Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software.

The “vulnpocalypse,” or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further.

Bug bounty platforms report dramatic increases in the number of reports they triage. HackerOne saw reports double year over year, while Bugcrowd and TrendAI’s Zero Day Initiative (ZDI) similarly cited massive spikes. This has led platforms to deploy AI-powered triage to automate parts of the bug bounty process, and some experts believe the new LLM reality will reconfigure the independent security research economy to become more of a volume game than a severity one.

Related:Cisco Zero-Day Highlights API Endpoint Authentication Issues

Aaron Portnoy, chief product officer at Mindgard and a founder of the Pwn2Own hacking competition, tells Dark Reading that because of AI, “vulnerabilities are losing a place to hide.”

“Software vendors used to be able to get away with shipping buggy software with no real accountability for a very long time, but now they can’t really hide anymore, because AI doesn’t sleep and can [find vulnerabilities] at scale,” he says.

Finding vulnerabilities is becoming cheaper and faster, but discovery is useful only if organizations can actually do something about it. LLMs enable researchers to become more productive, and so the challenge shifts downstream to software makers.

The Vulnpocalypse Is a Secure-by-Design Reckoning

“The bug bounty ecosystem has been suffering for a long time and AI just pointed out where the emperor had no clothes,” says Katie Moussouris, CEO and founder of Luta Security as well as a pioneer in vulnerability research.

Moussouris explains that the increase in bug-discovery velocity is a reckoning for software vendors that make the same mistakes and release insecure software over and over again. She argues that bug bounty platforms should be for the bugs a vendor somehow missed, and not the primary method of finding vulnerabilities.

And companies appear to be struggling with the demand. HackerOne CEO Kara Sprague tells Dark Reading that over the past 12 months, the number of critical vulnerabilities sitting in backlogs has increased 30 times, “despite the fact that we have gotten 50% better in terms of mean time to remediation.”

Related:MFA Won’t Save You From OAuth Consent Abuse

Similarly, Moussouris says she’s seeing a wave of even well-invested security organizations trimming back their bug bounty programs. “They are putting up more gateways, where, ‘You have to submit this many vulnerabilities before you get invited to our top tier payout’ … and they’re trying to do all of these kinds of things to artificially slow the pace of what they’re receiving.”

If secure-by-design and remediation represent one side of the bottleneck, disclosure represents another.

Vulnerability Disclosure Woes

Casey Ellis, the president and co-founder of Disclose.io who also previously started Bugcrowd, argues that while the security community spent years making vulnerability discovery easier, it has not spent nearly as much effort making vulnerability reporting easier.

In other words, the vast majority of security researchers who hunt vulnerabilities are well-meaning individuals that believe in fully disclosing bugs through ethical channels, but the inundation of vulnerabilities, combined with remediation woes, has made this process even more difficult.

Related:Black Hat USA 2026 | OpenAI’s Deep Dive Into Hugging Face Incident

“I talk to a lot of people doing AI-powered research and they’re sitting on a ton of bugs just because it’s too hard to get them to the right place. It’s not malicious, and they don’t have any kind of ill intent,” he says. “They say, we know that if we just drop this crap on the Internet, that’s actually going to create user risk, and we don’t want to do that, but without that or without the vendor being responsive, what do you do? There’s a lot of that right now.”

Ellis argues that many organizations still lack clear reporting channels, vulnerability disclosure policies, or legal safe harbors that make researchers comfortable reporting what they find. His concern is that AI is accelerating vulnerability discovery faster than the systems surrounding vulnerability disclosure are maturing.

AI has exacerbated these issues, though they aren’t new ones. Many organizations have long struggled to offer safe reporting pathways to researchers, and some organizations that aren’t technology-forward have misconstrued ethical security research as criminal activity. “If you’ve got people that want to do this stuff in good faith and you’re making them feel like they’re criminal, that’s dumb,” Ellis says.

The new AI future has enabled a massive increase in bug discovery velocity, but it has also put significant stress on the support beams that hold up this ecosystem. Parts of this puzzle are being solved; for example, the bug bounty economy is reforming around volume and vulnerability research platforms are leaning on AI triage. But it’s the vendors, those that sit at the bottom of the vulnerability research funnel, that may face the most uncertainty in the months and years to come.

Bugcrowd CEO Dave Gerry says that as far as the security industry is concerned, there’s more work to do, and remediation — fixing bugs — is “one that I don’t think we’re prepared for.”

“I’ve been doing this since 2012. We weren’t prepared for it then. We still weren’t fixing everything that was being found then,” he says. “We’re still not prepared.”





Source link

#

Comments are closed