
Palo Alto Networks has unveiled NOVA, an autonomous AI system that discovered 14,090 previously unknown vulnerabilities across 3,915 open-source projects during a two-month test. The company reported that 99.4% of these flaws…
Palo Alto Networks has unveiled NOVA, an autonomous AI system that discovered 14,090 previously unknown vulnerabilities across 3,915 open-source projects during a two-month test. The company reported that 99.4% of these flaws had not been publicly disclosed, and nearly 40% were rated High or Critical under the CVSS 4.0 framework.
The system uses a multi-agent architecture to automate source-code analysis, vulnerability identification, proof-of-concept generation and disclosure preparation. Notably, 92% of the discoveries were logic and semantic flaws, such as access control errors and code injection, rather than traditional memory-corruption bugs, indicating AI's growing ability to handle complex security research.
NOVA also uncovered 5,421 supply-chain findings, including 1,280 vulnerabilities in dependencies that created 4,141 downstream exposures. The report warns that faster AI-driven discovery may compress the time organisations have to patch flaws, while stressing that human researchers remain essential for validation and responsible disclosure.
Source: ciso.economictimes.indiatimes.com
This story was synthesised by AI from the source linked above.