'Zoomsday' Exploit Enabling Full Device Takeover Was Found by AI in 20 Prompts

An ai system found a vulnerability in widely deployed software by making twenty requests. A human researcher would have required substantially more time and resources. The vulnerability permits complete system compromise. Hundreds of millions of devices currently run the affected code. A patch exists in preliminary form. No deployment schedule has been established. The vulnerability is now known to exist.
Software vendors routinely discover flaws through conventional security research. The rate of discovery by automated systems suggests a gap between vulnerability prevalence and human capacity to find them. This gap will widen. The gap has always existed. Nobody documented it as a problem that required solving before the solving became automated.
The patch will be released according to release cycles designed for a different threat model. Some devices will never receive it. Some organizations will not apply it for years. The vulnerability will be used before it is closed. This sequence is standard. The only variable is which actor uses it first and whether they announce their use.