The vulnerability bottleneck has moved
finding bugs is easy, fixing them is hard
Updated june 2026
A spring of npm supply chain attacks and back-to-back Linux kernel exploits, and the uncomfortable thing they have in common. AI hasn't made attackers smarter so much as made finding bugs cheap enough to run in a loop overnight pushing existing systems of disclosure and open source maintainers to their limits.