The New Arms Race: AI Just Picked a Side... Both Sides
Attackers need one crack; defenders must cover every wall. Discover how AI accelerates zero-day discovery and why security leaders must rethink patch cycles.

Attackers need one crack; defenders must cover every wall. Discover how AI accelerates zero-day discovery and why security leaders must rethink patch cycles.

For as long as there's been software, there's been an unfair fight. The attacker needs to find one crack. The defender has to cover every wall, every window, every door, forever. That asymmetry is the oldest problem in security, and until recently, it moved at human speed on both sides.
That's over.
Bug bounty programs aren't seeing more submissions because more humans decided to go hunting this year. They're seeing more submissions because AI systems are reading code the way we always wished a human could, except they don't get tired, don't get bored halfway through a legacy codebase, and don't need a paycheck to keep going. Zero-days that used to surface once a researcher happened to stumble onto the right function, at the right time, in the right mood, are now surfacing because something is looking at everything, continuously.
The old defender's math was: cover it all, and hope the one gap you missed isn't the one they find. AI doesn't change that math. It just runs it exponentially faster, on both sides of the table at once.
Here's the part that should keep security leaders up at night: AI isn't a weapon we get to keep. It makes the good better and the bad worse, in the same breath, for whoever picks it up first. A defensive team using AI to scan its own stack finds bugs before an attacker does. An attacker using the same class of tooling finds the bugs the defensive team's older processes were never fast enough to catch. Same technology. Opposite outcomes. Whoever adapts their process around it first wins that round.
This isn't a new front in an old war. It's the same asymmetry we've always had; one crack versus every wall; except now the side hunting for the crack has a machine that never sleeps, and the side building the wall is often still running on quarterly patch cycles and a backlog nobody's gotten to yet.
Every security leader watching bug bounty numbers climb this year has had the same instinct: wait for it to level off. It won't. This is what "exponential" actually looks like from the inside; not a spike you ride out, but a new floor. The organizations treating this quarter's numbers as an anomaly are the ones who'll be caught flat-footed when next quarter's numbers are worse.
So what do you actually do with that?
Nobody chose this pace. It arrived. And the organizations that survive the next few years won't be the ones with the cleverest defenses on paper; they'll be the ones who accepted, early, that the old rhythm of finding and fixing is already gone.
The bad guys only ever needed one crack. Now they've got a machine helping them look for it around the clock. The only sane response is to stop defending at human speed too.