Source ledger checked July 20, 2026

Bug discovery is inflating.

The public record is small. The signal is real.

Bugflation is the gap between AI-accelerated vulnerability discovery and the slower human systems that validate, patch, and deploy fixes. We track real advisories, real CVEs, named AI systems, and attribution labels you can audit. CopyFail (CVE-2026-31431) is the case that made the term unavoidable.

98
Public entries in the source ledger
383
CVE IDs explicitly tracked
73
Critical or high-impact entries
340
Primary and corroborating source links
01 - The thesis

The scarce resource is moving from finding bugs to handling findings.

AI-assisted systems are starting to show up in accepted disclosure workflows. The right response is not panic or dismissal; it is better intake, faster validation, and patch pipelines that can absorb the new volume.

Discovery is cheaper

CopyFail, Big Sleep, AISLE, Claude, DepthFirst, Palo Alto, Security Copilot, XBOW, and bug-bounty Hackbots show different versions of the same economic shift: more vulnerability hypotheses can be generated and tested per unit of expert time.

Attribution is uneven

Some advisories directly name an AI system. Others rely on an operator write-up plus a public CVE. The index labels that difference instead of hiding it in a single score.

Validation is the tax

More reports are not automatically more security. Maintainers need reproducible evidence, duplicate detection, exploitability review, and regression tests to turn claims into shipped fixes.

Patch capacity is strategy

The teams that handle bugflation well will not be the ones that find the most issues. They will be the ones that close the loop from credible report to deployed patch fastest.

02 - Credited systems

Named systems in the public record.

These are not model leaderboards. They are evidence profiles for systems that appear in public vulnerability-discovery workflows.

Anthropic / Project Glasswing AI agent

Claude Mythos Preview

Anthropic's restricted cyber-capable frontier model, with public credits across FreeBSD, Firefox, curl, Squid, Symfony, and Project Glasswing's CVD ledger.

  • Indexed entries6
  • CVE IDs tracked25
  • Critical/high entries3
Google DeepMind / Project Zero AI agent

Google Big Sleep

The first public AI vulnerability-research agent with accepted real-world findings across SQLite, Chrome V8, and Apple WebKit.

  • Indexed entries7
  • CVE IDs tracked21
  • Critical/high entries6
Google and Linux kernel contributors AI agent

Google Gemini security review agents

Gemini CLI and experimental Gemini review agents with explicit discovery credits in accepted Linux kernel fixes.

  • Indexed entries1
  • CVE IDs tracked4
  • Critical/high entries1
Microsoft Autonomous Code Security Platform

Microsoft MDASH

Microsoft's multi-model agentic scanning harness, credited by Microsoft with 16 public CVEs across Windows networking and authentication code.

  • Indexed entries2
  • CVE IDs tracked16
  • Critical/high entries1
Z.AI and collaborating researchers AI agent

Z.AI GLM

Z.AI's GLM models now have direct upstream discovery credits across FreeBSD kernel and userland advisories and Apple WebKit.

  • Indexed entries2
  • CVE IDs tracked9
  • Critical/high entries2
AISLE Platform

AISLE

An autonomous security analyzer with a large public registry and validated credits across OpenSSL, FreeBSD, curl, Apache, Chrome, Squid, and other projects.

AISLE CVE discovery registry 268 assigned CVEs claimed

  • Indexed entries10
  • CVE IDs tracked53
  • Critical/high entries5
Anthropic and collaborators AI agent

Claude / Anthropic Research

Public Claude-assisted disclosure credits outside the Mythos-only record, spanning browsers, operating systems, cryptography, office documents, cloud auth, CMSs, and Microsoft/Apple platform bugs.

  • Indexed entries19
  • CVE IDs tracked73
  • Critical/high entries14
GitHub Security Lab AI agent

GitHub Security Lab Taskflow Agent

GitHub Security Lab's open-source AI-powered audit framework, with human-validated advisories across major web applications and frameworks.

GHSL Taskflow and named GHSL-agent advisory audit 43 public advisory pages

  • Indexed entries2
  • CVE IDs tracked24
  • Critical/high entries2
OpenAI and security partners Program

OpenAI Daybreak

OpenAI's defensive vulnerability-research program, combining frontier cyber models, Codex Security, expert validation, and coordinated patching.

  • Indexed entries7
  • CVE IDs tracked11
  • Critical/high entries5
Theori / Xint Platform

Xint Code

The AI-assisted vulnerability research system credited in CopyFail, with a broader public record spanning Linux, Apple platform, PostgreSQL, and tracker-backed findings.

Xint public bug tracker 51 public tracker rows

  • Indexed entries5
  • CVE IDs tracked13
  • Critical/high entries3
Bynario Platform

BynarIO AI

Bynario's AI-driven vulnerability-research pipeline, with direct Apple and Linux upstream credits across binary analysis, kernel discovery, validation, and patching.

  • Indexed entries3
  • CVE IDs tracked3
  • Critical/high entries2
Zellic AI / V12 Platform

V12

Zellic's agentic security platform, with public accepted findings in the Linux kernel, Rabby Wallet, NEAR Intents, and Miden Node.

  • Indexed entries4
  • CVE IDs tracked1
  • Critical/high entries2
DepthFirst AI Platform

DepthFirst

DepthFirst's autonomous low-level-code analysis platform, with accepted NGINX, FFmpeg, and Apache HTTP Server campaigns.

  • Indexed entries4
  • CVE IDs tracked20
  • Critical/high entries2
Striga / ISEC Platform

Striga AI

Striga's AI-based source-code auditing platform, with public CVE credits and research write-ups across Apache httpd, Tomcat, Ollama, axios, and Mattermost Desktop.

Striga CVE tracker 20 public CVE records

  • Indexed entries3
  • CVE IDs tracked20
  • Critical/high entries2
ZeroPath Platform

ZeroPath AI SAST

ZeroPath's AI-native SAST and security-research workflow, with public CVE-backed and upstream-patched findings across ProFTPD, Spinnaker, better-auth, FFmpeg, sudo, and other open-source projects.

ZeroPath Wall of Fame 47 fixed public records

  • Indexed entries8
  • CVE IDs tracked14
  • Critical/high entries8
XBOW Platform

XBOW

An autonomous AI-driven penetration-testing platform with public bug-bounty milestones and self-reported critical Microsoft and Exim RCE credits.

  • Indexed entries4
  • CVE IDs tracked4
  • Critical/high entries4
Palo Alto Networks Program

Palo Alto frontier AI scan

Palo Alto Networks' May 2026 frontier-model scan wave, reported as 26 CVEs across more than 130 products, with exact per-CVE model attribution unpublished.

  • Indexed entries1
  • CVE IDs tracked26
  • Critical/high entries1
Tencent Xuanwu Lab / XlabAI Team Platform

Atuin Automated Vulnerability Discovery Engine

Tencent Xuanwu Lab's LLM-based discovery engine, with direct public credits across cryptography, Vault, PostgreSQL, Windows, Linux, and FreeBSD.

  • Indexed entries4
  • CVE IDs tracked8
  • Critical/high entries4
Google Open Source Security Team Platform

Google OSS-Fuzz AI

LLM-enhanced fuzz-target generation and triage inside Google's OSS-Fuzz ecosystem.

  • Indexed entries1
  • CVE IDs tracked1
  • Critical/high entries0
Microsoft Threat Intelligence AI agent

Microsoft Security Copilot

Microsoft's AI security assistant, publicly tied to a GRUB2, U-Boot, and Barebox bootloader vulnerability campaign.

  • Indexed entries1
  • CVE IDs tracked20
  • Critical/high entries1
OpenAI AI agent

OpenAI Aardvark / Codex Security

OpenAI's agentic security researcher and Codex Security workflow, now carrying direct credits across browsers, operating systems, network services, and media tooling.

  • Indexed entries9
  • CVE IDs tracked30
  • Critical/high entries6
pwn.ai Platform

pwn.ai

An autonomous agentic pentesting platform with an accepted Chrome credit and a public CVE-backed embedded-device RCE disclosure.

  • Indexed entries2
  • CVE IDs tracked2
  • Critical/high entries1
GitHub Security Lab AI agent

GitHub Security Lab AI agent (unspecified)

AI-assisted GitHub Security Lab research that the official AI-agent index verifies without identifying the particular agent or workflow on the individual advisory.

GHSL system-unspecified AI-agent advisories 2 public advisory pages

  • Indexed entries1
  • CVE IDs tracked8
  • Critical/high entries1
HackerOne ecosystem Policy

HackerOne Hackbots

The policy layer around AI-assisted vulnerability discovery: human-in-the-loop rules, accountable operators, and bounty eligibility.

  • Indexed entries0
  • CVE IDs tracked0
  • Critical/high entries0

Evidence index is editorial: direct upstream credits score higher than self-reported attribution. It is not a model capability benchmark. Read the methodology.

03 - Latest findings

Real entries, source links first.

Every finding page includes an attribution label and references. Direct upstream credits and self-reported AI attribution are intentionally kept separate.

See all findings

04 - Timeline

The public milestones are concrete.

Nov 2024

Google says OSS-Fuzz AI found CVE-2024-9143 in OpenSSL

LLM-generated fuzz targets produce a 26-vulnerability OSS-Fuzz milestone, anchored by OpenSSL.

Nov 2024

Big Sleep publishes the first public real-world AI-agent vulnerability finding

Project Zero describes an exploitable SQLite stack buffer underflow found before release.

Feb 2025

HackerOne formalizes rules for AI-assisted bug hunting

The Hackbots policy puts human validation, scope compliance, and operator accountability on record.

Mar 2025

Microsoft Security Copilot enters the bootloader record

Microsoft describes a 20-CVE GRUB2, U-Boot, and Barebox campaign accelerated by Security Copilot.

Jul 2025

Google says Big Sleep helped cut off imminent SQLite exploitation

CVE-2025-6965 becomes the clearest public case of AI-assisted discovery paired with threat intelligence.

Jan 2026

AISLE turns OpenSSL into a sustained autonomous-analysis benchmark

AISLE reports 20 OpenSSL CVEs across three coordinated releases, with accepted fixes on many entries.

Mar 2026

Claude-assisted Firefox credits appear at browser scale

Anthropic and Mozilla document Firefox 148 findings, with Mozilla advisories crediting Claude across CVEs.

Mar 2026

XBOW reports autonomous critical Microsoft RCE findings

Microsoft/NVD records confirm critical CVEs; XBOW supplies the AI-attribution claim.

Apr 2026

CopyFail turns bugflation into a concrete kernel-security story

Xint Code scales a Taeyang Lee AF_ALG/page-cache insight across Linux crypto and surfaces CVE-2026-31431.

Apr 2026

ZeroPath publishes critical Spinnaker and ProFTPD findings

ZeroPath Research adds a self-reported AI-assisted trail for three CVE-backed RCE or RCE-adjacent findings across deployment and FTP infrastructure.

Apr 2026

AISLE expands from OpenSSL into FreeBSD core

FreeBSD credits AISLE Research Team for dhclient RCE, dhclient heap corruption, and libnv stack corruption advisories in the April 29 release.

May 2026

Striga publishes Apache httpd scan details

Striga says an open-weights scan costing under $100 surfaced CVE-2026-23918; Apache credits Dmitruk/striga.ai and Strzalkowski/isec.pl.

May 2026

Bynario AI enters the Linux kernel record

Linux commits for CVE-2026-31532 and CVE-2026-31694 carry Assisted-by: Bynario AI; the CAN write-up details discovery, validation, and patching.

May 2026

Palo Alto reports a 26-CVE frontier-AI scan wave

Palo Alto says frontier models drove the majority of its May Patch Wednesday findings, while exact per-CVE model attribution remains unpublished.

May 2026

DepthFirst publishes NGINX Rift

DepthFirst says its autonomous low-level analysis platform found four confirmed NGINX CVEs, led by CVE-2026-42945.

May 2026

Anthropic opens a CVD dashboard for Mythos findings

Project Glasswing now exposes a public ledger of disclosed, patched, CVE/GHSA-backed open-source findings attributed to Claude Mythos Preview.

Jun 2026

OpenAI Daybreak makes Patch the Planet findings public

Public patches and advisories connect model-assisted work to dnsmasq, FreeBSD, OpenBSD, Firefox, Chrome, and the HTTP/2 Bomb campaign.

Jun 2026

Apple credits three named AI systems in one WebKit release

Apple directly names Codex Security, Claude, and researchers using Z.AI GLM across five WebKit CVEs in its June 29 security notes.

Jul 2026

Shared AI attribution becomes part of the ledger model

Squid, FreeBSD, Apache, and Microsoft records show independent systems converging on the same CVEs, without increasing the global unique-CVE count.

05 - Analysis

Short, sourced, operational.

All articles

06 - What to do

Make the patch path as scalable as the search path.

01

Require reproducibility.

AI-assisted reports should arrive with affected versions, input, expected result, actual result, and a minimized proof path. Reject vibes, reward evidence.

02

Track attribution honestly.

Separate upstream credit, self-reported tool usage, and secondary reporting. The distinction makes the data stronger, not weaker.

03

Budget for triage.

More submissions mean more validation work. Invest in duplicate detection, maintainer playbooks, and regression tests before the queue spikes.

04

Use the same leverage.

Run guided variant analysis after every serious fix. Attackers will search nearby code. Defenders should search it first.