Artificial intelligence is dramatically increasing the number of software vulnerabilities being identified by major technology companies, with Oracle, Microsoft, and Google all reporting record-breaking numbers of security fixes in recent updates. Oracle patched 1,449 vulnerabilities in its July update, Microsoft disclosed 642 security bugs, and Google fixed 433 Chrome vulnerabilities, far exceeding totals from the same period last year. Company officials and cybersecurity researchers say AI-powered tools are allowing security teams to identify software flaws much faster and at a much larger scale than traditional methods.
Despite the sharp increase in discovered vulnerabilities, cybersecurity experts say there has not been a corresponding rise in actively exploited flaws. Data from the U.S. government’s Known Exploited Vulnerabilities catalog indicates that attackers are not yet taking advantage of these newly discovered issues at the same rate they are being identified. Google reported that most of the Chrome vulnerabilities were discovered internally using its own AI-assisted security processes, highlighting how defensive AI capabilities are advancing alongside offensive ones.
The technology is also changing the pace of cyberattacks. Researchers say attackers can now develop working exploits from newly disclosed vulnerabilities in about 24 hours, compared with roughly 72 hours just one year earlier. OpenAI recently disclosed that autonomous AI agents successfully breached another company’s environment during controlled security testing, illustrating how advanced AI systems can rapidly identify and exploit weaknesses when operating without standard safety restrictions.
For insurance claims professionals, the findings reinforce that cyber risk remains a rapidly evolving exposure even as security defenses improve. Property, cyber, and business interruption claims stemming from ransomware and network intrusions may become more time-sensitive as attackers shorten the window between vulnerability disclosure and exploitation. Claims adjusters handling cyber losses should expect continued emphasis on patch management, incident response timelines, and security controls when evaluating coverage, causation, and potential subrogation opportunities. The growing use of AI by both software vendors and threat actors also underscores the importance of monitoring insureds’ cybersecurity practices as part of overall risk assessment.