Research examining autonomous vulnerability discovery frames the question directly: the same capability that produced ten thousand disclosed findings can produce ten thousand undisclosed ones.
This desk describes capability rather than novelty, and the capability here is symmetric in a way defensive tooling usually is not.
Most Security Technology Is Not Symmetric
An intrusion detection system does not help an attacker. A backup does not help an attacker. Even fuzzing infrastructure is somewhat asymmetric in practice, because the effort of turning a crash into an exploit favoured the party with time and context.
A system that autonomously produces working exploitation chains removes that asymmetry. The finding is equally useful whichever direction it faces, and the only thing determining direction is who is running it.
The Advantage Is Temporary By Construction
A defensive coalition running this capability produces a real advantage while it is the only party doing so at scale — but that advantage is realised only where findings are actually fixed, and the six per cent rate at 26-0410 says most are not.
So the defensive lead is being converted into fixes slowly, while the capability itself becomes more widely available. Those two curves are not going in a comfortable direction relative to each other.
What Is Actually Protective Here
Not secrecy about the technique, which is published. The protective factors are cost, which falls; access controls at model providers, which are policy rather than physics; and the remediation capacity to convert findings into patches faster than an adversary converts them into exploits.
Only the last of those is something the defensive side can increase, and it is the one nobody is funding at the scale of the discovery.
This is an analysis file built on published research, listed below. We describe capability rather than predicting adversary adoption, and we are not aware of documented use of this class of capability by an adversary at comparable scale. Corrections: corrections@forensicpost.com.
- When AI becomes the attacker: Project Glasswing and the autonomous zero-day eraCloud Security Alliance
- Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance