Vulnpocalypse Now? How AI is changing vulnerability discovery
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我得仔细阅读文章,抓住主要观点。 文章主要讨论了AI如何改变漏洞发现和安全测试的未来。提到了“漏洞浩劫”(vulnpocalypse),说明AI辅助攻击的加速。同时,Intigriti作为众包安全公司,观察到AI带来的漏洞提交激增。他们认为这不仅是技术进步,还涉及研究人员数量和客户增长。 接下来,文章探讨了AI带来的机遇和风险。虽然AI提高了效率和降低了门槛,但也带来了大量无效提交的问题。Intigriti正在调整策略,利用AI工具优化流程,并强调人机协作的重要性。 最后,文章提到他们将继续支持安全研究人员,并通过透明使用AI来维护社区信任。因此,总结时需要涵盖AI的影响、Intigriti的角色、机遇与挑战以及他们的应对策略。 现在,把这些要点浓缩成100字以内的内容。确保涵盖AI对漏洞发现的影响、Intigriti的观察、挑战与应对措施。 </think> 文章探讨了人工智能(AI)对漏洞研究和安全测试的未来影响,包括“漏洞浩劫”现象、AI辅助攻击的加速及其对防御方的压力。作为一家众包安全公司,Intigriti观察到AI技术正在改变漏洞发现的经济模式,并面临处理大量低质量提交的挑战。文章还讨论了AI带来的机遇与风险,并强调了人机协作在漏洞研究中的重要性。 2026-4-23 00:0:0 Author: www.intigriti.com(查看原文) 阅读量:10 收藏

  • How vulnerability research and security testing may evolve in the future, based on expert insights and reflections from Intigriti COO Ed Parsons. 

  • How AI is reshaping vulnerability discovery, including the major trends and developments security teams should understand today. 

  • The ‘vulnpocalypse’, and what it signals about the future of AI-assisted hacking. 

  • The risks, opportunities, and practical impact of AI-supported hackers. 

Contextualizing AI’s impact  

Intigriti is one of several crowdsourced security companies experiencing a surge in AI-attributed vulnerability submissions. The impact is also being felt by organizations running their own bug bounty programs.  

In a recent article discussing common AI misconceptions, we explained how Intigriti has seen volume increases not only due to AI productivity gains, but also from growth in researcher numbers and our customer base.  

This article reflects on changes in the industry and where things might go from here. 

For insights, we’ve turned to Ed Parsons, Chief Operating Officer at Intigriti, who brings perspective from a career spent in cybersecurity. From hands-on investigations to leading some of the industry's most respected organizations, Ed spent several years helping organizations defend against threats from nation-state actors and organized criminal groups, work that gave him a grounded view of how adversaries think and operate. 

Before joining Intigriti, Ed served as Vice President of the world's largest member association for cyber professionals and led an international cybersecurity consultancy recognized for its research capability and technical depth. Now, as COO, Ed oversees Intigriti's triage, product, and engineering functions, and serves as the company's CISO.  

His position sits at the heart of the questions this article explores. When AI changes the economics of vulnerability discovery, the pressure lands squarely on his teams to maintain signal quality at scale. Ed's view is shaped not by theory, but by hacker activity on our platform: how AI-assisted submissions are already shifting the demands on customer programs, what that means for the humans and systems processing them, and how platform-driven security services need to evolve. 

Changes in the technology landscape typically affect cybersecurity by creating opportunities for both attackers and defenders. Earlier examples include the shift toward cloud infrastructure and cloud native technologies, and the impact of penetration testing frameworks and scanners on offensive security. 

In 2025, we saw advances in the use of AI for vulnerability discovery. Improvements in the performance and efficiency of Large Language Models (LLMs) for vulnerability discovery led to the democratisation of hacking LLMs. Autonomous security research moved from proof-of-concept to production infrastructure, culminating in the integration of AI-assisted penetration testing natively into Kali Linux, the popular hacking distribution. 

For context, this timeline tracks major advances in AI for vulnerability discovery.  

Major advances timeline in AI for vulnerability discovery.  

The same capabilities have allowed hackers to discover and exploit vulnerabilities at an accelerated pace. FIRST Vulnerability Forecast Feb 2026, predicts a (median) 60,000 CVEs this year, up from almost 50,000 in 2025 and 40,000 in 2024, according to data gathered by Jerry Gamblin.

The febrile environment around the phased release of Claude Mythos, together with Project Glasswing, from Anthropic, has led to speculation that we have entered a ‘vulnpocalypse’, where vulnerabilities can be discovered and exploited faster and cheaper than they can be patched.

For many in the industry, it feels like we’ve been in that situation for a while. Among the deluge of hot takes, beneath sophistic calls to accelerate patching, there is speculation about the demise of vulnerability research and bug bounties. Some imagine a world without human security researchers, seeming to ignore the demand for novel research created by mass adoption of AI, both to secure the technology itself and the proliferation of AI-generated code.

The age of AI-powered/supported hackers is upon us, and the impact is clear. As a crowdsourced security company receiving thousands of vulnerability submissions every year, Intigriti sees how AI technology is being used by security researchers.

  1. Many hackers are leveraging AI in their workflows, contributing to a rise in the average number of submissions per researcher.

  2. AI has lowered the barrier to entry for security research and accelerated vulnerability discovery.

  3. AI has the potential to improve report language and overall quality, which could accelerate processing.

We are also seeing a higher volume of AI-generated out-of-scope submissions and abuse of technology, which creates work without adding value. This has impacts on the whole vulnerability lifecycle, from discovery through to validation and remediation.

The ability of LLMs to discover vulnerabilities has led to speculation over the future of vulnerability research and the role of human actors therein. Beyond the excitement about new model releases and the marketing campaigns, it’s worth noting that:

  • Researchers are already finding bugs in AI and discovering vulnerabilities by using the technology in novel ways.

  • Organizations are finding incredible value through creative, meaningful engagement with the hacker community.

  • The remarkable advances in vulnerability discovery in software aren’t seen across all vulnerability classes and technologies.

  • The results of AI testing tools don’t always meet expectations.

Nevertheless, at Intigriti, we believe this is a paradigm shift, characterised by unprecedented scale and speed, and requires a rapid adaptation. While the situation is developing, in this ‘new normal’, our focus remains on the problems we understand well.

These include creating maximum impact for customers while operating at a significantly larger scale and supporting researchers working with AI while challenging behaviours that threaten the integrity of crowdsourced security.

At Intigriti, we acknowledge that AI is disrupting vulnerability research and security testing, largely through the automation of discovery across certain classes and technologies. It is changing the way security researchers work, with many embracing AI in their workflows. Hybrid (human and AI) approaches will remain essential to discover novel vulnerabilities and drive new applications of AI to vulnerability research.

The pace of change and adoption of AI-driven products will also create demand for validation and reproduction, while shifting customer expectations further away from traditional (service) delivery methodologies.

AI will not only change the way security researchers work, but also how they create value. As we’ve stated, ethical hackers and threat actors already use AI in their workflows. Increasingly, they will operate at a higher level of abstraction: orchestrating AI, validating its output, and ensuring its safe use. The elite will build proprietary models and workflows based on their own expertise, scaling their impact.

Increased adoption of AI for vulnerability research and security testing will also generate demand for the processing of machine-generated output. This will result in more need for automation, and the application of deterministic and agentic AI, like Intigriti’s AI Triage Assistant, into validation, reproduction, prioritisation, and remediation. This volume, combined with improvements in model accuracy, will lead to greater agency, challenging current expectations about ‘humans in the loop’, and precisely where human intelligence can provide most value. We also need reliable safeguards for AI testing tools.

The promise of AI-driven testing will accelerate the industry trend towards more continuous, scalable, and cost-effective forms of assurance that mirror the threats organisations face. Crowdsourced security already offers these properties and complements AI-driven approaches better than traditional penetration tests.

At Intigriti, we have a unique perspective on how hackers are using AI, its impact on vulnerability discovery generally, and the associated operational challenges. We are experimenting, learning, and improving based on feedback from researchers and customers on how to deploy AI and reflecting those lessons in our approach.

As AI develops, applied security research advances, and products mature, but our principles remain the same.

  • As we develop new AI features, we’ll prioritize "giving back" to the community. After all, the world will always need security researchers!

  • We believe in transparency about how we use AI: The model card has been updated to maintain consistency on data privacy principles.

  • We do not allow third parties to train on the data.

  • Humans remain responsible and accountable for the application of AI to our work.

For more AI-related thought leadership, take a look at our latest series and read more about ‘Common AI misconceptions debugged’, ‘The AI future of Bug Bounty’, ‘Vulnerability disclosure for AI safeguards’, which discusses how open programs should be and what incentives are necessary, and ‘How AI is leveraged to enhance the Intigriti platform’.

If you have any questions regarding the content in this article, please reach out to your designated manager. Or, if you are new to Intigriti, follow us on socials, comment on our posts, check out our knowledge base, and contact the team for more information.  


文章来源: https://www.intigriti.com/blog/business-insights/vulnpocalypse-now-how-ai-is-changing-vulnerability-discovery
如有侵权请联系:admin#unsafe.sh