A security startup called Depthfirst used an autonomous AI agent to discover 21 previously unknown zero-day vulnerabilities in FFmpeg — a widely used open-source media library — for roughly $1,000 in compute costs. Some bugs had existed in the codebase for over 20 years. Separately, Google shipped Chrome 149 with patches for a record 429 security bugs, over 100 of which are critical or high severity. The two events highlight a growing asymmetry: AI tools are finding vulnerabilities faster and cheaper than humans can triage and fix them. Other examples include an AI agent finding an RCE flaw in Redis and Mozilla patching 271 Firefox bugs found by Anthropic's Mythos model in a single pass. The core challenge has shifted from discovery to remediation — patching and deploying fixes at the pace AI can generate them.

3m read timeFrom thenextweb.com
Post cover image
96.8K Impressions4 Comments