Safety2 min read

AI Is Finding Software Bugs Faster Than Companies Can Fix Them

June 10, 2026Synthesized from 1 source: WIRED

AI tools are flooding security programs with more vulnerability reports than ever before, while the same technology is giving attackers new abilities to find and exploit those weaknesses, leaving most organizations caught between an accelerating discovery machine and a very human-paced repair process.

Software has always had flaws. What has changed is the speed at which those flaws are being found, and by whom.

AI tools can scan entire codebases in minutes, flagging issues that would take a skilled human days or weeks to spot. Anthropic's Claude found 22 vulnerabilities in Firefox's browser code in just two weeks, including 14 that Mozilla rated as high severity and that human reviewers had missed entirely. That kind of output, at that kind of speed, is now becoming routine.

The programs that businesses have relied on to stay ahead of attackers, where outside security researchers get paid to find and report vulnerabilities before they are exploited, are struggling to cope. HackerOne's Internet Bug Bounty program has paused new submissions because the balance between what is being found and what can actually be fixed has broken down. Google paid a record $17.1 million in bug bounty rewards in 2025 and is now overhauling its programs to focus on quality over volume, phasing out some reward categories entirely after being overwhelmed by AI-generated reports. The open-source tool Curl stopped its program in January for the same reason, though it has since reported that submission quality has improved as AI models have gotten better.

For most businesses, the harder issue sits on the attacker side. IBM's 2026 threat intelligence data shows that exploiting software vulnerabilities is now the leading cause of cyber incidents, accounting for 40% of all attacks tracked in 2025. Attacks that began by targeting public-facing applications rose 44% in a single year. AI is not just helping defenders find bugs faster: it is helping attackers find them faster too, and often before a patch exists.

One AI system called XBOW became the top-ranked vulnerability hunter on HackerOne in 2025, surpassing every human researcher on the platform. The median time between a vulnerability being disclosed and an attacker building a working exploit dropped from 771 days in 2018 to single-digit hours by 2024. By 2025, the majority of working exploits were being built before the vulnerability was even publicly disclosed.

For businesses outside the technology sector, this matters in a specific and practical way. Most organizations run software they did not build: accounting platforms, logistics tools, HR systems, cloud services. When vulnerabilities in those tools are found and exploited faster than vendors can patch them, the risk falls on every customer, not just the software maker. The supply chain exposure is real: large compromises tied to third-party suppliers or services have nearly quadrupled since 2020, according to IBM.

There are two things worth doing now, regardless of industry. First, stop treating patching as a periodic event. The window between a flaw being discovered and it being used against someone is now too short for quarterly or annual patch cycles to offer much protection. Organizations that cannot patch continuously should at least understand which of their software systems are highest-risk and prioritize those. Second, ask every software vendor you rely on what their vulnerability disclosure and patching process looks like. Vendors who can show a fast, structured process are materially lower-risk than those who cannot.

The deeper problem is structural. Security experts who work on this daily are pointing to the same conclusion: finding bugs is no longer the hard part. The hard part is fixing them at the pace they are now being discovered, and that requires people, processes, and institutional will that most organizations have not yet built.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable