AI industrialized vulnerability discovery. The code itself is now written by agents on developer workstations, and most AppSec programs have no control point there.
The Zero Day Clock Stopped Ticking (and That’s the Point)
A look at what changed in the latest version of the Zero Day Clock, why CISA KEV alone is no longer enough, and what it means for CISOs, AppSec teams, and the AI-driven collapse of exploitation timeli
Arora’s $1T Legacy Security Claim, OpenAI’s Astra & $1B Defender Fund, Another Agent Swarm Escapes, GTIG on Agentic Attackers, Patch the Planet, Sovereign AI Raises & Agents as Insider Threats
OpenAI’s Hugging Face post-mortem, NVIDIA’s reported bid for the open model hub, sandboxes that don’t hold, open models closing the gap & a fund built on the agent attack surface
The end-state fallacy, open-weight models catching up on offense, the CVE Program at human scale, agent identity gets real & a market that may have outgrown itself
A look at autonomous agents reaching real systems, the accountability scramble, defensive AI in production, funding megarounds & the state of exploitation
Lovable's CISO on soft guardrails, shared responsibility on an AI development platform, and what GRC engineering looks like when the attackers are AI-powered too.
AI has collapsed the cost of finding and reporting vulnerabilities at the same time, and Casey Ellis breaks down what that means for bug bounties, open source, and security research policy.