AI News Feed
Market watch
Cybersecurity

IBM Executive Warns of Vulnerability Disclosure 'Tsunami' as AI Strains Open Source Security

IBM's Jamie Thomas told the Linux Foundation Open Source Summit that about 66,000 unique vulnerability disclosures are expected in 2026, four times the level of seven years ago, while AI floods maintainers with duplicate and bogus reports.

Speaking in a keynote titled The Future of Open Source Security in the Age of AI, Thomas said the sheer volume of reports is only one of the pressures on defenders. Attackers are also exploiting flaws far faster than before. Citing publicly available data, she said the time required to exploit a vulnerability has shrunk from days to as little as 29 minutes, and that malware and cyberattacks are rising sharply.

For organizations that depend heavily on open source, the exposure extends well beyond a single project. A flaw in a widely used component can affect hundreds or thousands of downstream applications and businesses. Thomas said criminals frequently do not wait for public disclosure before acting. "We're seeing the time to exploit is actually negative," she said. "Many times we're getting a disclosure and we don't have a patch yet." That leaves defenders answering a growing number of security issues in a shrinking window, while attackers use automation to speed up their operations.

AI adds a further complication. According to TechRadar's account of the keynote, AI-powered tools can identify vulnerabilities and improve software security, but they also generate large volumes of inaccurate, duplicated and otherwise unactionable reports. Large companies with dedicated security teams struggle with such submissions, while many open source projects are run by small groups of developers, sometimes by one person.

Earlier this year, the developers of curl, the widely used open source command-line tool and software library, shut down their HackerOne bug bounty program. They said the financial incentives had produced poorly researched and sometimes entirely fake reports, including AI-generated submissions, in numbers the project's security team could not manage.

Google also suspended its Open Source Software Vulnerability Rewards Program temporarily after a significant rise in invalid and irrelevant reports, many of them apparently AI-generated. As of October 1, 2026, the company is no longer accepting new submissions and plans to reassess the program in early 2027.

Linux creator Linus Torvalds recently said AI-powered bug hunters had made the Linux security mailing list "almost entirely unmanageable." He criticized the heavy duplication of reports, saying different researchers were using the same AI tools to flag vulnerabilities that had already been fixed or at least already reported.

Thomas argued the security community should not abandon AI-enabled vulnerability discovery, but should apply the same technology to help maintainers cope with the workload. The Linux Foundation's Open Source Security Foundation, a collaboration among technology companies, developers and the wider open source community, is positioned to take on part of that effort by strengthening supply chain security. For IBM, the stated priority is reducing the burden on maintainers by making vulnerability management more efficient, with AI-powered tools filtering out duplicate and false reports, assessing the severity of bugs and identifying issues that require urgent attention.