The bottleneck is gone once a model can turn a scanner finding into a working exploit without human handoff. That speeds up weaponization and makes code-review triage a weaker defense when teams assume exploit development still takes manual effort.
Intruder says it built an LLM-driven pipeline that found and exploited a remote SQL injection zero-day, CVE-2026-3985, in a WordPress plugin used by more than 300,000 sites. The system first narrows the model to the small set of related functions, so the bug stays in context long enough to become an exploit instead of a vague code finding.
If defenders and researchers use AI to read code or generate fixes, attackers can use the same workflow in reverse. The risk is not just faster discovery; it is faster conversion from suspicious code to active exploitation.