Al-powered vulnerability-discovery tools may ultimately give defenders a significant advantage. For now, however, they are also exposing a more immediate problem: even the largest software vendors may be unable to remediate vulnerabilities as quickly as Al systems can uncover them.
A recent investigation by Renee Dudley details how Anthropic’s Mythos has dramatically expanded the number of vulnerabilities Microsoft must address. In April, Mythos reportedly identified 90 critical and 141 important vulnerabilities in SharePoint alone.
One of the challenges linked with LLM-enabled vulnerability discovery is triaging software patches. Software vendors have traditionally deferred lower-severity vulnerabilities to concentrate limited resources first on critical or important vulnerabilities. But Al systems can potentially help adversaries identify ways to chain several seemingly minor vulnerabilities into usable exploits. That may require vendors to rethink not only how quickly they patch, but also how they assess severity and allocate remediation resources.
Of note, previously discovered exquisite exploit chains used by nation-state adversaries have incorporated non-critical vulnerabilities to facilitate their cyber operations. It will bear watching as to whether a wider range of adversaries will be able to create similar exploit chains as LLM-powered tools are integrated into adversaries’ offensive development suites.