AI Is Rewriting Vulnerability Economics
Article

AI Is Rewriting Vulnerability Economics

Three recent disclosures show AI both finding and exploiting flaws, forcing US firms to rethink patch urgency and exposure.

JaysuryaOctober 1, 20264 min read

Photo: BleepingComputer

The economics of software vulnerabilities are shifting under the feet of US technology companies. Three recent disclosures show artificial intelligence accelerating the discovery of flaws at the same time it is being used to exploit them, while the vendors caught in the middle struggle to patch fast enough. The common thread is not a single bug or product, but a widening gap between how quickly vulnerabilities surface and how quickly organizations can close them.

Discovery Is Outpacing Disclosure

Google Threat Intelligence Group reported that monthly software vulnerability disclosures doubled between January and August, according to an account of the report published by SiliconANGLE. August's count reached 10,740. That is not a rounding error or a seasonal spike; it is a structural change in the volume of flaws entering public view. GTIG attributed part of the shift to artificial intelligence, noting that AI agents are changing which flaws get discovered. Half of the vulnerabilities turned up by AI agents allow remote code execution, the report found. That detail matters more than the headline number. Remote code execution flaws are the ones that let an attacker run their own code on a target system, which is the difference between a nuisance and a breach. If AI-driven discovery is disproportionately surfacing that class of bug, the defensive burden is not just larger, it is heavier per finding.

The Supply Chain Learns the Hard Way

The Dutch Institute for Vulnerability Disclosure said its own network was breached through a chain of two zero-day vulnerabilities in Zammad, an open-source ticketing system, as BleepingComputer reported. A vulnerability disclosure organization, staffed by people whose job is to find and report flaws, was compromised by flaws it did not yet know about. The detail that makes this more than an ironic anecdote is the AI-driven nature of the breach. An organization built around human expertise in vulnerability handling was undone by an attack that leveraged automation to exploit unknown flaws. For US companies, the lesson is not that open-source tools are uniquely dangerous. It is that the defensive advantage once held by knowledgeable operators is eroding when the attacker can scan, chain, and exploit at machine speed.

Patching Urgency Meets Patch Fatigue

TeamViewer urged customers to immediately patch a set of high-severity vulnerabilities affecting its client and host software, BleepingComputer reported. The language was blunt: patch as soon as possible. That kind of advisory is becoming routine, and routine is the problem. When every week brings another urgent patch for remote access software, the tools that employees and IT departments rely on to reach systems remotely, the organizational response tends to degrade. Teams triage, defer, and sometimes miss. The Zammad chain shows what happens when a flaw is not patched before an attacker finds it. The TeamViewer advisory shows the other side: a vendor trying to move faster than the exploit economy. US businesses run enormous fleets of remote access and ticketing software, much of it deeply integrated into support and operations workflows. A high-severity flaw in that layer is not a peripheral risk; it is a direct path into the corporate network.

What the Three Stories Share

Read together, the three disclosures describe a single pattern. AI is compressing the time between a flaw's creation and its discovery, and it is doing so across both proprietary and open-source software. The Zammad chain shows that zero-days are no longer the exclusive province of well-resourced attackers; AI-driven methods can find and chain them against a target that thought it was watching. The Google report shows that the overall supply of disclosed vulnerabilities is rising fast, with a high proportion of severe, remotely exploitable flaws. The TeamViewer advisory shows the downstream consequence: vendors issuing urgent patch guidance for software that sits at the center of enterprise connectivity. The common thread is speed. Discovery is speeding up, exploitation is speeding up, and the patch cycle is not.

The American Exposure

For US technology companies, the implications split into two categories. The first is direct exposure. Remote access and ticketing systems are not optional infrastructure in most American enterprises; they are the plumbing. A severe flaw in that plumbing, whether proprietary or open source, can be reached by attackers who no longer need to be the smartest people in the room. They need tooling that can find the flaw and a target that has not patched. The second is the disclosure burden itself. When monthly disclosures double and AI agents are surfacing remote code execution flaws at meaningful rates, security teams face a volume problem. Every disclosure requires triage, validation, and remediation, and the queue is growing faster than headcount. US consumers feel this indirectly but concretely: the companies holding their data are the ones struggling to keep up with the patch treadmill.

What to Watch

The material points to a few observable signals. Watch whether monthly vulnerability disclosure counts continue to climb or plateau after the January-to-August doubling that GTIG reported. Watch whether AI-discovered flaws keep skewing toward remote code execution, because that ratio determines how dangerous the volume increase really is. Watch how vendors of remote access and collaboration software communicate urgency, and whether customers respond faster than they did to previous advisories. And watch whether organizations that depend on open-source platforms like Zammad treat upstream flaws as a supply-chain risk rather than a background task. None of these are predictions. They are the places where the pattern described above will either hold or break.

The thread running through all three stories is straightforward. AI is changing which vulnerabilities get found, how quickly they get exploited, and how hard it is for defenders to keep pace. The companies that treat that as a temporary spike rather than a new baseline are the ones most likely to end up in the next disclosure.

Sources: BleepingComputer, SiliconANGLE.

More on this beat: Cybersecurity on TechManNews.

#vulnerabilities#artificial intelligence#zero-days#patching#supply chain#enterprise security

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.