AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. The proliferation of AI has automated and sped up large portions of the bug discovery pipeline, forcing vendors to confront their mistakes.

The “vulnpocalypse,” or the onslaught of vulnerabilities surfaced through the proliferation of AI, has brought about far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are accustomed to operating in a world where code reviews, researcher attention, and discovery capacity are finite. However, over the past two years, things have changed dramatically. Large language models (LLMs) have automated and accelerated large portions of the bug discovery pipeline, and frontier models could accelerate that process even further.

Bug bounty platforms report dramatic increases in the number of reports they triage. HackerOne saw reports double year over year, while Bugcrowd and TrendAI’s Zero Day Initiative (ZDI) similarly cited massive spikes. This has led platforms to deploy AI-powered triage to automate parts of the bug bounty process. Some experts believe that the new LLM reality will reconfigure the independent security research economy to become more of a volume game than a severity one.

The rise of AI-powered bug hunting has left software vendors scrambling to keep up with the influx of reports. As Aaron Portnoy, chief product officer at Mindgard and a founder of the Pwn2Own hacking competition, points out, vulnerabilities are losing their ability to hide due to AI’s relentless pace. “Software vendors used to be able to get away with shipping buggy software with no real accountability for a very long time, but now they can’t really hide anymore because AI doesn’t sleep and can find vulnerabilities at scale,” he says.

The increased velocity of bug discovery is exposing the shortcomings of secure-by-design practices in the industry. Katie Moussouris, CEO and founder of Luta Security, notes that the surge in bug-discovery speed is a reckoning for software vendors that consistently release insecure software without accountability. She argues that bug bounty platforms should be used to uncover bugs that vendors have somehow missed, rather than being the primary method of finding vulnerabilities.

Companies are struggling to cope with the rising demand. HackerOne CEO Kara Sprague reveals that over the past 12 months, the number of critical vulnerabilities sitting in backlogs has increased 30 times, despite a 50% improvement in mean time to remediation. Moussouris also notes that she is seeing well-invested security organizations reduce their bug bounty programs or implement gateways to artificially slow down the reporting process.

The bottleneck extends beyond vulnerability disclosure and remediation. Casey Ellis, president and co-founder of Disclose.io, points out that while the community has focused on making discovery easier, it has not spent nearly as much effort making reporting easier for security researchers. The inundation of vulnerabilities combined with remediation woes has made the process even more challenging.

As AI continues to revolutionize bug hunting, software vendors must adapt and improve their secure-by-design practices to meet the new demands. This means investing in more robust testing, revising internal processes, and prioritizing vulnerability disclosure. For security researchers, it is essential to maintain open communication channels with vendors and ensure that bug reports are actionable and well-documented.

Ultimately, the vulnpocalypse has exposed a fundamental flaw in the industry’s approach to secure-by-design. As Moussouris aptly puts it, “The bug bounty ecosystem has been suffering for a long time, and AI just pointed out where the emperor had no clothes.” It is time for software vendors to take responsibility for their products’ security and work closely with researchers to ensure that vulnerabilities are discovered, reported, and fixed in a timely manner.


Source: Dark Reading — 2026-09-04