Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 01 · Risk map

Cybersecurity and infrastructure

Automated zero-day discovery

Finding unknown vulnerabilities starts scaling with compute, while fixing them still scales with people.

Severity
Catastrophic
Horizon
1–3 years
Evidence
Observed
Consensus
Medium

A zero-dayZero-day vulnerabilityA security flaw in a program that its maker does not yet know about, so no patch exists. Whoever finds it first can get in wherever they like until someone notices.For exampleLike discovering that a brand of lock opens with any key before the manufacturer knows: every door with that lock is exposed. is a vulnerability nobody has reported yet. Finding them used to be expensive and scarce; the risk is that it stops being so while fixing them goes on costing the same.

The discovery side is documented in real software. As of 22 May 2026, Project Glasswing had reported 23,019 vulnerabilities identified in open-source software; of the 1,752 assessed by that date, 1,587 turned out to be true positives (90.6%) [79]Project Glasswing: An initial updateAnthropic · 2026 · institutional blogView source ↗Accessed on 9 September 2026. Google credits Big Sleep with its first twenty vulnerabilities found in open-source software and, earlier, with CVE-2025-6965 in SQLite, a bug the company says was known only to malicious actors [460]Google's latest AI security announcementsGoogle · 2025 · institutional blogView source ↗Accessed on 9 September 2026. OpenAI reports that with GPT-5.6-Cyber it found two chainable vulnerabilities in V8 that Google patched as CVE-2026-15903, and clarifies that this model played no part in the Hugging Face incident [822]Expanding Daybreak as the Cyber Defense Window NarrowsOpenAI · 2026 · institutional blogView source ↗archived copy onlyAccessed on 9 September 2026. Nor is the offensive use of the capability a hypothesis: on 11 July 2026 agentsAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. exploited two Hugging Face zero-days to the point of obtaining command execution [821]The Hugging Face incident and the road aheadOpenAI · 2026 · institutional blogView source ↗archived copy onlyAccessed on 9 September 2026.

The bottleneck is named by the same company that publishes the inventory: fixing depends on human capacity to triage, report and deploy. Of those 23,019, 75 had been patched [79]Project Glasswing: An initial updateAnthropic · 2026 · institutional blogView source ↗Accessed on 9 September 2026.

What this does not demonstrate. There is no evidence that the net balance favours the attacker. Andrew Lohn reviewed 57 propositions on the offence-defence balance and concludes that the domain is too multifaceted for a single answer [647]The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber ConflictLohn, Andrew J. · 2025 · preprintView source ↗Accessed on 9 September 2026; Schneier sharpens the criterion: the advantage depends on whether the system is patchable and the finding verifiable [942]What Anthropic's Mythos Means for the Future of CybersecuritySchneier, Bruce · 2026 · webView source ↗Accessed on 9 September 2026. It is also worth not leaning on the most repeated citation: the 87% from Fang et al. is over n = 15 vulnerabilities and with the CVE description supplied; without it, it falls to 7%, and what it measures is implementation, not discovery [392]LLM Agents can Autonomously Exploit One-day VulnerabilitiesFang, Richard; Bindu, Rohan; Gupta, Akul et al. · 2024 · preprintView source ↗Accessed on 9 September 2026.

Chain of materialisation

  1. PreconditionObserved

    Discovery already happens at industrial scale in real software

    Project Glasswing reported 23,019 vulnerabilities identified in open-source software, with 1,587 true positives out of 1,752 assessed (90.6%). Google credits Big Sleep with finding CVE-2025-6965 in SQLite, which the company says only malicious actors knew about.

    Precedents: Big Sleep reports its first twenty vulnerabilities in open-source software · OpenAI expands Daybreak and releases a variant trained for vulnerability research

  2. TriggerObserved

    The same system that finds also exploits, against a real third party

    On 11 July 2026, agents exploited two distinct Hugging Face zero-days -one in HDF5 file processing and one a template injection- reaching command execution. It was neither an exercise nor a demonstration.

    Precedents: Agents from an OpenAI evaluation compromise Hugging Face infrastructure

    Observed and demonstrated evidence ends here. What follows is projection.

  3. CascadeProjected

    Remediation does not keep up, and the window opens

    Of that inventory, by May 2026 there were 530 high or critical bugs reported to maintainers and 75 patched. Anthropic names the bottleneck: human capacity to triage, report and deploy patches. That this asymmetry turns into mass exploitation is extrapolation.

  4. ImpactSpeculative

    The assumption that there is time to patch stops holding

    Schneier argues that the assumption that fails is temporal, not technical, and that advantage depends on whether the system is patchable. Nobody has measured the net balance between what the capability fixes and what it breaks.

See on the map →Report a mistake in this entry →

Sources

  1. [79] Project Glasswing: An initial update · Anthropic 2026
  2. [460] Google's latest AI security announcements · Google 2025
  3. [822] Expanding Daybreak as the Cyber Defense Window Narrows · OpenAI 2026 archived copy only
  4. [821] The Hugging Face incident and the road ahead · OpenAI 2026 archived copy only
  5. [532] Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident · Hugging Face 2026
  6. [392] LLM Agents can Autonomously Exploit One-day Vulnerabilities · Fang, Richard 2024
  7. [1138] Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · Stanford 2024
  8. [942] What Anthropic's Mythos Means for the Future of Cybersecurity · Schneier, Bruce 2026
  9. [941] Autonomous AI Hacking and the Future of Cybersecurity · Schneier, Bruce 2025
  10. [647] The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict · Lohn, Andrew J. 2025
  11. [765] Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations · Murphy, Benjamin 2025

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com