Analysis · curated 23 Jul 2026

AI Agents Are Finding Zero-Days Faster Than Security Teams Can Govern Them

Coverage timeline

23 Jul 2026aona.ai

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Autonomous AI agents that find and produce reproducible exploits at scale reshape vulnerability management tempo and create governance, shadow-tooling, and trust challenges defenders must address.

An Aona AI blog post analyzes how autonomous AI security agents are discovering zero-days at unprecedented speed, citing a startup that reported 21 previously unknown FFmpeg vulnerabilities with reproducible PoCs for about $1,000 of compute, and Google patching a record 429 Chrome bugs after adapting its bounty program to a flood of AI-generated reports. The piece argues the bottleneck has shifted from discovery to validation, governance, and trust in AI-generated findings.