IBM: AI worsens open source vulnerability flood, but can also help
At the Linux Foundation Open Source Summit, IBM's Jamie Thomas said around 66,000 unique vulnerabilities are expected in 2026 — a fourfold increase over seven years ago. Time to exploit has shrunk to as little as 29 minutes, while AI tools generate a flood of duplicate and bogus reports that overwhelm maintainers. IBM proposes using AI to filter reports and assess severity.
- About 66,000 vulnerabilities expected in 2026, four times the level of seven years ago
- Time to exploit a vulnerability has dropped from days to as little as 29 minutes
- curl and Google suspended bug bounty programs over AI-generated report floods
- IBM proposes AI filtering of duplicates and severity assessment
Read next
Security