The economics of software vulnerabilities are shifting under the feet of US technology companies. Three recent disclosures show artificial intelligence accelerating the discovery of flaws at the same time it is being used to exploit them, while the vendors caught in the middle struggle to patch fast enough. The common thread is not a single bug or product, but a widening gap between how quickly vulnerabilities surface and how quickly organizations can close them.
Discovery Is Outpacing Disclosure
Google Threat Intelligence Group reported that monthly software vulnerability disclosures doubled between January and August, according to an account of the report published by SiliconANGLE. August's count reached 10,740. That is not a rounding error or a seasonal spike; it is a structural change in the volume of flaws entering public view. GTIG attributed part of the shift to artificial intelligence, noting that AI agents are changing which flaws get discovered. Half of the vulnerabilities turned up by AI agents allow remote code execution, the report found. That detail matters more than the headline number. Remote code execution flaws are the ones that let an attacker run their own code on a target system, which is the difference between a nuisance and a breach. If AI-driven discovery is disproportionately surfacing that class of bug, the defensive burden is not just larger, it is heavier per finding.
The Supply Chain Learns the Hard Way
The Dutch Institute for Vulnerability Disclosure said its own network was breached through a chain of two zero-day vulnerabilities in Zammad, an open-source ticketing system, as BleepingComputer reported. A vulnerability disclosure organization, staffed by people whose job is to find and report flaws, was compromised by flaws it did not yet know about. The detail that makes this more than an ironic anecdote is the AI-driven nature of the breach. An organization built around human expertise in vulnerability handling was undone by an attack that leveraged automation to exploit unknown flaws. For US companies, the lesson is not that open-source tools are uniquely dangerous. It is that the defensive advantage once held by knowledgeable operators is eroding when the attacker can scan, chain, and exploit at machine speed.
Patching Urgency Meets Patch Fatigue
TeamViewer urged customers to immediately patch a set of high-severity vulnerabilities affecting its client and host software, BleepingComputer reported. The language was blunt: patch as soon as possible. That kind of advisory is becoming routine, and routine is the problem. When every week brings another urgent patch for remote access software, the tools that employees and IT departments rely on to reach systems remotely, the organizational response tends to degrade. Teams triage, defer, and sometimes miss. The Zammad chain shows what happens when a flaw is not patched before an attacker finds it. The TeamViewer advisory shows the other side: a vendor trying to move faster than the exploit economy. US businesses run enormous fleets of remote access and ticketing software, much of it deeply integrated into support and operations workflows. A high-severity flaw in that layer is not a peripheral risk; it is a direct path into the corporate network.



