Advanced AI systems are rapidly changing vulnerability research and exploit development, with new reports showing they can move beyond bug discovery into practical weaponization. Hacktron said OpenAI's GPT-5.6 Sol Ultra built a full Google Chrome exploit chain from public V8 patch commits, progressing from browser primitives to sandbox escape and native code execution, while researchers and industry observers reported that modern models can now triage crashes, identify root causes, assess exploitability, and propose fixes at scale. Mozilla reportedly used a frontier model to help uncover and patch 271 vulnerabilities in a single Firefox release, but maintainers have also faced a surge of duplicate AI-assisted submissions that strain existing workflows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
South Korea said it is developing a sovereign, security-focused AI model to provide domestic bug-finding capabilities and reduce reliance on foreign providers, citing prior U.S. restrictions on access to Anthropic's Mythos as a strategic warning.
Earlier in 2026, Mozilla used a frontier AI model to uncover and patch 271 vulnerabilities in a single Firefox release, illustrating AI's growing role in vulnerability research and remediation.
In May 2026, Linux kernel maintainers clarified vulnerability submission guidance after a surge of duplicate AI-assisted reports created operational strain for maintainers.
Hacktron reported that OpenAI's GPT-5.6 Sol Ultra autonomously constructed a complete Google Chrome exploit chain from public V8 security patch commits, culminating in code execution demonstrated by launching Calculator.
Anthropic said it is working with the EU AI Office and ENISA to improve cyber resilience and acknowledged that advanced AI is a dual-use technology amid European scrutiny of its cyber-capable models.
European lawmakers criticized Anthropic after the company sent technical employee Donny Greenberg instead of its requested head of public policy to a Brussels hearing on risks from advanced AI systems. The hearing examined Anthropic's cyber-capable Mythos and Fable models and their potential impact on critical infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
foreignaffairs.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourcenature.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcesemgrep.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.