Analysis for a source-led vulnerability ledger.
Short pieces on what the public record shows, what it does not show, and what security teams should change as AI-assisted discovery scales. Follow new entries through the RSS feed.
July 2026 Source Audit: The Public Ledger Broadens
A primary-source audit adds post-cutoff disclosures, backfills public campaigns, preserves shared attribution, and separates tracker claims from upstream severity.
The CVE Layer Is Becoming the Bottleneck
AI-enabled discovery is increasing pressure on vulnerability identifiers, advisory quality, attribution, and disclosure workflows.
DirtyFrag and Copy Fail2 Show the Page-Cache Bug Class Is Not Done
DirtyFrag and Copy Fail2 are not new AI-attributed findings, but they are important CopyFail-adjacent evidence: Linux still has dangerous seams where zero-copy networking, page-cache provenance, and in-place crypto meet.
The Public Record Is Thin, but Real
The AI vulnerability-discovery record is still small, but direct credits now span browsers, kernels, bootloaders, crypto libraries, and OSS tooling.
CopyFail Is the Bugflation Moment
CVE-2026-31431 shows the bugflation pattern: expert framing plus AI-assisted subsystem review made a kernel root bug cheap to surface.
Introducing Bugflation
Bugflation names the gap between AI-accelerated vulnerability discovery and the slower systems that validate, patch, and deploy fixes.
Second-Pass Audit: What Changed in the Ledger
The launch audit added AI-attributed disclosures from Security Copilot, Claude, OpenAI Codex Security, AISLE, OSS-Fuzz AI, and Calif.io.
Patch Capacity Is the Bottleneck
If AI makes discovery cheaper, the scarce resource moves downstream: triage, reproduction, patch review, release engineering, and deployment.
From Big Sleep to XBOW: Two Different Signals
Big Sleep and XBOW point to different parts of the AI security stack: source-aware vulnerability research and autonomous black-box testing.