
The US National Vulnerabilities Database has recorded 45,207 software security flaws between January and Monday, nearing the total number discovered during all of 2025, according to a report Monday from Bloomberg News. This represents a significant increase from the all-time record of vulnerabilities recorded in 2025. Security vulnerabilities are flaws in software that can be exploited by hackers to break into computer systems for criminal or espionage purposes.
Major technology companies have reported unprecedented vulnerability discovery rates in recent updates. As reported by Bloomberg News, Oracle Corp. patched 1,449 security vulnerabilities in its July software update, marking a record for the company, compared to 309 fixes in the same update last year. Microsoft Corp. disclosed 642 security bugs in July, nearly five times the count from the same month in 2025. Alphabet Inc.'s Google found and fixed 433 bugs in a recent Chrome browser update, compared to 11 in an equivalent update one year earlier. The surge in vulnerability counts reflects a broader trend where AI-assisted testing is outpacing traditional manual methods, with security teams now leveraging AI to both find and fix defects.
The surge in discovered vulnerabilities is attributed to increasingly capable artificial intelligence systems integrated into security testing pipelines. According to Gabriel Shapiro, distinguished AI research scientist at SentinelOne Inc. as reported by Bloomberg News, "These tools are increasing people's ability to find vulnerabilities in software." At Google, the unprecedented scale and speed of vulnerability discovery results from advances in AI models and corresponding investment, according to Doug Turner, Chrome's director of engineering. Frontier AI models have accelerated their ability to discover software vulnerabilities, with Anthropic PBC's Mythos tool finding thousands of vulnerabilities in early testing. Companies like Oracle, Microsoft, and Google have invested heavily in machine learning models that can automatically scan code for weaknesses, often uncovering flaws that manual reviews would miss.
Recent developments demonstrate AI's unprecedented capabilities in cybersecurity research. Anthropic's Claude AI has achieved breakthrough findings in encryption systems that had previously withstood human scrutiny for years. The system found new weaknesses in HAWK digital signatures in just 60 hours, where experts had reviewed the system for two years without finding anything. By Anthropic's calculations, cracking the smallest HAWK key fell from 2^64 steps to 2^38, representing roughly 67 million times less work. The company also discovered vulnerabilities in AES encryption, attacking a weaker version with 7 of the usual 10 scrambling rounds, making attacks 200 to 800 times faster through a technique called the Möbius Bridge. These findings demonstrate that AI can now outpace human experts in complex security research, though the vulnerabilities discovered are theoretical rather than practical threats to current systems.
AI is fundamentally transforming the cybersecurity landscape by enabling faster, more automated attacks. According to Nikkei Asia, researchers at the University of Toronto tested an AI-powered agent in a virtual corporate network that independently identified security gaps, developed attack plans and took control of nearly 70% of computers and servers within about a week. Qualys found that hackers began exploiting 46 out of 52 software vulnerabilities before organisations finished installing security updates, with zero-day attacks starting even before software developers publicly disclosed the vulnerabilities. The average time for hackers to move across a network has fallen dramatically from 98 minutes in 2021 to just 29 minutes in 2025, with the fastest recorded breakout taking only 27 seconds. As Vishak Raman from Fortinet noted, AI allows attackers to automate several stages of an attack simultaneously, with FortiGuard Labs recording 640 billion reconnaissance events and nearly 122 billion exploitation attempts globally in 2025.