AI finding twice as many cyber flaws in 2026 as it did in 2025

1 hour ago 3
A motion graphic showing computer code on a digital screen, representing artificial intelligence, machine learning, and innovative software development technology.The surge in discovered vulnerabilities lends credence to the warnings governments and security firms have been issuing about the threat posed by hackers armed with powerful, new AI models. Photo by MR.Cole_Photographer/Getty Images

Article content

The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally of vulnerabilities that surfaced in 2025, an explosion driven by increasingly capable artificial intelligence systems.

Financial Post

THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLY

Subscribe now to read the latest news in your city and across Canada.

  • Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.
  • Daily content from Financial Times, the world's leading global business publication.
  • Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles, including the New York Times Crossword.

SUBSCRIBE TO UNLOCK MORE ARTICLES

Subscribe now to read the latest news in your city and across Canada.

  • Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.
  • Daily content from Financial Times, the world's leading global business publication.
  • Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles, including the New York Times Crossword.

REGISTER / SIGN IN TO UNLOCK MORE ARTICLES

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account.
  • Share your thoughts and join the conversation in the comments.
  • Enjoy additional articles per month.
  • Get email updates from your favourite authors.

THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account
  • Share your thoughts and join the conversation in the comments
  • Enjoy additional articles per month
  • Get email updates from your favourite authors

Sign In or Create an Account

or

Article content

The United States National Vulnerabilities Database, a repository of digital security holes, recorded 45,207 flaws between January and Monday, a count approaching the total number found in all of 2025. Last year saw an all-time record for recorded vulnerabilities in that database. Security vulnerabilities are flaws in software that can be exploited by a hacker, including to break into computer systems to commit crimes or carry out espionage.

Article content

Article content

Article content

Oracle Corp. said it patched 1,449 security vulnerabilities in its monthly July software update, an all-time record for the 49-year-old tech giant, while the same update last year contained 309 fixes. Microsoft Corp. disclosed 642 security bugs in July, another all-time high and nearly five times the count in the same month last year. Alphabet Inc.’s Google found and fixed 433 such bugs in a recent update to the Chrome browser versus 11 in an equivalent update one year ago.

Article content

By signing up you consent to receive the above newsletter from Postmedia Network Inc.

Article content

“We have to come to the reckoning that these tools are increasing the ability of people to find vulnerabilities in software,” said Gabriel Bernadett-Shapiro, distinguished AI research scientist at the cybersecurity firm SentinelOne Inc.

Article content

At Google, the “unprecedented scale and speed” of vulnerability discovery is a result of advances in AI models and a corresponding investment, Doug Turner, Chrome’s director of engineering, told Bloomberg.

Article content

Microsoft declined to comment. Oracle didn’t respond to a request for comment.

Article content

The surge in discovered vulnerabilities lends credence to the warnings governments and security firms have been issuing about the threat posed by hackers armed with powerful, new AI models.

Article content

Article content

A deeper look at the figures also reveals the limits of these worries. There’s been no rise in the number of exploited issues this year despite the uptick in discovered flaws, according to the U.S. government’s Known Exploited Vulnerabilities catalogue. Internal security personnel at the technology firms are finding many of the new vulnerabilities with their own cyber-focused AI tools, according to their disclosures. Of the 433 vulnerabilities in Chrome in July, 401 were “reported by Google” internally, according to the company.

Article content

Article content

“We just aren’t seeing the numbers to back up the doom and gloom prophets,” said Dustin Childs, head of threat awareness at the cybersecurity firm Trend Micro Inc.

Article content

Frontier AI models accelerated their ability to discover software vulnerabilities in recent months, prompting anxiety about a surge in hackers exploiting those flaws. Anthropic PBC’s Mythos tool found thousands of software vulnerabilities in early testing, showcasing a new level of capability for cutting-edge AI models. OpenAI has developed comparable tools. Officials at the National Security Agency have been impressed by the Anthropic model’s ability to find and exploit cybersecurity vulnerabilities, Bloomberg reported.

Read Entire Article