Frontier AI Models Significantly Accelerate the Discovery of Security Vulnerabilities
Palo Alto Networks Chief Product and Technology Officer Lee Klarich revealed in a blog post that the company, as a launch partner for Anthropic's Project Glasswing, tested frontier AI models such as Claude Mythos starting April 7, resulting in the disclosure of 26 CVEs in the first Patch Wednesday security advisory, far exceeding the usual 5. Klarich emphasized that merely running the models does not automatically solve problems; it requires building an AI scanning framework and adopting a multimodal approach. Meanwhile, Google and Microsoft also reported breakthrough progress in AI-driven vulnerability discovery.

The capability of artificial intelligence models in discovering software vulnerabilities is improving at a rate faster than expected, a trend that is reshaping the landscape of cybersecurity defense.
Palo Alto Networks' Chief Product and Technology Officer Lee Klarich, in a blog post published on Wednesday (May 13), shared the company's insights on how frontier AI models impact cybersecurity. As one of the launch partners for Anthropic's "Project Glasswing," Palo Alto Networks has been testing the Claude Mythos model since April 7. Additionally, according to Klarich, the company is also evaluating Claude Opus 4.7 and OpenAI's GPT 5.5-Cyber model.
After initially applying these models, Palo Alto Networks disclosed 26 Common Vulnerabilities and Exposures (CVEs) in its Patch Wednesday security advisory, whereas the company typically discloses around 5 vulnerabilities per advisory. Klarich specifically noted that none of these newly disclosed vulnerabilities have been found to be exploited in the wild.
However, Klarich cautioned that simply running these models does not automatically solve vulnerability issues. Organizations need to build "AI scanning frameworks" and integrate contextual information, guardrails, and threat intelligence to effectively discover and remediate these flaws at scale. He also advised security teams to adopt a "multi-modal approach" to identify a more comprehensive set of vulnerabilities.
In the long term, further integrating these models into the software development lifecycle will be a key direction. "This is the light at the end of the tunnel," Klarich wrote in the blog post, "a future where software is secure by design."
He also issued a warning: organizations have only a "three-to-five-month window" to get ahead, as AI-driven exploitation is likely to become the new norm.
This trend has been corroborated by multiple parties in the industry. On Monday, researchers from Google's Threat Intelligence Group reported that AI has been used to develop a working zero-day exploit. On Tuesday, Microsoft announced that its AI systems discovered 16 new vulnerabilities in its network and authentication stacks, including 4 critical remote code execution vulnerabilities.