Trending Topics

Ouroboros of cybersecurity is confirmed as the AI vulnerability disclosure cycle eats itself
Most people don’t follow vulnerability disclosures as closely as I do across all platforms and services. If they did, they would have noticed a remarkable thing happened this month: the volume of vulnerabilities being patched has gone through the roof.
This isn’t me being hyperbolic. Just take a look at the numbers:
Google Chrome fixed 127 vulnerabilities in the May 5 update, whereas the normal number might be anywhere between half a dozen and 30. As I type, I am still waiting for the number of vulnerabilities patched in the May 12 update to be confirmed.
The latest Microsoft Patch Tuesday rollout fixed 138 vulnerabilities, not including the 128 that were patched by the Edge browser. In April, there were 167 and 80 for Edge, but in March, there were just 79 and 9, respectively.
“The May 2026 Patch Tuesday is a milestone in the transition to ‘AI-speed’ security,” confirmed John Carberry, a Solution Sleuth with Xcape Inc, “with 138 vulnerabilities patched this month – the second-largest volume in history – and over 500 CVEs addressed since January, Microsoft is on pace to shatter the 2020 record of 1,245 annual patches.”
Sure, I understand that vulnerability discovery fluctuates, but the trend appears to be moving in a steep upward curve currently. And I think I know why: AI.
The rise of AI in vulnerability disclosure
More and more security researchers are employing AI-powered tools to help find bugs in code, and it’s working to a degree that perhaps we were not anticipating.
Cloud service provider Nextcloud emailed researchers in April stating that, due to the volume of low-quality AI reports, it has temporarily discontinued its bug bounty programme and “will not award any financial rewards for any submissions, regardless of severity”. Its hackerOne platform pages confirms that moving forward it will only accept issues that researchers have reproduced themselves, proven by screenshots, and will not accept submitted reports before reproducing the reported issue.
I mention the AI slop problem as it’s indicative of the surge in vulnerability hunting using such tools.
Which isn’t to say that AI hunting is a bad thing. If it uncovers real vulnerabilities then that’s good for everyone. Mozilla has conducted a Claude Mythos AI test against the Firefox 150 codebase, for example, and identified 400 vulnerabilities that it fixed in April alone.
Entering the Ouroboros phase
But there is a flip side to this, and that’s the speed at which vulnerabilities are being weaponised by attackers using AI as well.
“AI-accelerated vulnerability discovery changes both sides of the equation,” Rajeev Raghunarayan, Head of Go-To-Market at Averlon, told TechFinitive.
“The same capability that helps vendors find vulnerabilities faster helps attackers reverse-engineer patches faster. More CVEs per month means more simultaneous targets for weaponization, and the window between patch release and working exploit keeps compressing.”
“The offensive side is not waiting,” said Jacob Krell, Senior Director of Secure AI Solutions & Cybersecurity at Suzu Labs. “Google confirmed the first known AI developed zero-day exploit the same week, and Mandiant’s M-Trends 2026 report puts mean time to exploit at negative seven days, meaning exploitation is routinely outpacing disclosure.”
The problem being, of course, that discovery speed without remediation speed creates dangerous exposure rather than actual real-world protection.
As Carberry concluded: “We’ve officially reached the ‘Ouroboros’ phase of cybersecurity, where Microsoft’s AI finds flaws faster than its customers can patch them, effectively turning your IT department into a high-stakes unpaid intern for a machine.”
