Security teams are struggling to keep pace as AI accelerates vulnerability discovery, bug bounty submissions, and pentest findings faster than organizations can validate and remediate them. Microsoft said it paid more than $20 million to 562 researchers for 2,531 eligible reports across 15 bug bounty programs, attributing a surge in submissions in part to AI-assisted research, while Cloudflare said it now uses Anthropic’s Claude Sonnet to triage bug bounty reports, filtering duplicates and routing only higher-value submissions for human review. Survey data from Pentest-Tools.com similarly found that AI-generated findings are creating large validation backlogs, with practitioners citing false positives, duplicate reports, unexploitable issues, and even fabricated CVEs as persistent problems.
The operational gap is widening as attackers move faster than defenders can patch. Dataminr reported a median patch time of 43 days versus an average attacker breakout time of 29 minutes, and ZDNET described an ecosystem-wide surge in flaws across major vendors and open source projects, including high-volume bug discovery in Chrome, Apple platforms, and the Linux kernel. Open-source maintainers are also tightening disclosure processes under strain: GNOME reduced its disclosure deadline from 90 days to 30 days for new reports and said it would stop forwarding reports to projects that ban AI-generated content. Across the industry, the trend is pushing CISOs toward exploitability-based prioritization, stronger triage workflows, and selective automation rather than relying on raw finding volume alone.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks' Unit 42 disclosed an automated vulnerability discovery system called NOVA, saying it analyzed 3,915 open-source projects over two months and identified 14,090 validated vulnerabilities, including 5,421 supply-chain findings. Unit 42 said it is coordinating remediation with maintainers and clearinghouses including Lightwell and Akrites, but did not name affected projects or publish CVEs.
Elastic disclosed an AI-assisted triage system for its HackerOne bug bounty program that uses isolated analysis and reproduction environments, adversarial review, and mandatory human final decisions. The company said the system is already in production, was validated against 764 known-outcome reports with 85% agreement with human engineers, and costs about $2 per report to triage.
Starting August 1, 2026, GNOME reduced its disclosure deadline for new vulnerability reports from 90 days to 30 days. GNOME also said it would no longer forward vulnerability reports to projects that ban AI-generated content.
On July 20, 2026, Michael Catanzaro published a blog post announcing changes to GNOME's security bug handling process. The changes included shortening the disclosure deadline and altering how reports involving projects that ban AI-generated content are handled.
ZDNET says Microsoft's July 2026 Patch Tuesday included 570 patches and addressed three zero-days, underscoring the growing volume of fixes vendors are shipping.
ZDNET reports that 432 CVEs were reported in the Linux kernel over two days in July, illustrating the scale of vulnerability intake maintainers now face.
Microsoft said it paid more than $20 million to 562 researchers for 2,531 eligible reports submitted across 15 bug bounty programs between July 1, 2025, and June 30, 2026. The total included $2.3 million for Zero Day Quest and $800,000 for third-party and open source code initiatives.
ZDNET reports that Apple restricted the number of potentially dangerous software bugs researchers could submit to its internal security team in June 2026.
Pentest-Tools.com surveyed 158 security practitioners in June 2026 about AI-assisted penetration testing and validation workflows. The research found widespread use of AI tools alongside significant manual validation burdens.
In a May 2026 note on Patch Tuesday, Microsoft said AI is helping defenders discover more issues and that customers should expect a higher volume of security updates in each release.
Dataminr released its 2026 Mid-Year Threat Landscape Report, saying median patch time had risen to 43 days while average attacker breakout time was 29 minutes. The report also argued that CVSS alone is insufficient and recommended risk-based remediation prioritization.
In December 2025, Microsoft changed its bug bounty eligibility to an 'In Scope By Default' model for critical vulnerabilities with direct impact on Microsoft online services, including cases where the vulnerable code belonged to third-party or open-source components. Microsoft later said this expansion accounted for $800,000 in additional rewards.
ZDNET reported that Adobe updated its HermeticReader Chrome extension after an exploit chain involving three vulnerabilities exposed sensitive WhatsApp Web data, including chats, contacts, messages, profile name, and open conversation contents. The article also said the attack could be triggered by visiting a malicious web page and was later automated with DeepSeek through the Hermes Agent framework.
GNOME said Michael Catanzaro will step down from handling GNOME security work in November 2026 after six years in the role, and that the project is seeking a replacement.
Grant Bourzikas said Cloudflare has built more than 200 autonomous security agents and replaced almost all third-party security tools with internally developed applications. He cautioned that Cloudflare's build-versus-buy choices are specific to its own scale and requirements.
At a press lunch in Sydney, Cloudflare CSO Grant Bourzikas said the company uses Anthropic's Claude Sonnet to triage bug bounty submissions for about $58 per month. He said the workflow filters duplicates and identifies reports worth human review, replacing a fully manual process.
ZDNET reports that Google used AI agents to find and fix 1,072 Chrome security bugs over a 60-day period. The example was cited as evidence that AI-assisted discovery is accelerating vulnerability volume.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcezdnet.fr
Open sourcehelpnetsecurity.com
Open sourceitpro.com
Open sourceelastic.co
Open sourceitsecurityguru.org
Open sourceseclists.org
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.