AI Bug Hunts Are Swamping Human Triage

The bottleneck is shifting from finding bugs to absorbing them. Cheap AI runs can now hand defenders a stack of reproducible flaws faster than teams can verify impact, sort priority, and ship fixes, and that pressure hits hardest in widely embedded code that sits inside other products. This week brought both sides of that shift. A security startup said an autonomous agent found 21 confirmed FFmpeg zero-days with reproducible proofs of concept for about $1,000 a run, while Google shipped Chrome 149 with 429 security fixes, the most ever in one release, after overhauling its bounty program to handle a flood of AI-generated reports. The point is not the exact count; it is the growing gap between vulnerability throughput and human response capacity.

Part of the PlainSec briefing for 2026-06-07

Sources