, this ‘handsome’ Duterte grandson is not realHan Sun Hwa and Chang Ryul's chance reunion leaves them curious about each other in “The Table: Day and Night”East of Eden Review: Florence Pugh Dominates Netflix’s Steinbeck AdaptationLIVE UPDATES: Impeachment trial of Vice President Sara Duterte12 New K-Dramas To Check Out In October 2026Live: FlyDubai suspends flights to and from Israel after pilot attack4 Challenging Moments For Lee Jun Hyuk And His Team In Episodes 5-6 Of “The Ordinary Jackpot”Opinion: Islamic finance can support AirAsia’s restructuringSoutheast Asia Climate Outlook Survey (2026): Measuring Public momentum in regional Climate transitionSmiles and respect as Fury and Joshua have their first face-off ahead of DecemberAfter a decade, the UN’s Antonio Guterres is stepping down. His legacy will be mixed, at best Simon Adams, Murdoch UniversityF1 surge in hotel demand sees Sepang accommodation searches spike 1,600-fold ahead of 2026 race, Chuah Chee Hwai saysMalaysia vs Singapore: Where to watch, TV channel, live stream & kick-off time | FIFA ASEAN CupPalace defends BSKE postponement, prepared for Supreme Court challengeFirst flight, orphan creates sweet memory Sofia Nasir Oct 1 2026Tiny image sparks big backlash in Nikon photo contestIndonesia, Brunei, Malaysia, Singapore Propose Zapin Dance for UNESCO Cultural HeritageAustralia's Lynas makes takeover bid for Brazil's Meteoric ResourcesHow Marilyn Manson’s Alleged Abuse Scandals Fade Into Obscurity Despite His Anthemic StatusKim So-hyun and Choo Young-woo discuss their new drama Between Steps, their confidence in the director, and more[DECODED] No, this ‘handsome’ Duterte grandson is not realHan Sun Hwa and Chang Ryul's chance reunion leaves them curious about each other in “The Table: Day and Night”East of Eden Review: Florence Pugh Dominates Netflix’s Steinbeck AdaptationLIVE UPDATES: Impeachment trial of Vice President Sara Duterte12 New K-Dramas To Check Out In October 2026Live: FlyDubai suspends flights to and from Israel after pilot attack4 Challenging Moments For Lee Jun Hyuk And His Team In Episodes 5-6 Of “The Ordinary Jackpot”Opinion: Islamic finance can support AirAsia’s restructuringSoutheast Asia Climate Outlook Survey (2026): Measuring Public momentum in regional Climate transitionSmiles and respect as Fury and Joshua have their first face-off ahead of DecemberAfter a decade, the UN’s Antonio Guterres is stepping down. His legacy will be mixed, at best Simon Adams, Murdoch University
Home/Tech
Tech

AI automates vulnerability discovery, compressing exploit timelines to days

CERT-EU says the discovery window for software flaws has collapsed to negative seven days, meaning attacks now occur before patches are released.

Source: CERT-EU · August 6, 2026 at 3:47 PM · AI-assisted report

Single-source
AI automates vulnerability discovery, compressing exploit timelines to days
DomainFork
Photo: osde8info via flickr (BY-SA)

KUALA LUMPUR, 6 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

CERT-EU says the discovery window for software flaws has collapsed to negative seven days, meaning attacks now occur before patches are released.

Anthropic disclosed in April 2026 that its unreleased cybersecurity model, Claude Mythos Preview, autonomously found thousands of high- and critical-severity vulnerabilities, including previously unknown zero-days in decades-old code. Instead of a public release, Anthropic distributed the model through Project Glasswing to twelve launch partners and more than forty critical-infrastructure organisations for defensive work only.

HackerOne suspended new submissions to its Internet Bug Bounty programme that same month after AI-generated reports overwhelmed triage pipelines across the open-source ecosystem. The cURL project had already shut its bug bounty programme in January 2026 for similar reasons.

Google’s M-Trends 2026 report shows the mean time to exploit newly disclosed vulnerabilities fell to negative seven days, compared with 63 days in 2018.

The traditional discover-disclose-patch-deploy cycle was built for slower adversaries, CERT-EU says. That adversary no longer exists.

AI also opens the fastest defensive opportunity in years for organisations that embed analysis into development pipelines and software lifecycles. For commercial software, defenders can use the same tools to identify vulnerabilities, report them through coordinated disclosure, and build compensating controls while awaiting patches.

Anthropic benchmarked Claude Mythos Preview against Firefox 147’s JavaScript engine and generated working shell exploits 181 times out of several hundred attempts, compared with two successes by its predecessor, Claude Opus 4.6.

OpenAI’s GPT-5.3-Codex achieved 92% recall on seeded benchmark repositories and has evolved into Codex Security. The company later released GPT-5.4-Cyber, a defensive variant fine-tuned for binary reverse engineering and distributed through its expanded Trusted Access for Cyber programme to verified defenders.

Google DeepMind’s CodeMender autonomously identified and fixed 72 security issues in open-source projects. In January 2026, AISLE’s autonomous cyber reasoning system discovered all twelve CVEs in the OpenSSL coordinated release, plus historical vulnerabilities in one of the most heavily audited codebases.

Commercial tools are already proving themselves. In the first half of 2025, XBOW—an autonomous penetration testing platform—ranked first on HackerOne’s US leaderboard, submitting 1,060 vulnerability reports with 130 confirmed and resolved. Aikido Security’s AI-powered testing uncovered a high-severity cache deception flaw in SvelteKit applications deployed on Vercel with default configurations.

CVE-Bench, a real-world benchmark, initially recorded a 13% end-to-end exploitation rate for the best autonomous agents. Less than a year later, OpenAI reported its GPT-5.3-Codex model reached 90% on the same benchmark.

Even modest success rates tilt economics decisively toward AI because agents probe thousands of vectors per hour. Today’s models also chain findings into multi-step attack paths, a capability once reserved for elite specialists. This transforms isolated flaws into functional compromises.

Responsible use adds new burdens for defenders. Models hallucinate vulnerabilities, mischaracterise severity, or propose flawed patches. Validating every finding, reviewing proposed fixes, and testing before production remains labour-intensive even when discovery is instantaneous.

Operational costs are falling rapidly—each new generation cuts analysis costs by roughly an order of magnitude—yet the asymmetry persists. Attackers need only one working exploit and face no quality-control overhead, while defenders must triage every alert and remediate correctly.

CERT-EU warns that EU institutions, bodies, offices and agencies must reassess their exposure to internet-facing and third-party attack surfaces. The same AI systems that empower defenders can erode decades of security assumptions in months if ignored.

The window to act is shrinking. Those who integrate AI-augmented defensive workflows today will gain ground. Those who wait risk conceding the advantage entirely.

Related: Google

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Reporting based on CERT-EU. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.

Suggested Reads

European Union cyber agency logs 60% jump in threat actors targeting institutions in 2025
European regulators urge unified AI risk controls for EU lenders and insurers
Pepper Labs launches 50,000 AI learning opportunities in Malaysia
Canadian businesses lag in AI adoption despite personal use by executives

Analyst Consensus — This Week

Neutral4.7/10AI sentiment across 679 stories · not investment advice

The Daily Brief · Free

Five market signals.
Five minutes. Every morning.

The morning briefing on Malaysia, ASEAN and the world: markets, policy and the stories that matter, before the opening bell.

  • ✓ KLCI, ringgit & sector movers
  • ✓ Analysis and what to watch
  • ✓ No spam — one email, unsubscribe anytime

Free daily market briefing. No spam, unsubscribe anytime.

DomainFork

Independent news from Malaysia and the world: markets, policy, every state, society and culture, in words and video.

Share

Sections

  • Malaysia
  • ASEAN
  • Asia
  • World
  • Tech
  • Markets

Intelligence

  • Daily Briefing
  • Filings & Disclosures
  • Video
  • Audio
  • Explainers & guides
  • Data, feeds & widgets
  • Documents to download
  • Live
  • Graphics
  • Sentiment index
  • In depth
  • Weekend issue
  • News quiz
  • Watchlist
  • Send us a tip
  • Help centre
  • Everything else

Company

  • About Us
  • Editorial Standards
  • Privacy Notice
  • Advertise
  • Contact the Desk

Disclaimer: DomainFork provides financial, economic, technology, and primary-source regulatory information for general education and research. AI summaries, sentiment scores, and market data are not investment advice. Consult a licensed professional before making financial decisions.

© 2026 DomainFork. All rights reserved.