Thales says its new Sentinel Envelope Plus binary protection cut an AI agent's finds in one test application from 8 of 10 vulnerabilities to zero. The bugs stay in the code, so software vendors would be buying time to patch, and the only measurement of that time so far comes from the seller.
Reality
- Evidence25
- Adoption
- Insufficient
- Hype gap+45
- Incentives85
- Confidence35
VulnCheck counts Chrome CVEs up 563% and GitHub-issued CVEs up 476% this year, a rise it calls consistent with AI-assisted bug finding. Whether the volume lasts is unknown, so exploitation data still sets patch order.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives55
- Confidence50
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Oracle's database chief says AI is turning up hundreds of security issues in code his teams spent decades hardening. His prescription for agents is authorization enforced inside the database, keyed to the end user's identity.
Reality
- Evidence38
- Adoption12
- Hype gap+30
- Incentives88
- Confidence45
The year's CVE tally has reached 66,401, close to double where it stood last September, and Microsoft alone patched 974 in a single month. Jerry Gamblin, who keeps the count, says more known bugs is mostly the system working.
Reality
- Evidence55
- Adoption45
- Hype gap+25
- Incentives45
- Confidence50
Microsoft rated 114 of the 973 Critical, but 284 score 8.0 or higher and two Important-severity Windows bugs are already under attack. One 9.1 advisory in the same cycle came from outside Microsoft.
Reality
- Evidence62
- Adoption55
- Hype gap+12
- Incentives68
- Confidence58
Politico reported that ENISA and CERT-EU ran an advanced OpenAI model over an EU project's code and got four fixed flaws out of it. Poland's CERT, doing the same kind of work, said it tested every hypothesis on real systems.
Reality
- Evidence58
- Adoption62
- Hype gap+16
- Incentives71
- Confidence52
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
Core Lightning says the machine-written reports found real flaws in its payments software. It is holding the count and severity for at least two weeks, leaving node operators to decide what to do with a hazard whose size is still private.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 52%
- Investor
- Investor 20%
Reality
- Evidence60
- Adoption40
- Hype gap+25
- Incentives68
- Confidence62
Bradley Chambers argues in his sponsored 9to5mac column that AI-assisted vulnerability discovery has killed the 90-day compatibility test, and that Mac fleets now need device management willing to stop work to force a patch.
Reality
- Evidence30
- Adoption20
- Hype gap+42
- Incentives75
- Confidence58
Chrome 153 started a two-week milestone cadence, which leaves the enterprise Extended Stable channel on its old eight-week calendar carrying twice as much change per jump. Google wants most admins on Stable anyway.
Perspective Coverage
4 publishers
- Builder
- Builder 39%
- Operator
- Operator 45%
- Investor
- Investor 16%
Reality
- Evidence70
- Adoption68
- Hype gap+18
- Incentives74
- Confidence76
Microsoft fixed 974 flaws in September and two were already under attack, but both need an attacker who is already on the machine, while the twenty bugs Dustin Childs classes as wormable need no login at all.
Reality
- Evidence74
- Adoption58
- Hype gap+14
- Incentives60
- Confidence71
A J.P. Morgan report counts more than 1,400 AI-generated vulnerability reports that maintainers accepted at roughly 90% validation and mostly did not patch, which moves the budget question from finding to fixing.
Reality
- Evidence28
- Adoption32
- Hype gap+42
- Incentives85
- Confidence60
CryptWare shipped fixes in two releases without publishing update notes, and the ATM maker that embeds the software says only two bugs touched its product. Who else runs it is the harder question, and the answer is not written down anywhere.
Reality
- Evidence64
- Adoption31
- Hype gap+12
- Incentives66
- Confidence55
Two of the patched bugs need nothing more than a page load, according to Malwarebytes. Chrome applies fixes on restart, so uptime is the exposure operators actually own.
Reality
- Evidence78
- Adoption60
- Hype gap+12
- Incentives55
- Confidence74
A 2021 seed flaw cut entropy from 128 bits to about 40, so no attacker needed to touch the hardware. Every seed generated before July 2026 now has to be replaced.
Reality
- Evidence62
- Adoption54
- Hype gap+14
- Incentives66
- Confidence58
Microsoft has delayed the first cumulative update for Exchange Server Subscription Edition a second time, with no new date, while engineers validate a growing pile of AI-found security findings.
Reality
- Evidence58
- Adoption24
- Hype gap+22
- Incentives62
- Confidence55
A Black Hat USA 2026 keynote described AI tooling that found roughly 1,000 bugs and then stalled on reporting. Patch Tuesday volume tells the same story from the other end.
Reality
- Evidence30
- Adoption24
- Hype gap+34
- Incentives54
- Confidence30