cd /news/ai-safety/ai-is-finding-software-vulnerabiliti… · home topics ai-safety article
[ARTICLE · art-75832] src=startupfortune.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

AI is finding software vulnerabilities faster than security teams can fix them

Microsoft patched a record 622 security flaws in July, triple the previous monthly record, while China's 360 Digital Security Group has used an AI agent to uncover nearly 1,000 previously unknown bugs. OpenAI's Codex Security tool scanned over 1.2 million commits and surfaced 792 critical and 10,561 high-severity vulnerabilities in open-source projects. The Cloud Security Alliance confirmed at least 35 CVEs in March 2026 were directly attributable to AI-generated code, up from 6 in January, and OX Security found that 62% of AI-generated code ships with at least one vulnerability.

read4 min views1 publishedJul 27, 2026
AI is finding software vulnerabilities faster than security teams can fix them
Image: Startupfortune (auto-discovered)

Microsoft patched 622 security flaws in a single month this July, a record triple the size of the previous one, while China's 360 Digital Security has used an AI agent to uncover nearly 1,000 previously unknown bugs. The same technology generating code at scale is now the only tool fast enough to audit it.

The numbers coming out of Patch Tuesday this July were not a typo. Microsoft fixed 622 vulnerabilities in a single release, according to reporting from The Register and CyberScoop, shattering the prior monthly record of 206 set just weeks earlier. Among those 622 were 416 Windows defects, 82 in Office, and three zero-days, two of which were already being exploited in the wild before a patch existed. Microsoft's security team declined to comment on whether AI tooling was the primary driver, but analysts tracking the trend are clear: autonomous vulnerability discovery engines are finding bugs faster than traditional patch cycles were ever designed to handle.

The clearest proof of that comes from Beijing. 360 Digital Security Group, known in some markets as Qihoo 360, deployed an AI-powered Vulnerability Discovery Agent that has now uncovered close to 1,000 previously unknown flaws, including in Microsoft Office and in OpenClaw, an open-source framework for building AI agent workflows. Bloomberg reported the findings in April, framing 360's agent as a direct echo of the approach Anthropic took with its Mythos model. That's the scale of the threat. State-linked security firms now have autonomous systems hunting through commercial software stacks at a pace no human team could match.

OpenAI launched Codex Security on March 6 as a research preview, available initially to ChatGPT Pro, Enterprise, Business, and Edu subscribers. The numbers are striking. As The Hacker News reported, the tool scanned over 1.2 million commits during testing and surfaced 792 critical and 10,561 high-severity vulnerabilities in open-source projects. OpenAI positions it as a context-aware agent that builds a deep understanding of a codebase before flagging issues - reducing the false-positive noise that drowns traditional static analysis tools. The first month is free, at least for the organisations it's aimed at.

Investors are paying attention. VCs poured $18.7 billion into cybersecurity in 2025, and AI-native security overtook identity as the fastest-growing venture category in Q1 2026, pulling in $4.1 billion at 47% year-over-year growth, according to data tracked by Help Net Security. Cyera raised $600 million in June at a $12 billion valuation. The pattern is familiar: a structural shift creates a new attack surface, a generation of startups gets funded to secure it, and the incumbents scramble to acquire or replicate. What's different this time is the speed. The shift from traditional code to AI-generated code didn't take a decade; it took roughly eighteen months.

The problem founders shipping AI-generated code haven't priced in #

Here's the thing about vibe coding: the bugs it produces aren't random. They cluster. The Cloud Security Alliance confirmed at least 35 CVEs in March 2026 alone were directly attributable to AI-generated code, up from 6 in January. The dominant failure patterns, authorization flaws, missing access controls, hardcoded credentials, are the same ones that appear when developers move fast without security review. AI tools lower the bar to shipping functional code. They don't lower the bar to evaluating that code for security properties. They may raise it.

OX Security found that 62% of AI-generated code ships with at least one vulnerability. Georgia Tech's Vibe Security Radar put the confirmed AI-linked CVE count at 74 through March, while estimating the true undetected figure is 5 to 10 times higher. AI-assisted commits expose secrets at more than twice the rate of human-only commits, 3.2% versus 1.5%, according to Cloud Security Alliance research. A startup shipping a product built primarily with Cursor or Claude Code, without a dedicated security audit in the loop, is accumulating debt it can't see and can't price.

That's not an argument against using these tools. It's an argument for understanding what they don't do. Codex Security, 360's agent, and the category of AI-native scanners emerging around them exist precisely because the old model, a security engineer manually reviewing pull requests, doesn't scale to the output that AI coding assistants now produce. You can't manually review 1.2 million commits. You need a machine to check the machine's work.

Frankly, the more interesting competitive question for founders right now isn't whether to use AI to write code. That's settled. It's whether they're building a security review step into their pipeline before their first serious customer does a vendor assessment and finds it missing. The enterprise buyers writing large checks in 2026 have seen enough AI-generated breach disclosures to ask the question directly. The ones who can answer it clearly will close faster.

Also read: OpenAI picks Dublin as its EU headquarters with €105 million and 250 new jobsMicrosoft's AI security overhaul sets a benchmark every enterprise security startup now has to beatGoogle AI Mode is now the default for a billion users and your startup's SEO playbook is already obsolete

── more in #ai-safety 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-is-finding-softwa…] indexed:0 read:4min 2026-07-27 ·