NextFin News - AI is no longer just a faster way to sort alerts. It is becoming a better way to find software flaws, and that changes the economics of cybersecurity because the same capability that helps defenders uncover bugs sooner can also help attackers compress the time from discovery to exploitation.
A recent security research release made that shift concrete. It said a frontier model found a 27-year-old vulnerability in OpenBSD and a 16-year-old flaw in FFmpeg, both in mature codebases that had already been through years of testing and hardening. The release said the issues were patched after disclosure, and it showed the model reproducing vulnerabilities on the CyberGym benchmark at 83.1%, versus 66.6% for the next-best model in the comparison. That is not a marginal product update. It suggests that machine assistance is moving from support role to discovery engine.
The deeper implication is that vulnerability hunting is changing from a labor-constrained process into a compute- and model-quality-constrained one. For years, the security industry assumed the bottleneck was human review, manual fuzzing and the limited number of specialists who could inspect code at scale. AI changes that bottleneck by reading code, tracing paths and prioritizing likely weaknesses more quickly than many existing workflows can. That can lower the cost of defense. It can also lower the cost of offense.
The backdrop matters. The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog continues to add new entries, including Joomlack Page Builder, SonicWall SMA1000 appliances and Fortinet FortiSandbox in July 2026, while the National Vulnerability Database remains a large and continuously updated registry. The point is not that every entry is directly related to AI. The point is that the inventory of flaws that matter in practice is still large, and the introduction of better discovery tools arrives into an already crowded threat environment.
This is why the most useful question is not whether AI can find bugs. It can. The real question is whether AI helps defenders keep the patch pipeline ahead of a capability that adversaries can use just as well. On that question, the evidence points to a structural shift rather than a temporary spike. When a model can expose flaws that survived 16 years and 27 years in mature software, the old assumption that the long tail of code is already “known good” no longer holds. The floor has moved.
Why This Is a Structural Change, Not a Temporary Cycle
The short answer is that the age of the bugs matters more than the novelty of the tool. A cyclical story would say AI is generating a burst of findings that will fade as the obvious issues are cleared out. A structural story says the discovery engine itself has improved in a way that permanently changes what can be found, how fast it can be found and how quickly it can be acted on.
The OpenBSD and FFmpeg examples support the structural view because both systems represent code that had already endured long exposure to testing, patching and scrutiny. A 27-year-old vulnerability in a hardened operating system is not just an old bug. It is evidence that prior review methods still left material blind spots. A 16-year-old flaw in a ubiquitous media library is similarly important because it shows how a weakness can persist across many downstream products even when the upstream code has been widely deployed for years.
The benchmark result sharpens the point. A CyberGym reproduction score of 83.1% versus 66.6% does not just indicate better performance; it indicates a wider gap between what the new model can surface and what the previous state of the art could reliably recover. In a field where the difference between a missed bug and a found bug can determine whether a company patches before or after exploitation, that spread matters.
The mechanism is straightforward. AI compresses the reading, reasoning and prioritization steps in vulnerability management. That raises the throughput of security teams, but it also raises the throughput of adversaries who use the same tools. The second-order effect is more important than the first-order one: if discovery gets cheaper faster than patching gets faster, then the window between disclosure and weaponization narrows. That is where the real risk sits.
It is also why this story is more structural than cyclical. Cycles mean the system self-corrects as inventories normalize and tools become less novel. Here, the opposite may happen. As more organizations adopt AI-assisted scanning, more flaws will be surfaced, which will increase the remediation burden, which will in turn increase demand for automated triage, exposure management and code-level defenses. That feedback loop does not unwind on its own.
Security leaders are already treating it that way. In a letter signed by more than 50 security leaders, they argued that curbs on advanced security models would limit the industry’s ability to find and fix software flaws at a time when other AI tools are making it easier for hackers to exploit vulnerabilities. That is effectively a confession that the industry sees a capability race, not a one-off product debate.
“These models need to be in the hands of open source owners and defenders everywhere to find and fix these vulnerabilities before attackers get access. Perhaps even more important: everyone needs to prepare for AI-assisted attackers. There will be more attacks, faster attacks, and more sophisticated attacks.”
The quote matters because it captures the counter-thesis at its strongest. The optimistic view is that AI makes defenders dramatically more effective and therefore reduces net risk. That is plausible. If a model finds flaws before attackers do and maintainers patch them quickly, security improves. But that argument only wins if remediation keeps pace with discovery and if organizations can absorb the extra workflow without lengthening exposure.
That condition is not guaranteed. In internet-facing software, in open-source dependencies and in fragmented enterprise estates, patching is rarely instantaneous. Attackers need only one usable path. Defenders need to close many. That asymmetry is why the offensive side of AI can outrun the defensive side even if both improve.
The falsifying signal for the structural-risk view is concrete: if AI-assisted discovery rises but the rate of exploited-in-the-wild incidents and the average disclosure-to-exploit window both fall for a sustained period, then the defensive benefit is winning. If those metrics do not improve, or if they worsen, the case that AI is mostly helping defense starts to weaken.
What the Market Is Pricing, and What It May Be Missing
The market has already absorbed the idea that AI boosts cybersecurity spending. What it may not have fully priced is that AI also raises the intensity of the threat environment. Those two forces point in different directions for different companies.
Vendors with strong vulnerability management, exposure management, identity security and automated remediation products can benefit from both sides of the trade. More discoveries mean more demand for tools that help teams rank risk, validate patches and reduce manual work. But enterprises with slow release cycles, sprawling dependencies and weak asset visibility are more exposed because the discovery flood increases their remediation backlog.
The public vulnerability pipeline suggests that backlog remains meaningful. CISA’s Known Exploited Vulnerabilities catalog continues to grow, and the NVD remains a vast, continuously updated repository. That does not prove a record in any one month, and it does not prove that AI is responsible for every new finding. It does show that the world is not running short of exploitable software. In that environment, anything that improves triage has value, but anything that improves attacker efficiency has cost.
The strongest counter-thesis is that AI-assisted vulnerability discovery will ultimately make software safer, not more dangerous, because it will find latent flaws before they are weaponized. That is not a straw man. It is the logic behind a lot of security investment and the reason companies want these tools in the first place. The recent research release itself supports that logic by saying the vulnerabilities it found were patched.
But the answer depends on timing and operating discipline. If the patch arrives before exploitation, the tool is defensive. If the exploit comes first, the tool has expanded the attacker’s opportunity set. The market is therefore not just pricing AI as a productivity upgrade; it is implicitly pricing an arms race over time. The key question is not whether vulnerabilities can be found. It is whether they can be neutralized faster than they can be used.
That second-order question matters for spending too. Companies are likely to shift more budget toward tools that shorten mean time to detect, triage and patch, as well as toward runtime monitoring and identity controls that can blunt the impact of a missed flaw. The benefit accrues to vendors that can sit inside the development and response workflow. The exposure falls on firms that rely on manual review and long maintenance cycles.
This is also why the current phase looks structural across the tech sector. The old baseline assumed that security teams could not inspect enough code to keep up. AI changes the ceiling on inspection, but it also changes the ceiling on offense. A structural change does not require every company to be affected in the same way. It only requires the operating assumptions to change for everyone. That is what is happening here.
Short term, the sentiment effect should favor cybersecurity names tied to automation, exposure management and developer-security tooling. Medium term, the winners should be the companies that reduce the patch backlog fastest and can prove lower exploitability in production. Long term, the biggest gap may be between firms that redesign their development pipelines around continuous vulnerability discovery and firms that keep treating security as a downstream audit function.
Base case: AI keeps widening the discovery funnel, which lifts demand for security software and forces faster remediation across the sector. Upside case: defenders turn AI into a workflow advantage and materially shrink time-to-patch, lowering the real-world exploit rate. Downside case: attackers use the same capabilities more quickly than enterprises can respond, compressing the disclosure-to-exploit window and leaving the most exposed software categories vulnerable for longer.
The next things to watch are straightforward: whether more major vendors publicly disclose AI-assisted bug finds, whether the cadence of exploited-in-the-wild incidents changes, and whether organizations can measurably shorten patch cycles in the next several quarters. If exploit windows keep tightening despite the new tools, the story will have moved from productivity improvement to a deeper security regime change.
For now, the clearest reading is that AI has made bug hunting industrial. The uncomfortable part is that industrialization cuts both ways: the same machine that finds the flaw first can also help someone break it faster.

