AI Is Finding More Vulnerabilities but Open Source Needs More People to Fix Them
Infosecurity Magazine, Friday, October 2nd, 2026
OpenSSL reports AI-driven vulnerability reports rising from about 9 to 70 a month, straining the experts needed to triage and fix them.
AI tools have sharply increased vulnerability reports to OpenSSL, from roughly nine a month in 2025 to as many as 70, yet each still requires an experienced engineer to assess validity and risk, build and test a fix, and coordinate disclosure.
Of just over 400 reports in the past year, about one in ten produced a CVE.
The author warns that the gap between AI-scale discovery and limited human remediation capacity is becoming a security problem for open source, and calls for more investment in people who can fix flaws.