an AI just found 14,090 real security bugs in open source — in two months

Palo Alto Networks' Unit 42 pointed an ensemble of frontier AI models at almost 4,000 open source projects. 99.4% of what it found had never been…

Aliteq
Lena Fischer · AI & Local Compute Editor

The numbers, up front

Unit 42's autonomous system, NOVA (Network and Open-Source Vulnerability Analyzer), scanned 3,915 open source projects over two months using an ensemble of multiple frontier AI models rather than one.

The numbers, up front

It confirmed 14,090 vulnerabilities. 99.4% were previously unreported, and 39.7% (under CVSS 4.0 scoring) rated high or critical severity.

The numbers, up front

Only 4% of findings (557 bugs) were classic memory-safety issues; 92% were semantic and logic flaws — the category static analyzers historically miss.

The numbers, up front

NOVA traced 1,280 flaws into dependency packages and found 4,141 downstream applications exposed through them, 2,776 validated with a working proof-of-concept exploit.

The numbers, up front

Unit 42's own framing: 'the patch window has collapsed' — the old ~55-day gap between disclosure and exploitation no longer describes a world where AI can find and weaponize a bug the same afternoon.

My honest take

This is genuinely double-edged in a way that should make people uncomfortable, not reassured. Unit 42 built NOVA to help defenders, and the numbers are a real public good — 14,090 bugs getting fixed…

Aliteq

Read the full story

an AI just found 14,090 real security bugs in open source — in two months

Read the full story on Aliteq