AI Finds Vulnerabilities Faster Than Humans Can Patch Them—And That's Only Half the Problem
We're watching a security inflection point unfold in real time. This week, the industry crossed two unsettling thresholds simultaneously: an AI agent discovered 21 zero-day vulnerabilities in FFmpeg in one pass, while Google shipped Chrome 149 with patches for 429 bugs. In the same 24 hours, we learned that consumer devices you trust in your home are silently scraping the internet for profit, that sophisticated worms are replicating through Microsoft's own repositories, and that critical vulnerabilities in widely-used tools are already being weaponized at scale. The unifying thread isn't technical—it's pace. The speed at which vulnerabilities are discovered, exploited, and deployed now outpaces the speed at which most organizations can respond.
Start with the sobering headlines on active exploitation. CISA just added a SolarWinds Serv-U denial-of-service flaw to its Known Exploited Vulnerabilities catalog, which means attackers are weaponizing it in the wild right now. Simultaneously, researchers documented a critical vulnerability in Everest Forms Pro being actively exploited to take complete control of WordPress sites. These aren't hypothetical threats—they're attacks happening today against production systems. What makes this worse is the supply chain dimension: many organizations don't even know they're running vulnerable versions of these tools. The SolarWinds Serv-U flaw is particularly insidious because it targets file transfer infrastructure that organizations often assume is secure. And for WordPress site owners running Everest Forms, the vulnerability essentially hands over administrative access to attackers.
But the supply chain problem extends far beyond individual plugins and servers. Microsoft's own GitHub repositories fell victim to the Miasma self-replicating worm, which compromised 73 repositories across four GitHub organizations. This is worth sitting with for a moment. If Microsoft—with its dedicated security teams and fortress mentality around source code—can have dozens of repositories compromised by a self-replicating worm, then the assumption that "GitHub is just where open-source lives" is dangerously naive. Every repository is a potential foothold. Every pull request is a potential distribution vector. The Miasma campaign shows what happens when attackers realize that compromising trusted infrastructure upstream can cascade outward to thousands of downstream consumers.
Now consider the AI dimension, and things get genuinely unsettling. On one side, we see the promise: an autonomous AI agent uncovered 21 previously unknown vulnerabilities in FFmpeg, which is the media library embedded in nearly everything that touches video. This is the flip side of AI security—machine learning algorithms systematically probing code for flaws faster than human auditors ever could. That's potentially defensive. But this week also revealed the darker flip side of the same coin.
Researchers reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and discovered something troubling: free applications are quietly turning smart TVs and mobile devices into web-scraping proxies for AI companies. Let that sink in. Millions of devices connected to home networks and always-on smart TVs are being commandeered as infrastructure for large-scale data collection operations. It's not malware in the traditional sense—no ransomware, no wiper, no credential theft—but it's arguably more insidious. The device abuse is happening with user consent buried in terms of service, and the victims don't even know their hardware is being rented out as a bot in someone else's scraping operation. This is the new supply chain attack: not compromising software, but commodifying users' devices.
OpenAI's response to similar risks is revealing. The company is rolling out Lockdown Mode for ChatGPT to reduce the risk of data exfiltration from prompt injection attacks. This is a tacit acknowledgment that AI tools themselves have become attack surfaces. A sophisticated attacker can craft prompts designed to exfiltrate data or abuse the tool's capabilities. By restricting what ChatGPT can do with certain inputs, OpenAI is essentially putting guardrails around a system that users expect to be flexible and powerful. It's a compromise: less useful in some contexts, safer in others. It's the kind of trade-off we'll keep making as AI becomes infrastructure.
For security teams, all of this converges on a few uncomfortable realizations. First, the vulnerability discovery rate is accelerating, and AI agents will only make that faster. Chrome's 429 patches in a single release is almost certainly not a peak—it's a new floor. Teams that can't keep up with monthly patching cadences will find themselves perpetually out of cycle. Second, the supply chain is no longer something you protect by auditing your vendors; it's an attack surface that requires continuous monitoring and rapid response. Third, the consumer device layer is now a liability in ways that most organizations haven't fully reckoned with. If employees are bringing compromised smart home devices onto corporate networks, or if your infrastructure runs on media libraries with 21 unpatched zero-days, the perimeter is already breached.
There's a reason Opal Security just raised $23 million for AI-native identity governance. The insight driving that funding is sound: in a world where software supply chains are compromised at scale and vulnerabilities are discovered faster than they can be patched, the game shifts from prevention to containment. You assume breach. You assume your tools have vulnerabilities. You assume your devices might be abused. The only thing you can still control with reasonable confidence is who has access to what, and when. Identity governance becomes the moat.
The question for the week ahead is whether the industry can sustain this pace of discovery and response. Vendors are shipping hundreds of patches per quarter. AI agents are finding zero-days that humans missed for years. Attackers are exploiting those holes within days of disclosure. And in the background, devices in homes and offices are being quietly repurposed as infrastructure for data collection operations that users didn't consent to and don't understand. This isn't a vulnerability problem anymore—it's a systems problem. The only way forward is faster response times, tighter identity controls, and a hard reset on what we assume about supply chain security.
Watch this space closely. The next time a critical flaw is disclosed, assume it's already being exploited. The next time you deploy a new tool or service, assume it's collecting data in ways you haven't audited. And the next time you're told a patch Tuesday is "just routine," remember that routine now means 429 individual vulnerabilities in a single release.
Key Takeaways
- Active exploitation is the new normal: SolarWinds and WordPress vulnerabilities are being weaponized in the wild now. Patch SolarWinds Serv-U and audit all active Everest Forms Pro installations immediately—assume breach if you can't verify patching.
- AI is discovering zero-days faster than humans can respond: 21 new vulnerabilities in FFmpeg found by an AI agent in one analysis pass. Patch cadence expectations need to accelerate; monthly updates are already behind schedule.
- Consumer devices are supply chain attack infrastructure: Smart TVs and mobile devices are being commodified as web-scraping proxies without user knowledge. Audit what applications are deployed on home networks and what data permissions they hold.
- Identity governance is the new perimeter: Assume vulnerabilities will exist; focus on controlling who has access when. The Opal funding round signals that vendors are betting on identity controls as the primary defense layer.
The Wire is HackWire's daily editorial briefing, published every morning.