The vulnerability economy is being reshaped by artificial intelligence on both sides of the disclosure line. Attackers are using AI to find and exploit flaws faster, while the pipelines meant to receive, triage, and fix those flaws are buckling under machine-generated volume. Three recent stories - a mass patch from Kiteworks, Microsoft's assessment of the attacker-defender gap, and Google's suspension of an open-source bounty program - are not separate incidents. They are the same structural shift seen from three angles.
Attackers Are Compounding Their Advantage
The clearest statement of the problem comes from Microsoft, which said threat actors are benefiting from artificial intelligence faster than defenders. As BleepingComputer reported, the company points to attackers using AI to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. That ordering matters. Discovery is the front of the chain, and if AI shortens the time between a flaw existing and a flaw being found, every downstream stage - triage, disclosure, patch development, deployment - is placed under compression it was not designed for. Microsoft's framing is not that defenders lack tools. It is that the tempo has changed, and the advantage currently sits with the side that only needs to find one usable path in.
The Patch Load Is Getting Heavier
Kiteworks offered a concrete illustration of what that pressure looks like at the vendor end. As BleepingComputer reported, the secure file-sharing company released security updates addressing 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway security solution. A triple-digit patch count in a single release is not unusual in modern software, but the presence of a maximum-severity issue inside a security product is the sharper detail. Security solutions sit in positions of trust, often directly in the path of email and file traffic that enterprises assume has been inspected. When a flaw of that severity lands in that class of product, the remediation window for every customer is effectively immediate.
Disclosure Pipelines Are Being Flooded
The intake side of the system is under a different kind of strain. Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program, according to Tom's Hardware, over an influx of invalid AI-driven reports. This is the mirror image of the attacker problem. The same generative capability that helps a researcher draft a plausible-looking report also lets someone produce submissions that consume reviewer time without describing a real defect. For a program built on open-source volunteer and maintainer labor, that is an existential throughput problem rather than a nuisance. Suspending submissions is a blunt response, but it is a response to volume, not to quality alone.




