Just in:
NVIDIA opens viral protein map with BioNeMo pipeline // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services // Bitget chief links $387.5 million breach to North Korea // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Long-lived Linux kernel flaw permits root container escape // MIHAS Reaffirms Malaysia’s Pivotal Role in the Growing Global Halal Economy // Kweichow Zhenjiu Partners with CDF Cruise to Host Exclusive Tasting Event Aboard “Adora Magic City” // After the FOMC: my macro convictions for 2027 // Microsoft equips smaller Surfaces with Snapdragon X2 Plus // Hawaii braces as Hurricane Nolo threatens catastrophic flooding // Bitcoin rally lifts Tesla holdings towards $1 billion // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // Discord deploys machine learning to classify user ages // MIHAS Awards 2026 Celebrates Excellence and Sets New Benchmark for Innovation, Sustainability and Digitalisation Across the Global Halal Ecosystem // Green SM starts Amsterdam electric taxi pilot // Iran proposes uranium transfer in US diplomacy push // Salesforce patches Agentforce flaws enabling zero-click data theft // RemControl enables remote takeover of Android banking devices // UNGA 81 Day 3: Gaza, Iran War And The Limits Of Multilateral Diplomacy //

AI vulnerability race gathers speed

Commercial artificial intelligence models are advancing quickly in vulnerability research and exploit development, sharpening concern across the cybersecurity industry that tools built for productivity and defence could also lower the barrier for offensive misuse. A study by Forescout’s Vedere Labs found that commercial systems now outperform open-source and underground alternatives in identifying software flaws, while more than half of the models tested were able to generate exploits with varying degrees of autonomy or user guidance.

That marks a notable shift from the picture Forescout outlined in mid-2025, when failure rates remained high across vulnerability research and exploit development tasks. In the earlier study, 48 per cent of models failed the first vulnerability-research task, 55 per cent failed the second, 66 per cent failed the first exploit-development task and 93 per cent failed the second. In its follow-up work, the company said progress over even a three-month testing window was “remarkable”, with newer reasoning systems solving tasks that had been out of reach only weeks earlier.

Forescout’s testing suggests the strongest gains are now concentrated in mainstream commercial offerings rather than in openly distributed or illicitly marketed “uncensored” tools. In its breakdown of 17 commercial models, several products from OpenAI, Google, DeepSeek and specialist offensive-security assistants successfully handled at least some stages of both flaw discovery and exploit construction. Open-source models lagged badly, with none of the 16 tested generating a working exploit for the first exploit-development task. Underground models, often advertised in criminal forums as unrestricted alternatives, were described as unstable, technically weak and poor value when compared with commercial systems.

Even so, Forescout stopped short of arguing that fully autonomous AI hacking has arrived. Its researchers said many models still required substantial steering, correction and debugging help from the user, and warned that polished but inaccurate responses can mislead inexperienced operators. That caveat is important because it suggests the present risk is less about a push-button machine attacker and more about a sharp increase in the speed, scale and accessibility of skilled or semi-skilled exploitation work.

The wider industry backdrop points in the same direction. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87 per cent of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk over 2025. The International AI Safety Report 2026 said AI systems are particularly effective at discovering software vulnerabilities and writing malicious code, adding that criminal groups and state-associated attackers are already using general-purpose AI in their operations. It also cited a cyber competition in which an AI agent identified 77 per cent of vulnerabilities in real software, placing it among the top-performing teams.

Pressure on defenders has intensified as frontier AI companies begin releasing specialised cyber models under controlled programmes. Reuters reported on April 14 that OpenAI introduced GPT-5.4-Cyber for vetted security professionals, a week after Anthropic announced Mythos under its Project Glasswing initiative. Reuters said Anthropic’s model had already found thousands of major vulnerabilities in operating systems, browsers and other software. Forescout, commenting on that development, said such systems could expose serious flaws at machine speed and compress the time between discovery and exploitation.

That compression matters most in environments where patching is slow or operationally risky. Forescout noted that critical infrastructure operators may patch only every few months to avoid disrupting energy supply or manufacturing, while hospitals must weigh security fixes against patient-safety concerns. In those sectors, a sudden rise in AI-assisted vulnerability discovery could leave organisations exposed for longer, especially when vendors have not yet produced patches or asset inventories are incomplete.

There is also a second layer to the threat. Reuters reported in January that researchers found thousands of internet-accessible open-source large language model deployments operating outside the guardrails of the main AI platforms, with hundreds showing evidence that safety controls had been stripped away. Researchers warned such systems could be repurposed for phishing, spam and disinformation, illustrating how defensive or neutral AI capability can spill into criminal use once controls weaken or disappear.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
MIHAS Awards 2026 Celebrates Excellence and Sets New Benchmark for Innovation, Sustainability and Digitalisation Across the Global Halal Ecosystem // MIHAS Reaffirms Malaysia’s Pivotal Role in the Growing Global Halal Economy // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // Data displaces skills as threat hunting barrier // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Keralam Govt Stays Implementation Of Minimum Marks In Schools // OpenAI agents accessed three U.S. government websites // Salesforce patches Agentforce flaws enabling zero-click data theft // Google, OpenAI and Anthropic advance AI standards plan // Discord deploys machine learning to classify user ages // Microsoft equips smaller Surfaces with Snapdragon X2 Plus // Long-lived Linux kernel flaw permits root container escape // Binance opens bStocks access to UAE users // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // Iran proposes uranium transfer in US diplomacy push // Bitget chief links $387.5 million breach to North Korea // UNGA 81 Day 3: Gaza, Iran War And The Limits Of Multilateral Diplomacy // Trump targets $810 million in congressionally approved spending // NVIDIA opens viral protein map with BioNeMo pipeline //