Bottom line: The emergence of autonomous AI models for vulnerability identification may accelerate the pace of software patches but also introduces new risks and challenges for security teams.
What's happening: Frontier AI models, developed by Anthropic and OpenAI, are now capable of autonomously identifying vulnerabilities in production software, similar to the work of human researchers, but with an estimated 60-day turnaround time. For example, researchers from Google and Microsoft have already successfully used these models to identify vulnerabilities in production software, including a critical vulnerability in the Apache Kafka 3.6.0 release.
What to do: Security teams should prioritize monitoring for signs of autonomous vulnerability identification and review their incident response plans to address the potential risks and challenges introduced by these AI models.