AI Is Reshaping Vulnerability Work on Both Sides
Article

AI Is Reshaping Vulnerability Work on Both Sides

Three recent stories show artificial intelligence simultaneously accelerating attacker discovery, straining disclosure pipelines, and forcing vendors into mass patching.

HemeswariOctober 3, 20264 min read

Photo: BleepingComputer

The vulnerability economy is being reshaped by artificial intelligence on both sides of the disclosure line. Attackers are using AI to find and exploit flaws faster, while the pipelines meant to receive, triage, and fix those flaws are buckling under machine-generated volume. Three recent stories - a mass patch from Kiteworks, Microsoft's assessment of the attacker-defender gap, and Google's suspension of an open-source bounty program - are not separate incidents. They are the same structural shift seen from three angles.

Attackers Are Compounding Their Advantage

The clearest statement of the problem comes from Microsoft, which said threat actors are benefiting from artificial intelligence faster than defenders. As BleepingComputer reported, the company points to attackers using AI to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. That ordering matters. Discovery is the front of the chain, and if AI shortens the time between a flaw existing and a flaw being found, every downstream stage - triage, disclosure, patch development, deployment - is placed under compression it was not designed for. Microsoft's framing is not that defenders lack tools. It is that the tempo has changed, and the advantage currently sits with the side that only needs to find one usable path in.

The Patch Load Is Getting Heavier

Kiteworks offered a concrete illustration of what that pressure looks like at the vendor end. As BleepingComputer reported, the secure file-sharing company released security updates addressing 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway security solution. A triple-digit patch count in a single release is not unusual in modern software, but the presence of a maximum-severity issue inside a security product is the sharper detail. Security solutions sit in positions of trust, often directly in the path of email and file traffic that enterprises assume has been inspected. When a flaw of that severity lands in that class of product, the remediation window for every customer is effectively immediate.

Disclosure Pipelines Are Being Flooded

The intake side of the system is under a different kind of strain. Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program, according to Tom's Hardware, over an influx of invalid AI-driven reports. This is the mirror image of the attacker problem. The same generative capability that helps a researcher draft a plausible-looking report also lets someone produce submissions that consume reviewer time without describing a real defect. For a program built on open-source volunteer and maintainer labor, that is an existential throughput problem rather than a nuisance. Suspending submissions is a blunt response, but it is a response to volume, not to quality alone.

Why This Hits US Companies and Consumers

The practical consequences for US technology companies run in two directions. First, patch cadence: vendors like Kiteworks are shipping large update bundles that customers must evaluate and deploy, and a max-severity flaw in a security product compresses that evaluation to near zero. Enterprises that have stretched their patching cycles to manage operational risk now face releases that cannot safely wait. Second, disclosure friction: when a major program like Google's OSS VRP pauses submissions, legitimate researchers lose a channel, and the open-source components that underpin a large share of US commercial software lose a source of scrutiny. For US consumers, the chain is shorter than it looks. The email gateways and file-sharing platforms that carry their data are the same products being patched in bulk, and the open-source libraries inside consumer apps are the same ones whose bug reports are now harder to file.

The Asymmetry Is Structural, Not Temporary

The temptation is to read Microsoft's assessment as a temporary lead that defenders will close with their own AI adoption. The three stories together suggest something less symmetrical. Attackers need one viable finding; defenders must process every finding, valid or not. That ratio is what Google's experience demonstrates: a flood of invalid submissions degrades a program even when no real vulnerability is involved. It is also what Kiteworks demonstrates: a single release carrying 126 vulnerabilities, including one at maximum severity, demands attention across an entire customer base. AI raises the rate on both sides, but the defender's workload scales with volume while the attacker's scales with success.

What to Watch

Three signals are worth tracking against this pattern. Whether Microsoft's assessment of the attacker advantage prompts changes in how defenders prioritize discovery, since the company identified discovery as the stage where AI is helping attackers most. Whether other vendors follow Kiteworks with comparably large update bundles, and whether max-severity flaws continue to appear inside security products themselves. And whether Google's suspension of OSS VRP submissions remains in place or is replaced by a filtering mechanism, since the duration and design of that response will indicate whether the invalid-report problem is treatable or structural. None of these is a prediction. They are the places where the compression described above will show up first.

More on this beat: Cybersecurity on TechManNews.

#vulnerabilities#artificial intelligence#patch management#bug bounty#open source#disclosure

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.