Source-led article
AI-Powered Bug Hunting Drives Record Surge in Security Vulnerability Reports

The advent of AI models specifically designed for identifying software vulnerabilities has dramatically increased the number of reported security flaws, according to a recent analysis by Epoch AI. In June 2026, 21 organizations collectively reported approximately 1,500 high-severity and critical Common Vulnerabilities and Exposures (CVEs). This figure represents more than 3.5 times the previous monthly record, underscoring a significant shift in cybersecurity practices.
The surge in vulnerability reports directly correlates with the launch and widespread adoption of AI-powered bug-hunting programs. These programs leverage advanced AI capabilities to scour codebases for weaknesses that might otherwise go unnoticed by human researchers or traditional scanning tools.
AI Models at the Forefront
Anthropic’s Claude Mythos Preview model is a key driver behind this trend. Announced in April, this AI model is specifically engineered to autonomously discover software vulnerabilities. Anthropic revealed that trusted partners were already utilizing Claude Mythos Preview to identify and rectify bugs even before its public release. The company’s “Glasswing” program, which employs this technology, has reportedly unearthed over 10,000 high-severity or critical vulnerabilities to date, with many still awaiting public disclosure.
Similarly, OpenAI’s “Daybreak” program is believed to be contributing significantly to the escalating number of reported vulnerabilities. While specific details on Daybreak’s findings are less public, its involvement further emphasizes the growing role of AI in proactive cybersecurity.
Impact on Software Security
The substantial increase in reported CVEs suggests a dual impact on the software ecosystem. On one hand, it highlights a previously underestimated volume of critical vulnerabilities present in existing software. On the other, it indicates that AI tools are becoming indispensable for enhancing the overall security posture of digital infrastructure. For Indian developers and businesses, this trend implies a necessity to integrate advanced AI-driven security checks into their development pipelines. The ability of AI to rapidly identify complex flaws can significantly reduce the window of opportunity for malicious actors.
For businesses and developers in India, this development offers both challenges and opportunities. While the immediate consequence is a higher number of reported vulnerabilities that require patching, the long-term benefit is more secure software. Integrating AI-powered security tools can help Indian tech companies to proactively address potential threats, strengthen their products, and comply with evolving cybersecurity standards. This also creates a demand for AI security specialists and dedicated AI tools tailored for the Indian market.
Key facts
| Feature | Detail |
|---|---|
| Reporting Period | June 2026 |
| Vulnerabilities Reported | ~1,500 high-severity and critical CVEs |
| Reporting Organizations | 21 |
| Increase from Previous Record | >3.5 times |
| Key AI Models | Anthropic’s Claude Mythos Preview (Glasswing program), OpenAI’s Daybreak program |
Addressing the Influx of Vulnerabilities
The sheer volume of new vulnerability reports presents a challenge for software vendors and security teams, who must now prioritize and patch a significantly larger number of flaws. This necessitates more robust incident response plans and accelerated patching cycles. Epoch AI’s analysis confirms that this wave of discoveries is largely attributable to AI-driven methods rather than a sudden decline in software quality or increased human effort.
The ongoing advancements in AI for cybersecurity are set to redefine how vulnerabilities are discovered, managed, and mitigated. This shift benefits end-users and organizations by leading to more secure software environments, but also demands continuous adaptation from development and security teams to keep pace with these powerful new tools.
Source: The Decoder, https://the-decoder.com/security-vulnerability-reports-have-exploded-since-ai-models-started-hunting-for-bugs/