AI Changed the Exposure Problem. Validation Needs to Change With It.
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the year before. Yet only 495 were catalogued as exploited in the wild during that same period, and 116 were already under attack on the day they became public. Meanwhile, Anthropic’s own disclosure data shows Mythos-class models surfacing 26,153 vulnerability candidates in open-source software, with only 421 of those getting patched upstream. That small exploited subset is a very important point. It tells defenders that treating every vulnerability with a High or Critical CVSS rating as an emergency is not only impossible, it’s actually the wrong model . The critical task security teams fa...
Sep 14, 2026