CVE Disclosures Have Doubled Two Years Running — And Now the Backlog Is

CVE Disclosures Have Doubled Two Years Running — And Now the Backlog Is "Radioactive"

BackerLeader 43 231 390
calendar_today agoschedule4 min read

"Vulnpocalypse" isn't a term Jeff Williams coined himself — he credits his marketing department — but the Contrast Security founder and OWASP creator uses it anyway, because it captures something real. Frontier AI models, Claude Mythos among them, can now find and exploit vulnerabilities at a cost approaching zero. That changes the math for every organization that spent years rationally deferring remediation on vulnerabilities nobody was ever likely to exploit. "Their whole backlog suddenly became radioactive," Williams said. Roughly half of that backlog is CVEs in open source dependencies; the other half is custom code vulnerabilities in a company's own software. Both just got dramatically cheaper to find and chain together into working exploits.

Williams breaks the shift into three forces. AI helps developers ship code faster, but not more securely, so the same defect rate now runs through a much larger volume of code, producing more vulnerabilities in absolute terms. AI helps security researchers find CVEs faster too, and Williams says disclosure rates have more than doubled this year, after doubling the year before. And AI helps attackers do what a human attacker used to do manually: probe running code for holes, just faster and at far greater scale.

Williams has been doing this for 30 years, and he's watched the tooling landscape evolve accordingly. Eleven years ago, when he last spoke with Coder Legion, a typical enterprise ran five or six point solutions for application security alone: static and dynamic scanners, software composition analysis, manual penetration testing, manual code review. Fixing what those tools found meant developers begging, borrowing, and stealing minutes out of their own roadmaps. On the production side, web application firewalls tried to block exploits at the perimeter, with mixed results. Since then, the finding side has consolidated into platforms and a newer category called ASPM that tries to unify results into one picture; Contrast built what Williams calls a context graph, a kind of digital twin of an application's security posture. On the production side, WAF gave way to RASP, which Contrast pioneered, and that category has since evolved into what's now called ADR, application detection and response.

The newest piece of that evolution launched days before this conversation: Contrast CVE Shield, a free compensating control that runs inside a live application and blocks known vulnerabilities from being exploited without requiring an immediate patch. It works through runtime microsandboxing wrapped around each supported CVE, blocking the specific capability an exploit needs rather than relying on signatures, which means new exploit variations hit the same protected boundary without requiring an update. Initial coverage spans 60 critical Java vulnerabilities, including Log4Shell, with support for Go, Node.js, .NET, and Python planned for later this year. For a security team staring down a backlog it can't patch fast enough and can't fully trust a WAF to cover, Williams pitches it as a third option: a way to satisfy compliance and buy time without pretending the underlying problem is fixed. The timing lines up with new government mandates shrinking the remediation window for critical vulnerabilities to three days, a deadline Williams calls directionally correct and, for most companies, close to impossible to hit without something like it.

Williams also founded OWASP and wrote its original Top 10 list in 2002, and he's candid about the strain AI-era vulnerability volume puts on a community-driven model. OWASP doesn't review every finding itself, he explains; it builds the tools, processes, and shared workforce that make review possible at scale. That informal capacity roughly matched the problem a couple of years ago. It doesn't now. OWASP remains, in Williams's view, the leading research organization on AI security specifically, but the field as a whole is stuck in a familiar pattern: build first, retrofit security once something breaks, then repeat.

Asked what one thing he'd want developers to understand, Williams points to MITRE's catalog of roughly a thousand distinct vulnerability classes, every one of them, he says, genuinely non-obvious. He uses clickjacking as an example: an attacker overlays an invisible, fully functional version of a legitimate site underneath something innocuous-looking, so a click that appears to hit a game button actually triggers an action on the hidden page underneath. Nobody invents that kind of attack by intuition. Someone has to think of it once, and then everyone else has to learn it. With a thousand of those tricks in circulation and AI now finding new ones faster than any team can track, Williams argues the expectation that developers alone can catch everything was never realistic, AI era or not.

He's not entirely pessimistic about where this goes. Williams argues the same AI capabilities now accelerating attackers can eventually automate the expert-intensive workflows, threat modeling, architecture review, security-by-design verification, that most organizations have never had the staff to do at scale. So far, he says, the industry has mostly used AI to automate yesterday's reactive workflows: find a vulnerability, patch it, repeat. The bigger opportunity, in his view, is using it to build software that's verified secure before it ships in the first place, closing the structural advantage defenders already have on paper, since they control the blueprint, and attackers don't, but have rarely been able to use.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

Defending Against AI Worms: Securing Multi-Agent Systems from Self-Replicating Prompts

alessandro_pignati - Apr 2

The Security Conversation Your Clients Aren't Having About Agentic AI

Tom Smithverified - Jun 29

Hardening the Agentic Loop: A Technical Guide to NVIDIA NemoClaw and OpenShell

alessandro_pignati - Mar 26
chevron_left
15.8k Points664 Badges
197Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

8 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!