AI-assisted vulnerability discovery is driving a sharp rise in open source security findings, straining the systems used to validate, disclose, and remediate flaws. Chainguard said its Athena coalition has already processed more than 20,000 AI-generated findings and helped produce over 2,000 patches across 500 projects, while Anthropic previously estimated its tooling uncovered 6,202 high- or critical-severity issues in more than 1,000 open source projects. The Linux Foundation has also launched Akrites, a coalition with a shared incident response capability and standardized coordinated disclosure process to help the ecosystem manage AI-enabled vulnerability discovery.
GitHub said the resulting volume has pushed its Advisory Database to record levels, with 1,560 reviewed advisories published in May 2026 and more than 6,000 advisory decisions processed per month from March through May, yet incoming private reports, repository advisories, and CVE requests still outpaced review capacity. The company said reviewed advisories remain human-validated and Dependabot alerts continue to function normally, but publication timelines for many new advisories have stretched from roughly a week to several weeks as analysts handle package disambiguation, version-range reconstruction, multi-ecosystem verification, and conflicting upstream data; GitHub is responding with improved triage, expanded backend capacity, automation, AI-assisted research tools, and guidance for researchers to submit more complete reports and request CVEs only when publication is intended.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reported that Anthropic's Claude Mythos Preview analyzed more than 23,000 open-source code paths over about nine weeks and generated 1,596 verified vulnerability reports, with external reviewers confirming a 90.8% true-positive rate on the subset examined. The report also quantified a remediation gap, saying verified discoveries were occurring at roughly 25 per day while credited repairs proceeded at about 1.5 per day.
GitHub responded to the advisory backlog by improving triage, expanding backend capacity, deploying AI-assisted research tools, increasing automation, and investing in documentation and training while keeping human validation in place.
In May 2026, GitHub published 1,560 reviewed advisories, its highest monthly total ever, but incoming reports still exceeded processing capacity and publication delays stretched from about a week to multiple weeks.
From March through May 2026, GitHub processed more than 6,000 advisory decisions per month as vulnerability reporting, disclosure, and CVE requests surged across the ecosystem.
Chainguard CEO Dan Lorenc warned that AI-driven vulnerability discovery in open source software would make the coming months difficult for defenders because advanced models are uncovering large volumes of previously unknown flaws in widely used dependencies.
Chainguard's Athena coalition, comprising roughly two dozen companies, had already processed more than 20,000 AI-generated open source vulnerability findings and produced over 2,000 patches across 500 projects.
The Linux Foundation launched Akrites, an industry coalition with a shared Security Incident Response Team and a standardized coordinated vulnerability disclosure process to help defend open source software against AI-enabled threats.
The Register reported that Anthropic previously used Mythos Preview to scan more than 1,000 open source projects and estimated it found 6,202 high- or critical-severity vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcehelpnetsecurity.com
Open sourcegithub.blog
Open sourcetheregister.com
Open sourcegithub.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.