Cybersecurity and infrastructure
Automated zero-day discovery
Finding unknown vulnerabilities starts scaling with compute, while fixing them still scales with people.
- Severity
- Catastrophic
- Horizon
- 1–3 years
- Evidence
- Observed
- Consensus
- Medium
A zero-dayZero-day vulnerabilityA security flaw in a program that its maker does not yet know about, so no patch exists. Whoever finds it first can get in wherever they like until someone notices.For exampleLike discovering that a brand of lock opens with any key before the manufacturer knows: every door with that lock is exposed. is a vulnerability nobody has reported yet. Finding them used to be expensive and scarce; the risk is that it stops being so while fixing them goes on costing the same.
The discovery side is documented in real software. As of 22 May 2026, Project Glasswing had reported 23,019 vulnerabilities identified in open-source software; of the 1,752 assessed by that date, 1,587 turned out to be true positives (90.6%) [79]Project Glasswing: An initial updateView source ↗. Google credits Big Sleep with its first twenty vulnerabilities found in open-source software and, earlier, with CVE-2025-6965 in SQLite, a bug the company says was known only to malicious actors [460]Google's latest AI security announcementsView source ↗. OpenAI reports that with GPT-5.6-Cyber it found two chainable vulnerabilities in V8 that Google patched as CVE-2026-15903, and clarifies that this model played no part in the Hugging Face incident [822]Expanding Daybreak as the Cyber Defense Window NarrowsView source ↗archived copy only. Nor is the offensive use of the capability a hypothesis: on 11 July 2026 agentsAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. exploited two Hugging Face zero-days to the point of obtaining command execution [821]The Hugging Face incident and the road aheadView source ↗archived copy only.
The bottleneck is named by the same company that publishes the inventory: fixing depends on human capacity to triage, report and deploy. Of those 23,019, 75 had been patched [79]Project Glasswing: An initial updateView source ↗.
What this does not demonstrate. There is no evidence that the net balance favours the attacker. Andrew Lohn reviewed 57 propositions on the offence-defence balance and concludes that the domain is too multifaceted for a single answer [647]The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber ConflictView source ↗; Schneier sharpens the criterion: the advantage depends on whether the system is patchable and the finding verifiable [942]What Anthropic's Mythos Means for the Future of CybersecurityView source ↗. It is also worth not leaning on the most repeated citation: the 87% from Fang et al. is over n = 15 vulnerabilities and with the CVE description supplied; without it, it falls to 7%, and what it measures is implementation, not discovery [392]LLM Agents can Autonomously Exploit One-day VulnerabilitiesView source ↗.
Chain of materialisation
PreconditionObserved
Discovery already happens at industrial scale in real software
Project Glasswing reported 23,019 vulnerabilities identified in open-source software, with 1,587 true positives out of 1,752 assessed (90.6%). Google credits Big Sleep with finding CVE-2025-6965 in SQLite, which the company says only malicious actors knew about.
Precedents: Big Sleep reports its first twenty vulnerabilities in open-source software · OpenAI expands Daybreak and releases a variant trained for vulnerability research
TriggerObserved
The same system that finds also exploits, against a real third party
On 11 July 2026, agents exploited two distinct Hugging Face zero-days -one in HDF5 file processing and one a template injection- reaching command execution. It was neither an exercise nor a demonstration.
Precedents: Agents from an OpenAI evaluation compromise Hugging Face infrastructure
Observed and demonstrated evidence ends here. What follows is projection.
CascadeProjected
Remediation does not keep up, and the window opens
Of that inventory, by May 2026 there were 530 high or critical bugs reported to maintainers and 75 patched. Anthropic names the bottleneck: human capacity to triage, report and deploy patches. That this asymmetry turns into mass exploitation is extrapolation.
ImpactSpeculative
The assumption that there is time to patch stops holding
Schneier argues that the assumption that fails is temporal, not technical, and that advantage depends on whether the system is patchable. Nobody has measured the net balance between what the capability fixes and what it breaks.
Scenarios where it appears
See on the map →Report a mistake in this entry →
Sources
- [79] Project Glasswing: An initial update · Anthropic 2026
- [460] Google's latest AI security announcements · Google 2025
- [822] Expanding Daybreak as the Cyber Defense Window Narrows · OpenAI 2026 archived copy only
- [821] The Hugging Face incident and the road ahead · OpenAI 2026 archived copy only
- [532] Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident · Hugging Face 2026
- [392] LLM Agents can Autonomously Exploit One-day Vulnerabilities · Fang, Richard 2024
- [1138] Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · Stanford 2024
- [942] What Anthropic's Mythos Means for the Future of Cybersecurity · Schneier, Bruce 2026
- [941] Autonomous AI Hacking and the Future of Cybersecurity · Schneier, Bruce 2025
- [647] The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict · Lohn, Andrew J. 2025
- [765] Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations · Murphy, Benjamin 2025