AI finds thousands of hidden vulnerabilities, overwhelming security teams with unprecedented discoveries

2 Sources

Share

Advanced AI models are uncovering thousands of previously hidden bugs in open-source code faster than security teams can patch them. The Linux Foundation launched Akrites alongside tech giants to coordinate fixes, while the Athena coalition has already processed over 20,000 findings across 500 projects. With fewer than 5% of AI-discovered vulnerabilities patched and attackers moving quickly, the industry faces a critical race to secure software infrastructure.

AI in Cybersecurity Uncovers Massive Scale of Hidden Flaws

Advanced AI models are discovering open-source vulnerabilities at a pace that has left security teams scrambling. The Athena coalition, led by Chainguard and comprising about two dozen companies including Cisco, Cloudflare, Docker, JPMorganChase, and PwC, has already processed more than 20,000 findings and developed over 2,000 patches across 500 open source projects

1

. The coalition's first wave of bug disclosures will begin in about three weeks, marking what Chainguard CEO Dan Lorenc describes as a "messy summer" for everyone in the industry

1

.

Source: Decrypt

Source: Decrypt

The challenge extends beyond discovery. According to Endor Labs CEO Varun Badhwar, fewer than 5% of the thousands of validated open-source vulnerabilities AI has surfaced in recent months have been patched

2

. This alarming gap between AI-driven vulnerability discovery and actual vulnerability patching creates significant risk, especially as frontier models like Anthropic's Mythos and OpenAI's GPT-5.5-Cyber continue improving their bug-hunting capabilities.

New Coalitions Emerge to Defend Open Source Software

The Linux Foundation launched Akrites on Thursday alongside 19 founding organizations including Amazon, Anthropic, Citi, Google, JPMorganChase, Microsoft, NVIDIA, and OpenAI to coordinate patching critical open-source software before AI-powered attacks can exploit discovered flaws

2

. The initiative addresses a fundamental timeline problem: frontier models can now scan a major open-source project and return multiple confirmed vulnerabilities in minutes, work that previously took skilled security researchers weeks

2

.

Akrites replaces the fragmented disclosure process with a single, confidential Security Incident Response Team, providing open-source maintainers with one predictable partner rather than a flood of uncoordinated reports

2

. When a critical package has no active maintainer, Akrites commits to stepping in as maintainer of last resort. The Alpha-Omega fund, which has issued over 70 grants totaling more than $20 million to open-source security projects since 2022, will provide seed funding

2

.

The Scale and Speed Problem Facing Security Teams

Many Athena coalition members partner with Anthropic's Project Glasswing and OpenAI Daybreak, which allow them to test the most advanced bug-hunting models

1

. In May, Anthropic used Mythos Preview to scan more than 1,000 open-source projects and found an estimated 6,202 high or critical-severity vulnerabilities

1

.

Lorenc explained the dilemma facing organizations: after running advanced models on proprietary code and fixing those issues, teams point the models at applications where 95 percent of the code is open source

1

. When AI finds hidden vulnerabilities across thousands of bugs at a time in projects organizations didn't even know they were using, coordinating vulnerability fixes becomes overwhelming. "The stats and data we're seeing are so scary - if you just keep running scans on the same libraries and same code, it just keeps finding more," Lorenc said

1

.

The Exploitation Timeline Has Collapsed

JPMorganChase CISO Pat Opet outlined the stakes: "AI has massively compressed the time between vulnerability discovery and exploitation to near real time," meaning adversaries can reverse-engineer a published patch and build a working exploit before many downstream systems have deployed the fix

2

. Success, according to Opet, requires "patch deployment, not patch publication"

2

.

Anthropic Deputy CISO Jason Clinton noted that the existing coordinated disclosure model "has been outpaced by how quickly AI can now find vulnerabilities"

2

. The old process buried maintainers under noise as multiple organizations independently scanned the same libraries and went through long bureaucratic processes before fixing bugs

2

.

OpenAI launched its own parallel effort called Patch the Planet three days before Akrites, using GPT-5.5-Cyber and Trail of Bits engineers across 19 open-source projects to merge dozens of patches

2

. While Patch the Planet focuses on AI-assisted discovery and patch delivery with expert human review, Akrites builds the coordination layer that routes validated findings upstream across the industry. Organizations can join by contributing engineering resources or funding at akrites.org

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved