📊 Key Data
  • 1,596 verified vulnerabilities discovered by AI in 281 open-source projects
  • 95% of these had no public advisory, leaving them invisible to standard security tools
  • Only 6.1% of flaws were patched within the study period, creating a dangerous exposure window of 90–150 days
🎯 Expert Consensus

Experts agree that AI is uncovering vulnerabilities far faster than current patching processes can address, necessitating AI-driven solutions to manage and mitigate these risks at machine speed.

26 days ago
The AI Patch Gap: Security's New Race Against Machine-Speed Threats

The AI Patch Gap: Security's New Race Against Machine-Speed Threats

SAN FRANCISCO, CA – June 24, 2026 – A startling new reality is confronting the cybersecurity world: the very artificial intelligence designed to build a better future is also systematically dismantling our digital defenses. New research from Agentic SecOps platform Tuskira finds that AI is discovering software vulnerabilities at a rate that far outstrips the industry's capacity to patch them, creating a vast and dangerous blind spot for enterprises worldwide.

The report, titled “The Emerging Patch Gap,” analyzes data from the disclosure program of Anthropic's powerful Claude Mythos AI model. The findings paint a stark picture of a security ecosystem under immense pressure, where traditional defense mechanisms are becoming lagging indicators of risk rather than proactive shields.

The Scale of the Unseen Threat

According to Tuskira's analysis of the first 63 days of the Mythos program, the AI disclosed 1,596 verified vulnerabilities across 281 open-source projects. The most alarming statistic is that a staggering 95% of these discoveries had no public advisory at the time of the research. This means they were invisible to the standard tools and workflows—CVE databases, NVD, and vulnerability scanners—that form the bedrock of corporate security programs.

The data reveals a profound asymmetry. AI-driven discovery outpaced visible remediation by a factor of roughly 16.5 to 1, with Mythos flagging about 25 new vulnerabilities per day while only 1.5 were marked as patched. This isn't for lack of trying on the part of software maintainers, who acknowledged nearly 91% of the disclosures. The bottleneck is capacity; despite the quick response, only 6.1% of the flaws were actually patched within the snapshot period.

This creates a perilous window of exposure, which the report estimates can stretch from 90 to 150 days between a private disclosure and a patch being deployed in a production environment. “Most security leaders already understand that AI is finding vulnerabilities faster than teams can patch them,” said Om Moolchandani, Co-Founder and Head of Threat Research at Tuskira. “What’s been missing is a concrete benchmark for how wide that gap is becoming. The new problem isn’t that every AI-discovered vulnerability is urgent. The problem is that CISOs need to know which vulnerabilities are reachable, exposed, and exploitable before the traditional advisory pipeline catches up.”

AI's Double-Edged Sword

The engine driving this “patch gap” is the phenomenal power of frontier AI models like Anthropic's Claude Mythos. Not specifically designed for cybersecurity, Mythos demonstrated what researchers call “striking cybersecurity capabilities,” unearthing flaws that have survived decades of human review, including a 27-year-old vulnerability in OpenBSD. Its capabilities are so potent that Anthropic has restricted its access to a select group of vetted partners under an initiative called Project Glasswing, aiming to give defenders a head start.

This flood of AI-discovered flaws has led some industry insiders to coin terms like the “vulnpocalypse” or the “AI vulnerability storm.” The core issue is that while AI accelerates discovery, the human-centric process of validating, prioritizing, and patching has not kept pace. One security strategist at a major cloud provider noted that AI is “compressing time,” surfacing years of latent technical debt in a matter of months and creating an overwhelming backlog for already strained security teams.

Yet, the consensus is that fighting AI-driven threats requires embracing AI in defense. The very technology creating the problem holds the key to its solution. The conversation is shifting from simply finding more flaws to managing them at machine speed. This involves using AI not just for discovery, but for analysis, risk prediction, and orchestrating remediation, turning fragmented intelligence into actionable security measures.

The Ripple Effect in the Software Supply Chain

The pressure is most acute in the sprawling, interconnected world of open-source software, which forms the foundation of modern applications. Tuskira's research highlights how a single upstream vulnerability can trigger a cascade of downstream alerts. Their report cites a single CVE in the popular ImageMagick library that propagated to over 18 variants in the NuGet package manager alone, a ripple effect that multiplies the workload for countless development and security teams.

This dynamic places immense strain on open-source project maintainers, who are often volunteers or small, under-resourced teams. The high acknowledgment rate shows they are engaged and responsible, but they simply lack the bandwidth to patch the firehose of vulnerabilities being directed at them. This creates a systemic risk for every organization that consumes open-source software—which is to say, nearly every organization on the planet.

For enterprises, the challenge is no longer just about scanning their own code but gaining deep visibility into their entire software supply chain. They must understand which of the thousands of potential vulnerabilities in their third-party components pose a genuine, immediate threat to their specific environment.

A New Paradigm for Security Operations

To survive in this new era, organizations are rapidly moving away from reactive, list-based vulnerability management toward a more proactive and continuous model of threat exposure management. The goal is to gain a comprehensive, real-time understanding of the attack surface and prioritize flaws based on actual business risk, not just technical severity scores.

Leading this charge are AI-powered defensive platforms. The next evolution is “agentic” AI systems, where autonomous software agents can research new vulnerabilities, correlate them with an organization's unique asset landscape, validate exploitability, and even initiate automated responses. Tuskira's own platform, for example, uses AI agents and a “Security Context Graph” to reason across an organization’s entire technology stack to find and block attack paths, often before a patch is even available.

This approach is gaining traction across the industry, with major players like Microsoft and initiatives like OpenAI's “Daybreak” project focused on building AI tools to help defenders validate, prioritize, and fix vulnerabilities faster. The emerging consensus is that effective security is becoming an orchestration problem: one that requires seamlessly integrating AI-driven intelligence into automated workflows that can operate at the speed of discovery.

Topics & Related

Sector:
AI & Machine Learning
Cybersecurity
Theme:
Agentic AI
Artificial Intelligence
Threat Landscape
Product:
Claude
UAID: 39026