AI-assisted bug hunting has pushed Microsoft’s patch count for September to 974 CVEs, a monthly record for the company. Oracle shipped 1,448 fixes in July. The same month a year earlier produced 309.
Google Chrome’s two June releases carried 1,072 fixes between them. Every patch from the prior 23 major releases combined does not match that total. Mozilla found 271 Firefox flaws in a single sprint using Anthropic’s Mythos model.
The running tally on cve.icu reached 66,401 by midweek. Jerry Gamblin, who runs the project and heads research at Empirical Security, puts the same date last year at 33,512. All of 2022 produced 25,000.
Gamblin pushes back on reading the surge as pure danger. In his framing, a larger CVE count means more flaws are known, not that more exist, and that is largely the disclosure system doing its job.
The arithmetic that worries researchers runs the other way. Finding flaws scales with compute. Fixing them scales with people, and the volunteers behind critical open source projects cannot be hired in bulk. Britain’s National Cyber Security Centre has said plainly that finding vulnerabilities does nothing for security on its own.
Cisco threat intelligence director Matthew Olney describes attackers and defenders as both still working out where AI fits, which keeps a tenuous balance for the moment. No slowdown would alter what has already been disclosed.