In open source cybersecurity, AI is kind of a problem — but it can also be a solution
The last few years have seen a growing wave of vulnerability disclosures heading towards the cybersecurity industry, and the people working on fixing these flaws are often struggling to keep up.
And while AI is a major contributor to this problem, but also an essential part of the solution.
Speaking at the recent Linux Foundation Open Source Summit, Jamie Thomas, IBM's Chief Client Innovation Officer for Enterprise Security, warned there is “a bit of a tsunami in vulnerability disclosures,” with approximately 66,000 unique entries expected to emerge in 2026 alone.
At the keynote, titled The Future of Open Source Security in the Age of AI, Thomas stressed this represents a fourfold increase compared to seven years ago.
So, how can the cybersecurity industry possibly keep up with this pace, Thomas asked, especially when the expectations placed on developers and security professionals continues to grow? The answer seems to be the same as with everything these days - AI.
Attackers are moving faster than ever The volume of attacks is definitely an issue, but it’s not the only issue.
Cybercriminals are also a lot faster at exploiting them, giving defenders an ever-shrinking window to identify and remediate different security issues.
Citing publicly available data, Thomas said the time required to exploit a vulnerability shrunk from days to as little as 29 minutes.
“And in fact, we're seeing a rapid increase in cyberattacks, as well as malware attacks,” she said.
For businesses that rely heavily on open source, this is definitely cause for serious concern.
A vulnerability in a widely used component can potentially affect hundreds, if not thousands, of downstream applications and businesses.
To add insult to injury, cybercriminals don’t really wait for the cybersecurity community to publicly disclose a vulnerability before they can exploit it.
“We're seeing the time to exploit is actually negative,” she said.
“Many times we're getting a disclosure and we don't have a patch yet.” That is the position the defenders are in, right now.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.