
Palo Alto Networks says its autonomous AI system, NOVA, found 14,090 previously unknown vulnerabilities across 3,915 open-source projects during a two-month evaluation. The company reports that 99.4% had not been publicly disclosed,…
Palo Alto Networks says its autonomous AI system, NOVA, found 14,090 previously unknown vulnerabilities across 3,915 open-source projects during a two-month evaluation. The company reports that 99.4% had not been publicly disclosed, while nearly 40% were rated High or Critical under CVSS 4.0. NOVA reviews code, identifies flaws, generates and tests proof-of-concept exploits, and prepares disclosure reports and patch guidance.
The system found that 92% of its discoveries involved logic or semantic flaws, including access-control failures, path traversal, code injection and server-side request forgery. It also identified 5,421 supply-chain findings, including 1,280 vulnerabilities in dependencies linked to 4,141 downstream exposures. Palo Alto Networks says researchers validated 2,776 exposure paths. Human review remains needed for validation, disclosure and remediation.
Claims that AI has made security researchers obsolete go too far, just as warnings that open-source software is inherently unsafe miss the point. The findings come from Palo Alto Networks’ own evaluation, so independent testing matters before treating the totals as a measure of the whole ecosystem. The practical test is how many reported flaws maintainers confirm, patch and prevent from reaching users.
Source: ciso.economictimes.indiatimes.com
This story was synthesised by AI from the source linked above.