Researchers and security leaders at Black Hat USA 2026 warned that AI is sharply increasing the rate of software vulnerability discovery, raising concerns that defenders may struggle to keep pace with disclosure and remediation. The discussion highlighted research from Arizona State University led by Yan Shoshitaishvili, which found that AI-assisted workflows and training on characteristics of previously identified bugs significantly boosted the number of flaws uncovered.
The surge in findings is colliding with growing defensive pressure, including high recent Microsoft Patch Tuesday CVE volumes and the U.S. government's new Gold Eagle initiative to coordinate vulnerability research, mitigation, and fixes. Speakers cautioned that discovery may now be outpacing responsible disclosure and patching capacity, increasing the risk of exposed systems and hurried fixes, while also arguing that sustained AI-driven research could eventually reduce long-standing bug backlogs and improve software security overall.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
According to the article, July brought 622 vulnerabilities, including zero-days under active exploitation.
The article states that June included 571 CVEs overall, including 208 direct Microsoft CVEs, underscoring the scale of vulnerability handling demands.
A June Washington Post article cited by the source reported that Anthropic's Claude Mythos discovered 479 vulnerabilities in the Linux kernel.
The article says Microsoft's May Patch Tuesday included 118 CVEs, continuing the pattern of high vulnerability remediation volume.
The article states that Microsoft's April Patch Tuesday included 169 CVEs, cited as part of mounting defensive pressure from rising vulnerability volumes.
At Black Hat USA 2026, a keynote highlighted Arizona State University research led by Yan Shoshitaishvili showing that AI workflows and training on prior vulnerability characteristics sharply increased software flaw discovery.
After training the GPT models on properties of previously known vulnerabilities, the Arizona State University team reported discovering approximately 1,000 vulnerabilities.
Using Claude Mythos's Linux kernel results as a benchmark, Arizona State University researchers integrated similar workflows into three GPT models and increased discovery to around 600 vulnerabilities.
The article says the U.S. government created a vulnerability clearing house named Gold Eagle to coordinate vulnerability discovery, mitigation, and fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.