AlphaWire

newswire

JPMorgan Chase: AI discovers vulnerabilities far faster than it can patch them, and cyber risks continue to accumulate

2026-07-23·newswire-us-stock-185750
JPMorgan Chase: AI discovers vulnerabilities far faster than it can patch them, and cyber risks continue to accumulate.

Michael Cembalest, chairman of markets and investment strategy at J.P. Morgan Asset and Wealth Management, warned in the latest report "Patchmageddon" that artificial intelligence (AI) is bringing global network security into a new high-risk stage.

Cutting-edge models such as Mythos and GPT-5.5 can not only discover previously unknown software vulnerabilities on a large scale, but also reverse-analyze patches, concatenate multiple flaws, and quickly generate runnable attack tools.

The key is that the speed at which attackers can exploit vulnerabilities is shortening from months to days and hours, while the remediation capabilities of enterprises, open source communities, and industrial infrastructure have not improved at the same time.

The report believes that an ever-expanding "patch gap" is forming in the field of network security: vulnerability discovery and weaponization have entered the era of automation, but patching, testing and deployment are still constrained by complex software dependencies, insufficient maintenance personnel, business continuity requirements, and a large number of old equipment that cannot be upgraded.

Vulnerability exploitation enters the "zero-day norm" Even before the emergence of new generation AI models, the global cybersecurity situation has continued to deteriorate.

In 2025, the number of global cyber attacks will increase by 18%, with an average of approximately 75,000 attacks occurring per hour, and each organization encountering an average of approximately 2,000 attacks per week. The global cybersecurity talent gap reaches approximately 4.8 million people.

In terms of attack methods, phishing and social engineering accounted for 40% of cyber attacks, ransomware accounted for 30%, business email fraud accounted for 15%, and malware and credential theft accounted for 10%. In simulation tests, about 33% of employees were likely to be deceived by phishing messages.

(Proportions of major network attack methods) What's even more dangerous is that the reaction time left for companies to respond after a vulnerability is disclosed is shortening dramatically.

In 2025, the average time from public disclosure to first confirmed exploitation of a vulnerability has dropped to less than 100 days, with the median dropping to zero days, and some attacks even occur before patches are released. About 1.5% to 2% of publicly disclosed vulnerabilities end up being exploited every year.

After entering 2026, this trend will further accelerate.

Citing Zero Day Clock data, the report said that the proportion of attacks that occurred on or before the day the vulnerability was disclosed has reached nearly 80%; the median vulnerability exploitation time has dropped from about one year in 2021 to one day in 2026, and may be further shortened to one minute in 2027.

In 2026, all vulnerabilities that will eventually be exploited will have been exploited 50 days after they were disclosed. This means that traditional vulnerability disclosure and patching mechanisms are failing.

In the past, the software industry usually disclosed vulnerabilities 90 days after discovery so that manufacturers and users could fix them in advance; now, attackers may complete reverse analysis within minutes of a vulnerability being disclosed, and spread the attack globally within hours.

Cutting-edge AI brings qualitative changes in vulnerability discovery capabilities The report believes that the emergence of models such as Mythos and GPT-5.5 has brought "seismic changes" to the network risk landscape.

When Mozilla used Mythos Preview to test Firefox 150, it discovered and fixed 271 vulnerabilities, which was more than ten times the number when it used Claude Opus 4.6 to test Firefox 148.

Anthropic and Project Glasswing participants discovered more than 10,000 new high-risk and severe zero-day vulnerabilities in the first month after the model was put into use; Cloudflare discovered 2,000 vulnerabilities during the same period, 400 of which were high-risk or severe.

But when studying statistics, 95% of the vulnerabilities discovered by Mythos have not yet appeared in public security bulletins, the National Vulnerability Database or the GitHub Security Database, meaning these risks are invisible to traditional monitoring systems. The threats of AI go beyond discovering vulnerabilities.

The model can already connect multiple low- and medium-risk vulnerabilities into severe attack paths, and automatically write exploit programs based on public vulnerabilities and patches.

Anthropic's testing showed that Mythos Preview turned a known vulnerability into a workable privilege escalation attack in less than a day and at a cost of less than $2,000 without human intervention.

At the same time, AI’s ability to independently complete complex tasks is currently doubling approximately every 3 to 4 months, which is significantly faster than the doubling cycle of approximately 7 months before 2024.

The report predicts that in the next 12 to 24 months, capabilities currently mainly controlled by a few national-level cyber forces may be copied into the free and open weight model. Cyberattacks may thus shift from a high-cost, specialized activity to a tool available to more extortion gangs, hacktivists, and even destructive organizations.

‘Patch gap’ becomes real risk AI's ability to discover vulnerabilities is improving rapidly, but global patching capabilities are clearly not keeping up. A total of 48,185 common vulnerabilities were disclosed in 2025, and approximately 7,500 were patched.

When about 60% of data breaches occur, the relevant patches actually already exist, but companies fail to deploy them in time. Businesses delaying patches aren't entirely out of negligence.

Many patches can only be installed on the latest version of the software, and companies must first upgrade databases, third-party components and related programs, which may cause system downtime or business interruption.

More than 80% of security professionals have given up or postponed patches to avoid affecting their work; about 80% of CIOs and CISOs have discovered that patches that they thought had covered the entire network had not actually updated all end devices. 61% of reported incidents are related to "patches are available but not installed".

At the same time, large models are non-deterministic. Different users may find different vulnerabilities in the same code, and enterprises may need to repeatedly patch the same software for multiple rounds.

When enterprises measure patch management capabilities in the future, they cannot just focus on accuracy, but must also consider deployment speed as a core indicator. Open source software becomes the weakest link The report focuses specifically on open source software.

Modern business software is no longer primarily written from scratch, but rather "assembled" from a large number of open source libraries and frameworks.

About 96% to 99% of commercial code bases contain open source components, and about 77% of the underlying code for commercial applications comes from pre-made open source libraries and frameworks; another study estimates that 70% to 90% of the content in any software code base belongs to open source components.

However, the maintenance resources of open source software are seriously mismatched with its economic importance. More than 18 million open source projects have only one registered maintainer, accounting for 55% of the total number of projects.

Among 50 important open source projects, 94% of the projects have less than 10 developers contributing more than 90% of the code, and only 136 developers contributed more than 80% of the new code of these projects. 45% of maintainers surveyed cited burnout as their biggest challenge. Open source dependencies are also highly complex.

The average commercial application contains about 1,180 open source components, and the number of dependencies in a typical code base has nearly tripled since 2020. A JavaScript project has an average of only 10 direct dependencies, but 683 indirect dependencies, and 95% of open source vulnerabilities exist in these transitive dependencies.

The dependency versions used by open source users are on average 278 days behind the latest major version, up from 215 days the previous year. About 90% of code bases rely on outdated components in some way. As of May 2026, Anthropic has discovered more than 23,000 potential open source vulnerabilities, of which approximately 3,900 are high-risk or critical.

High-severity vulnerabilities take an average of two weeks to patch. Among a set of high-risk and critical vulnerabilities, 530 were submitted to maintainers, but only 75 were fixed. Tuskira Research estimates that Mythos discovers vulnerabilities 16.5 times faster than they can patch them.

Industrial facilities facing 'irrepairable' dilemma Risks to industrial facilities such as power, water, manufacturing and transportation are more problematic than those faced by software systems.

Cloud IT equipment is usually updated every 4 to 5 years, while industrial operation equipment is often used for 10 to 18 years, resulting in a large number of legacy systems that are difficult to upgrade or replace.

JPMorgan Chase estimates that only 55% to 65% of industrial network hardware can be patched, 12% to 20% is technically unpatchable, and another 20% to 30% is not patched at all. Among them, only 45% to 60% of operational technology equipment can be repaired.

A scan found that at least 179 industrial control devices exposed to the Internet have no authentication, and outsiders may directly read or even modify system data. Iran-linked hackers have also attacked programmable logic controllers in U.S. water, wastewater, and energy facilities, causing operational disruption and economic losses.

In extreme cases, attacks on large power grids, telecommunications backbones, financial clearing institutions or cloud service providers may have a chain reaction across multiple industries.

Long-term outages in regional power grids can affect banks, base stations, data centers and medical systems; loss of synchronization at city water pumping stations can lead to drops in water pressure, ruptured pipes, failure of fire protection systems and the entry of contaminants into water networks.

AI will also become a defense tool While cutting-edge models magnify attack risks, the report believes the same technology can also be used to speed up vulnerability remediation.

Claude Security from Anthropic scans the code base and generates fix recommendations, and Claude Opus 4.7 has been used to patch more than 2,100 vulnerabilities in the weeks since its launch.

OpenAI's Codex Security can discover, verify and repair vulnerabilities; since its launch in March, its cloud version has scanned more than 30 million code submissions, covering more than 30,000 code libraries.

Manual reviewers have confirmed that more than 70,000 problems have been fixed, and the system has automatically determined that more than 500,000 problems have been fixed. However, the cybersecurity model will not be monopolized by a handful of U.S. companies for long.

The report believes that new closed source, open weight and open source models in China and the United States are providing capabilities close to leading models at a lower cost. (This figure compares the comprehensive intelligence score of the main AI models and the cost of a single task.

The closer to the upper left, the higher the cost-effectiveness) Kimi K3, considered by the report's authors to be the strongest non-Anthropic model in testing, performed the same batch of cybersecurity tasks at about half the cost of Mythos.

Cybersecurity spending may see long-term growth From an investment perspective, the report points out that network security companies have performed significantly better than the overall software industry since 2026. Traditional software stocks have been dragged down by concerns that intelligent AI may replace existing enterprise software.

Although they have rebounded about 15% from the panic lows in April, the price-to-sales premium of the software sector relative to the S&P 500 index is still close to the lowest level since 1991.

In contrast, the rising number of vulnerabilities, accelerated patch deployment, industrial equipment updates, and the popularity of defensive AI will continue to drive demand for network security services, asset management, authentication, network partitioning, and infrastructure updates.

But enterprise upgrades will also be subject to supply chain constraints.

The report estimates that the prices of memory, CPU and storage in server racks will increase approximately 3 to 4 times during the year, and the delivery period will exceed 6 months; the price of storage equipment will increase approximately 3 times, and the delivery period will be 4 to 5 months; the delivery period of infrastructure such as generators, cooling equipment, and transformers will reach 18 to 24 months, and substations and power equipment may take 24 to 36 months.

#Stocks #Amazon #AI #SP500

Full text

JPMorgan Chase: AI discovers vulnerabilities far faster than it can patch them, and cyber risks continue to accumulate

Michael Cembalest, chairman of markets and investment strategies at JPMorgan Asset and Wealth Management, warned in the latest report "Patchmageddon" that artificial intelligence (AI) is bringing global network security into a new high-risk stage. Cutting-edge models such as Mythos and GPT-5.5 can not only discover previously unknown software vulnerabilities on a large scale, but also reverse-analyze patches, concatenate multiple flaws, and quickly generate runnable attack tools.

Michael Cembalest, chairman of markets and investment strategy at J.P. Morgan Asset and Wealth Management, warned in the latest report "Patchmageddon" that artificial intelligence (AI) is bringing global network security into a new high-risk stage. Cutting-edge models such as Mythos and GPT-5.5 can not only discover previously unknown software vulnerabilities on a large scale, but also reverse-analyze patches, concatenate multiple flaws, and quickly generate runnable attack tools. The key is that the speed at which attackers can exploit vulnerabilities is shortening from months to days and hours, while the remediation capabilities of enterprises, open source communities, and industrial infrastructure have not improved at the same time. The report believes that an ever-expanding "patch gap" is forming in the field of network security: vulnerability discovery and weaponization have entered the era of automation, but patching, testing and deployment are still constrained by complex software dependencies, insufficient maintenance personnel, business continuity requirements, and a large number of old equipment that cannot be upgraded. Vulnerability exploitation enters the "zero-day norm" Even before the emergence of new generation AI models, the global cybersecurity situation has continued to deteriorate. In 2025, the number of global cyber attacks will increase by 18%, with an average of approximately 75,000 attacks occurring per hour, and each organization encountering an average of approximately 2,000 attacks per week. The global cybersecurity talent gap reaches approximately 4.8 million people. In terms of attack methods, phishing and social engineering accounted for 40% of cyber attacks, ransomware accounted for 30%, business email fraud accounted for 15%, and malware and credential theft accounted for 10%. In simulation tests, about 33% of employees were likely to be deceived by phishing messages. (Proportions of major network attack methods) What's even more dangerous is that the reaction time left for companies to respond after a vulnerability is disclosed is shortening dramatically. In 2025, the average time from public disclosure to first confirmed exploitation of a vulnerability has dropped to less than 100 days, with the median dropping to zero days, and some attacks even occur before patches are released. About 1.5% to 2% of publicly disclosed vulnerabilities end up being exploited every year. After entering 2026, this trend will further accelerate. Citing Zero Day Clock data, the report said that the proportion of attacks that occurred on or before the day the vulnerability was disclosed has reached nearly 80%; the median vulnerability exploitation time has dropped from about one year in 2021 to one day in 2026, and may be further shortened to one minute in 2027. In 2026, all vulnerabilities that will eventually be exploited will have been exploited 50 days after they were disclosed. This means that traditional vulnerability disclosure and patching mechanisms are failing. In the past, the software industry usually disclosed vulnerabilities 90 days after discovery so that manufacturers and users could fix them in advance; now, attackers may complete reverse analysis within minutes of a vulnerability being disclosed, and spread the attack globally within hours. Cutting-edge AI brings qualitative changes in vulnerability discovery capabilities The report believes that the emergence of models such as Mythos and GPT-5.5 has brought "seismic changes" to the network risk landscape. When Mozilla used Mythos Preview to test Firefox 150, it discovered and fixed 271 vulnerabilities, which was more than ten times the number when it used Claude Opus 4.6 to test Firefox 148. Anthropic and Project Glasswing participants discovered more than 10,000 new high-risk and severe zero-day vulnerabilities in the first month after the model was put into use; Cloudflare discovered 2,000 vulnerabilities during the same period, 400 of which were high-risk or severe. But when studying statistics, 95% of the vulnerabilities discovered by Mythos have not yet appeared in public security bulletins, the National Vulnerability Database or the GitHub Security Database, meaning these risks are invisible to traditional monitoring systems. The threats of AI go beyond discovering vulnerabilities. The model can already connect multiple low- and medium-risk vulnerabilities into severe attack paths, and automatically write exploit programs based on public vulnerabilities and patches. Anthropic's testing showed that Mythos Preview turned a known vulnerability into a workable privilege escalation attack in less than a day and at a cost of less than $2,000 without human intervention.

At the same time, AI’s ability to independently complete complex tasks is currently doubling approximately every 3 to 4 months, which is significantly faster than the doubling cycle of approximately 7 months before 2024. The report predicts that in the next 12 to 24 months, capabilities currently mainly controlled by a few national-level cyber forces may be copied into the free and open weight model. Cyberattacks may thus shift from a high-cost, specialized activity to a tool available to more extortion gangs, hacktivists, and even destructive organizations. ‘Patch gap’ becomes real risk AI's ability to discover vulnerabilities is improving rapidly, but global patching capabilities are clearly not keeping up. A total of 48,185 common vulnerabilities were disclosed in 2025, and approximately 7,500 were patched. When about 60% of data breaches occur, the relevant patches actually already exist, but companies fail to deploy them in time. Businesses delaying patches aren't entirely out of negligence. Many patches can only be installed on the latest version of the software, and companies must first upgrade databases, third-party components and related programs, which may cause system downtime or business interruption. More than 80% of security professionals have given up or postponed patches to avoid affecting their work; about 80% of CIOs and CISOs have discovered that patches that they thought had covered the entire network had not actually updated all end devices. 61% of reported incidents are related to "patches are available but not installed". At the same time, large models are non-deterministic. Different users may find different vulnerabilities in the same code, and enterprises may need to repeatedly patch the same software for multiple rounds. When enterprises measure patch management capabilities in the future, they cannot just focus on accuracy, but must also consider deployment speed as a core indicator. Open source software becomes the weakest link The report focuses specifically on open source software. Modern business software is no longer primarily written from scratch, but rather "assembled" from a large number of open source libraries and frameworks. About 96% to 99% of commercial code bases contain open source components, and about 77% of the underlying code for commercial applications comes from pre-made open source libraries and frameworks; another study estimates that 70% to 90% of the content in any software code base belongs to open source components. However, the maintenance resources of open source software are seriously mismatched with its economic importance. More than 18 million open source projects have only one registered maintainer, accounting for 55% of the total number of projects. Among 50 important open source projects, 94% of the projects have less than 10 developers contributing more than 90% of the code, and only 136 developers contributed more than 80% of the new code of these projects. 45% of maintainers surveyed cited burnout as their biggest challenge. Open source dependencies are also highly complex. The average commercial application contains about 1,180 open source components, and the number of dependencies in a typical code base has nearly tripled since 2020. A JavaScript project has an average of only 10 direct dependencies, but 683 indirect dependencies, and 95% of open source vulnerabilities exist in these transitive dependencies. The dependency versions used by open source users are on average 278 days behind the latest major version, up from 215 days the previous year. About 90% of code bases rely on outdated components in some way. As of May 2026, Anthropic has discovered more than 23,000 potential open source vulnerabilities, of which approximately 3,900 are high-risk or critical. High-severity vulnerabilities take an average of two weeks to patch. Among a set of high-risk and critical vulnerabilities, 530 were submitted to maintainers, but only 75 were fixed. Tuskira Research estimates that Mythos discovers vulnerabilities 16.5 times faster than they can patch them. Industrial facilities facing 'irrepairable' dilemma Risks to industrial facilities such as power, water, manufacturing and transportation are more problematic than those faced by software systems. Cloud IT equipment is usually updated every 4 to 5 years, while industrial operation equipment is often used for 10 to 18 years, resulting in a large number of legacy systems that are difficult to upgrade or replace. JPMorgan Chase estimates that only 55% to 65% of industrial network hardware can be patched, 12% to 20% is technically unpatchable, and another 20% to 30% is not patched at all. Among them, only 45% to 60% of operational technology equipment can be repaired.

A scan found that at least 179 industrial control devices exposed to the Internet have no authentication, and outsiders may directly read or even modify system data. Iran-linked hackers have also attacked programmable logic controllers in U.S. water, wastewater, and energy facilities, causing operational disruption and economic losses. In extreme cases, attacks on large power grids, telecommunications backbones, financial clearing institutions or cloud service providers may have a chain reaction across multiple industries. Long-term outages in regional power grids can affect banks, base stations, data centers and medical systems; loss of synchronization at city water pumping stations can lead to drops in water pressure, ruptured pipes, failure of fire protection systems and the entry of contaminants into water networks. AI will also become a defense tool While cutting-edge models magnify attack risks, the report believes the same technology can also be used to speed up vulnerability remediation. Claude Security from Anthropic scans the code base and generates fix recommendations, and Claude Opus 4.7 has been used to patch more than 2,100 vulnerabilities in the weeks since its launch. OpenAI's Codex Security can discover, verify and repair vulnerabilities; since its launch in March, its cloud version has scanned more than 30 million code submissions, covering more than 30,000 code libraries. Manual reviewers have confirmed that more than 70,000 problems have been fixed, and the system has automatically determined that more than 500,000 problems have been fixed. However, the cybersecurity model will not be monopolized by a handful of U.S. companies for long. The report believes that new closed source, open weight and open source models in China and the United States are providing capabilities close to leading models at a lower cost. (This figure compares the comprehensive intelligence score of the main AI models and the cost of a single task. The closer to the upper left, the higher the cost-effectiveness) Kimi K3, considered by the report's authors to be the strongest non-Anthropic model in testing, performed the same batch of cybersecurity tasks at about half the cost of Mythos. Cybersecurity spending may see long-term growth From an investment perspective, the report points out that network security companies have performed significantly better than the overall software industry since 2026. Traditional software stocks have been dragged down by concerns that intelligent AI may replace existing enterprise software. Although they have rebounded about 15% from the panic lows in April, the price-to-sales premium of the software sector relative to the S&P 500 index is still close to the lowest level since 1991. In contrast, the rising number of vulnerabilities, accelerated patch deployment, industrial equipment updates, and the popularity of defensive AI will continue to drive demand for network security services, asset management, authentication, network partitioning, and infrastructure updates. But enterprise upgrades will also be subject to supply chain constraints. The report estimates that the prices of memory, CPU and storage in server racks will increase approximately 3 to 4 times during the year, and the delivery period will exceed 6 months; the price of storage equipment will increase approximately 3 times, and the delivery period will be 4 to 5 months; the delivery period of infrastructure such as generators, cooling equipment, and transformers will reach 18 to 24 months, and substations and power equipment may take 24 to 36 months.

← Back to archive