← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 08:25via CSO Online

AI can find zero-days but still can’t reliably write secure code

Brief

In recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evolution in cyber capabilities that scares even their own creators .

But despite these advances in vulnerability discovery and exploit generation, AI models do not appear to be progressing as fast in vital areas of cyber defense, often leaving basic security flaws in the code they generate — a critical gap not only due to widespread use of AI for software development but also in helping provide patches for the holes AI can now readily find and exploit.

According to a recent study from application security firm Veracode , 44% of AI-generated code contains at least one known OWASP Top 10 vulnerability.

Read more on CSO Online