AI Security Boom: Armadin Found 90+ Zero-Days as Critical CVEs Jump to 600/Month
kevinnbass · x · 2026-10-07
a16z data shows reported critical vulnerabilities across 21 major software companies (Apple, AWS, Microsoft, Google) never exceeded 100 per month in four years — since spring they've jumped to over 600 per month.
Kevin Mandia explains how AI-based attacks find logic flaws rather than code flaws in custom applications, exhausting all routes at all times. Armadin has found over 90 zero-days at customer production sites since January, with models post-trained by real red teamers who can develop actual exploits — none discovered via source code review.
Related event: Mandiant Founder's Armadin Uses AI Agents to Uncover 90+ Zero-Days(3 posts)→
More from Safety
- OpenSSH drops sshd sandboxing on macOS as SDK 27 removes key API — jedisct1 · 2026-10-07
- vf3 fuzzer unveiled at OAIC claims to outpace Jackalope and libprotobuf-mutator — dyn___ · 2026-10-07
- Harvard releases privacy-preserving agent tool for blood biomarker discovery, +4.18 AUC points median — Harvard · 2026-10-07
- Reddit Guide: Sandbox Untrusted Vibecoded Docker Apps With a socat Gateway and Internal Network — dtdisapointingresult · 2026-10-07
- NYT Op-Ed: A Spy's Guide to Fighting A.I. Propaganda — nytopinion · 2026-10-07
- ChatGPT uploads pasted clipboard images before you even hit send, user finds — Innomen · 2026-10-07