AI is finding vulnerabilities faster, whether the industry is ready or not. Mitigation is the only way for the defender to regain control.
Doug Britton
The cybersecurity industry is betting big on artificial intelligence. The idea is that if AI can be used to find vulnerabilities faster, software will be more secure and organizations can stay ahead of malicious actors.
However, in most organizations, finding vulnerabilities is not something that hinders security teams. It’s a repair. Teams are already burdened with more common vulnerabilities and exposures (CVEs) than they can prioritize and address. According to Verizon’s 2026 Data Breach Investigations Report, one of the most common breach vectors is the exploitation of known vulnerabilities. Although vulnerabilities exist, organizations often delay remediating them in a timely manner because they are difficult and resource-intensive to patch.
We are now seeing AI models dramatically accelerate vulnerability discovery, placing an unrelenting strain on already overwhelmed cybersecurity teams.
In April, Anthropic announced Claude Mythos Preview, an AI model that has discovered thousands of bugs in major operating systems and browsers, many of which went undetected for decades.
Following the announcement, the US government warned that what would happen next would be an “avalanche” of vulnerabilities. These new vulnerabilities simply pile on top of existing vulnerabilities.
The backlog will continue to grow as the time between discovery and remediation widens. The pool of exploitable vulnerabilities available to attackers will continue to grow.
This is a dynamic missing from much of the current discussion of AI in security. The industry is investing heavily in finding problems faster, without investing commensurate with the ability to solve them. This asymmetry has consequences.
The growing number of known but unpatched vulnerabilities presents an opportunity for adversaries to exploit defenders in perpetual triage. In these situations, increased visibility does not translate into improved security. That puts added pressure on a team that is already at its limits.
The industry’s response to date has focused on faster scanning, better detection, and smarter prioritization. While these are all important steps, the reality is that remediation does not scale at the same rate as discovery. Addressing this gap is the real problem and the best way to ensure your cyber defenses are not overwhelmed.
This leaves one avenue that has not received enough attention. It’s about mitigating the impact of vulnerabilities that can’t be fixed right away. This is not a replacement for the patch, but a complement to it. By limiting the exploitability of an entire vulnerability class, organizations can contain risk even if remediation takes weeks or months.
This model already exists in industrial systems, embedded platforms, and environments where patching is difficult or impossible. For example, Microsoft’s Security Response Center, which prioritizes all reported Microsoft security vulnerabilities, found that approximately 70% of vulnerabilities assigned CVEs each year are memory safety issues. In addition, the Google Security Blog regularly publishes articles on memory safety efforts, and at one time Android memory safety vulnerabilities accounted for 76% of the time.
AI is finding vulnerabilities faster, whether the industry is ready or not. Mitigation is the only way for the defender to regain control.
Doug Britton is Executive Vice President and Chief Strategy Officer at RunSafe Security.
Copyright © 2026 Federal News Network. Unauthorized reproduction is prohibited. This website is not directed to users within the European Economic Area.
