Snyk AI-Driven Zero-Day Vulnerabilities Surge at Fortune 500s
Article Content
- •Over 90 zero-day vulnerabilities found at Fortune 500s by AI agents.
- •AI attacks are faster and broader, changing the dynamics of cybersecurity.
- •Defenders must implement machine-speed responses to counteract autonomous threats.
Armadin, a startup founded by Kevin Mandia, reported discovering over 90 zero-day vulnerabilities at Fortune 500 companies since January 2026, all identified by AI agents without source code access. This marks a significant shift in cybersecurity, as AI-driven offensive security has transitioned from theory to operational reality. Mandia highlighted that AI attacks are less stealthy but more effective due to their scale and speed, allowing attackers to probe multiple paths simultaneously. The average time for an attack has drastically decreased, with CrowdStrike reporting breakout times now measured in minutes. Snyk's CTO also emphasized the need for machine-speed defense to counteract these autonomous attacks, which have doubled the introduction of new security issues in enterprise environments. The current landscape suggests that defenders must adapt quickly to keep pace with evolving threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many zero-days were found?
What is the current status of these vulnerabilities?
What should organizations do in response?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…