AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
The proliferation of AI-powered tools is dramatically increasing the rate at which vulnerabilities are discovered, overwhelming software vendors and bug bounty platforms. This ‘vulnpocalypse’ is exposing insecure-by-design practices and creating a bottleneck in remediation. While AI is accelerating vulnerability discovery, the industry struggles to manage the influx of reported bugs and ensure vendors are adequately addressing them, leading to a backlog of critical vulnerabilities and a need for improved vulnerability disclosure processes.
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. The ‘vulnpocalypse,’ driven by AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further.
Bug bounty platforms report dramatic increases in the number of reports they triage. HackerOne saw reports double year over year, while Bugcrowd and TrendAI’s Zero Day Initiative (ZDI) similarly cited massive spikes. This has led platforms to deploy AI-powered triage to automate parts of the bug bounty process, and some experts believe the new LLM reality will reconfigure the independent security research economy to become more of a volume game than a severity one.
Aaron Portnoy, chief product officer at Mindgard and a founder of the Pwn2Own hacking competition, tells Dark Reading that because of AI, "vulnerabilities are losing a place to hide." "Software vendors used to be able to get away with shipping buggy software with no real accountability for a very long time, but now they can't really hide anymore, because AI doesn't sleep and can [find vulnerabilities] at scale," he says.
Finding vulnerabilities is becoming cheaper and faster, but discovery is useful only if organizations can actually do something about it. LLMs enable researchers to become more productive, and so the challenge shifts downstream to software makers. The bug bounty economy is reforming around volume and vulnerability research platforms are leaning on AI triage. But it's the vendors, those that sit at the bottom of the vulnerability research funnel, that may face the most uncertainty in the months and years to come.
Casey Ellis, the president and co-founder of Disclose.io who also previously started Bugcrowd, argues that while the security community spent years making vulnerability discovery easier, it has not spent nearly as much effort making vulnerability reporting easier. In other words, the vast majority of security researchers who hunt vulnerabilities are well-meaning individuals that believe in fully disclosing bugs through ethical channels, but the inundation of vulnerabilities, combined with remediation woes, has made this process even more difficult. "I talk to a lot of people doing AI-powered research and they're sitting on a ton of bugs just because it's too hard to get them to the right place. It's not malicious, and they don't have any kind of ill intent," he says. "They say, we know that if we just drop this crap on the Internet, that's actually going to create user risk, and we don't want to do that, but without that or without the vendor being responsive, what do you do? There's a lot of that right now."
Many organizations still lack clear reporting channels, vulnerability disclosure policies, or legal safe harbors that make researchers comfortable reporting what they find. His concern is that AI is accelerating vulnerability discovery faster than the systems surrounding vulnerability disclosure are maturing. The new AI future has enabled a massive increase in bug discovery velocity, but it has also put significant stress on the support beams that hold up this ecosystem.
