Security teams are racing to issue patches ahead of a projected wave of attacks that leverage large language models. An open letter signed by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and a hundred other entities warned that the window for remediation is shrinking as AI-enabled exploits become more common. Companies have responded by dramatically increasing the volume of monthly updates.
Two months ago Microsoft released a patch addressing a record 570 flaws, and the following month that figure rose to roughly 620. Together with similar spikes at Google and other firms, the industry has logged unprecedented vulnerability counts. To date this year Microsoft has remedied 2,760 issues, more than double the total fixed in the prior year, suggesting an accelerating trend.
According to Zero Day Initiative researcher Dustin Childs, the most recent Tuesday update contains 972 patched vulnerabilities, a figure that climbs to 997 when fixes ported from Chromium for the Edge browser are included. Of the newly disclosed issues, 112 carry a critical severity rating while the remainder are classified as important. Childs notes that many of these bugs are wormable, meaning they can propagate without user interaction.
Childs describes the surge in monthly patch counts as the ‘new normal’ for the sector, warning that the cumulative effect of AI-assisted exploits could be substantial. He halted his tally after encountering twenty wormable flaws, emphasizing that such vulnerabilities can spread autonomously across networks and trigger chain reactions that are difficult to contain. The potential for rapid, self-propagating attacks underscores the urgency of swift remediation.
The rise of large language model-driven vulnerability hunting has sparked debate over its cost-effectiveness and false-positive rates. Critics argue that the expense of deploying AI tools may outweigh benefits and question whether firms are motivated by the need to justify billions spent on developing the same models they now use for security. Skeptics also point to the risk of over-reliance on automated discovery.
Proponents counter that the sheer volume of severe bugs uncovered by AI-assisted scans validates the approach. Mozilla reported in May that its team, using the Mythos system, identified a record 271 vulnerabilities with minimal false positives. While the long-term impact of AI-driven bug hunting remains to be measured, experts agree that maintaining an open, inquisitive stance will be essential as the field evolves.