The rapid acceleration of vulnerability discovery due to the use of AI has sent shockwaves through the cybersecurity community, sparking concerns about the ability of enterprise security teams to keep pace. However, a new study suggests that while the situation may seem dire at first glance, it’s actually more manageable than initially feared – provided organizations have the right strategies in place.
Researchers from software supply chain security firm Echo analyzed nearly 40,000 CVE life cycles across 250 open source container projects, combining their own platform telemetry with survey responses from over 80 security leaders and an independent analysis of Anthropic’s Claude Mythos. The study reveals that while AI has dramatically accelerated the discovery of vulnerabilities – with monthly CVE disclosures rising by a staggering 145% in just two years – many of these findings are not yet vetted, and often turn out to be less serious than initially assumed.
One key factor is the ability of security teams to quickly validate findings, prioritize risk, and get available fixes into production. According to Eylam Milner, chief technology officer (CTO) and co-founder at Echo, “Mythos is really good at finding real vulnerabilities, but it’s much less reliable at determining how serious those vulnerabilities actually are.” This distinction is crucial for security teams trying to decide what requires their attention.
Rather than completely rethinking everything they’re doing around vulnerability management, organizations should focus on building infrastructure that can quickly validate a larger number of vulnerabilities and understand which ones matter. By streamlining the remediation process and getting available fixes into production more efficiently, security teams can stay ahead of the curve – even in the face of an increasingly rapid influx of new vulnerabilities.
Interestingly, Echo’s research also suggests that some of the vulnerability management challenges organizations are facing may be self-inflicted. A notable 89% of the vulnerabilities examined had a fix, yet nearly 40% of these remained unresolved for more than six months. This highlights the importance of prioritizing vulnerability remediation and ensuring that security teams have the resources they need to stay on top of patching and fixing known issues.
Ultimately, while the use of AI has undoubtedly accelerated vulnerability discovery, it’s not a reason for organizations to panic. By focusing on quick validation, risk prioritization, and efficient remediation, security teams can manage the surge in vulnerabilities – and even turn it into an opportunity to strengthen their defenses.
Source: Dark Reading — 2026-09-02