AI Vulnerability Discovery Analysis: VulnCheck Speed Check
Key Takeaways
- Separate discovery volume from exploitation speed when evaluating AI security claims.
- Add provenance and reproducibility checks to vulnerability intake before escalating AI found bugs.
- Prioritize exposed, exploitable, high impact flaws over noisy AI assisted reports.
The bug backlog is swelling faster than the evidence for AI driven exploit acceleration.
The robot bug hunter is not necessarily kicking down the door. It may just be ringing the vulnerability management bell until the battery dies. VulnCheck's Patrick Garrity reports a sharp rise in CVE disclosure volume across major software suppliers, which is exactly the kind of chart that makes security teams quietly open a second coffee. The interesting part is what the data does not yet prove: that AI discovered flaws are being exploited faster than traditional ones. That distinction matters because AI security discourse has the subtlety of a leaf blower in a library. Discovery volume and exploitation speed are related, but they are not the same machine. One fills the queue. The other determines whether the queue catches fire.
VulnCheck: the CVE firehose got suspiciously hydrated
VulnCheck reports that CVE disclosure volumes are up sharply year to date across several suppliers, including Chrome at +563.2%, VMware at +180.9%, Apache at +170.3%, Mozilla at +156.9%, HPE at +132.3%, and F5 at +113.8%. VulnCheck also says GitHub CVE issuance is up +476.07% year to date, with GitHub indicating the increase is spread across many reporters and projects rather than concentrated in one source. That is an important clue, because the pattern looks less like one heroic bug goblin and more like a broad tooling effect. VulnCheck is careful about causality, which is refreshing in an industry where a toaster can get labeled agentic if it has a YAML file. The firm says the increases are consistent with broader use of AI assisted vulnerability discovery, but the signal is still emerging and not all increases can be directly attributed to AI. It also points to public examples from Mozilla, Microsoft, Apache, Curl, and Palo Alto where AI models are being used to find, validate, or triage vulnerabilities, with mixed results depending on the project. The practical takeaway is not that the machine has become a perfect auditor. It is that the marginal cost of poking code is falling, and the number of pokes appears to be rising. Think of it as fuzzing with a junior analyst who never sleeps, occasionally hallucinates, and still needs someone senior to ask, politely, whether the finding reproduces.
Cloud Security Alliance: exploit automation is real, but do not mix buckets
The Cloud Security Alliance argues in its AI Safety Initiative paper that the broader exploit window is compressing. According to CSA, mean time to exploit for a disclosed vulnerability fell from roughly 32 days in 2022 to approximately 5 days for 2023 exploitation activity, and 2025 data showed 32.1% of newly tracked exploits appeared on or before the CVE's public disclosure date. CSA also says AI systems can generate working proof of concept exploit code for published CVEs in as little as 10 to 15 minutes at approximately one dollar per attempt. Those are serious claims, and defenders should not file them under bedtime reading unless they enjoy sleeping like a Kubernetes cluster during a region outage. But they answer a different question than VulnCheck's disclosure volume analysis. CSA is describing broad weaponization pressure around published CVEs, while VulnCheck is flagging a rise in disclosure volumes consistent with AI assisted discovery. Proving that AI discovered flaws themselves move to exploitation faster requires provenance aware telemetry that cleanly separates how a bug was found from how attackers later behaved. CSA's CVE-Genie example makes the point sharper. The paper says the multi agent framework reproduced 51% of all CVEs published in 2024 and 2025 with verifiable exploits at an average cost of $2.77 per CVE. That suggests exploit validation can get cheaper, but it still does not automatically mean every AI found bug becomes a faster real world intrusion. Automation can accelerate the lab without rewriting the street map.
VulnCheck and CSA together point to a triage problem Read
VulnCheck and CSA side by side and the defender lesson is almost annoyingly practical: the first impact of AI may be backlog inflation, while the speed story remains uneven and context dependent. VulnCheck explicitly says it is less clear whether the disclosure volume increases will be sustained or whether this is a temporary surge as frontier AI models are applied across different code. That uncertainty is not a shrug. It is a planning input. Security teams should treat AI assisted findings like any other high volume signal source: demand reproducibility, map findings to exposed assets, verify exploitability, and prioritize based on operational blast radius. If a report lacks a working repro, affected version clarity, or a credible path to impact, it should not outrank a boring known exploited issue just because an AI wore a lab coat while finding it. The model is a metal detector, not a judge. CSA's compression data still argues for faster patch decision loops, especially once a CVE is public and exploit code becomes cheap to test. But VulnCheck's data argues against panic sorting every AI touched CVE to the top of the heap. The sane posture is provenance aware triage: record whether AI helped find, validate, or triage the bug, but make the patch call on exposure, exploit evidence, affected assets, and confidence.
What to watch next
The next useful signal will not be another press release claiming the robot found a bug. It will be datasets that connect discovery provenance, disclosure quality, exploit availability, and real exploitation timing. If AI assisted discovery keeps raising CVE volume without a matching, measurable increase in exploitation speed for those same flaws, defenders will need better intake automation more than louder sirens. For builders, this is an invitation to make vulnerability management less theatrical and more measurable. Add fields for discovery method. Track false positives. Separate validation from exploitability. The bug pile is getting taller, but the answer is not to worship the pile. It is to build a better shovel, preferably one that does not hallucinate a critical severity rating because a function name looked spicy.
