AI-Driven Bug Discovery Overwhelms Software Vendors
Frontier AI models are finding vulnerabilities faster than companies can fix them, exposing fundamental weaknesses in secure development practices.
Software vendors face an unprecedented challenge as AI-powered vulnerability discovery outpaces their ability to remediate security flaws, according to multiple bug bounty platforms reporting dramatic increases in vulnerability submissions.
HackerOne saw vulnerability reports double year-over-year, while Bugcrowd and Trend Micro's Zero Day Initiative reported similar spikes. The surge has forced platforms to deploy AI-powered triage systems to manage the volume, fundamentally reshaping the economics of security research from a severity-focused model to one driven by volume.
Why it matters
This shift exposes a critical weakness in how software is developed and secured. For years, vendors could ship buggy code with limited accountability because human-driven code review and researcher attention were finite resources. AI has eliminated that constraint, forcing a long-overdue reckoning with secure-by-design principles. Organizations that haven't invested in robust security practices now face mounting backlogs of critical vulnerabilities with no place to hide.
The remediation bottleneck
The problem isn't just discovery velocity—it's what happens after bugs are found. HackerOne CEO Kara Sprague told Dark Reading that critical vulnerabilities sitting in backlogs have increased 30-fold over the past year, despite the platform achieving 50 percent improvement in mean time to remediation.
Katie Moussouris, CEO of Luta Security and a vulnerability research pioneer, argues the crisis reveals fundamental failures in secure development. "The bug bounty ecosystem has been suffering for a long time and AI just pointed out where the emperor had no clothes," she said. Bug bounty programs, she contends, should catch edge cases vendors missed—not serve as the primary quality assurance mechanism.
Well-funded security organizations are responding by restricting their bug bounty programs, implementing tiered access requirements and other measures to artificially slow the influx of reports.
Disclosure challenges compound the problem
Casey Ellis, president and co-founder of Disclose.io, points to another bottleneck: vulnerability disclosure itself. While the security community spent years making discovery easier, it hasn't invested comparable effort in making reporting easier.
Many researchers now sit on stockpiles of vulnerabilities because organizations lack clear reporting channels, vulnerability disclosure policies, or legal safe harbors. "I talk to a lot of people doing AI-powered research and they're sitting on a ton of bugs just because it's too hard to get them to the right place," Ellis said.
The concern is that well-meaning researchers, unable to report through proper channels and unwilling to publicly disclose and create user risk, are stuck in limbo.
Vendors unprepared for the new reality
Aaron Portnoy, chief product officer at Mindgard and founder of the Pwn2Own hacking competition, summarized the shift: "Software vendors used to be able to get away with shipping buggy software with no real accountability for a very long time, but now they can't really hide anymore, because AI doesn't sleep and can [find vulnerabilities] at scale."
Bugcrowd CEO Dave Gerry acknowledged the industry isn't prepared for the remediation challenge. "I've been doing this since 2012. We weren't prepared for it then. We still weren't fixing everything that was being found then. We're still not prepared."
The vulnerability discovery revolution powered by large language models has arrived, but the infrastructure to handle it—from secure development practices to disclosure pathways to remediation capacity—remains inadequate.
These details were first reported by Alexander Culafi at Dark Reading.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call