AI-assisted security research has reached the point where “the model found a bug” can mean a reproducible flaw that maintainers actually fix. That is encouraging for defenders and uncomfortable for anyone hoping their old software has already revealed all its surprises.
Three recent developments show different parts of that story: Anthropic’s report of hundreds of vulnerabilities, its collaboration with Mozilla, and Calif’s separate MAD Bugs series. Together they make a strong case for taking the technology seriously. They also deserve to be kept distinct.
Where the figure of 500 comes from
On February 5, Anthropic said it had found and validated more than 500 high-severity vulnerabilities during work with Claude Opus 4.6. Its researchers described examining open-source projects, checking potential findings and beginning to coordinate fixes.
The company said it validated reports before sending them to maintainers, with human researchers handling validation and patch development. Its published examples included Ghostscript, OpenSC and CGIF.
That is Anthropic’s reported total, not a count of 500 bugs found by Calif during April. Nor does “high severity” mean that every finding gives any attacker immediate control of any computer running the software. Exposure and exploitability depend on the particular flaw.
Mozilla provides a concrete example of fixes landing
Mozilla described its collaboration on March 6. Anthropic supplied reproducible test cases; Firefox engineers checked the issues and incorporated fixes into Firefox 148.
Mozilla reported 14 high-severity bugs and 22 CVEs from the work, alongside 90 other bugs of varying significance. Those numbers describe different categories. They should not be combined into a claim of 112 critical remote takeovers.
The reproducible examples are an important part of the result. A convincing paragraph about a possible bug is easy to generate. A small test that demonstrates the problem gives a maintainer something actionable.
There is a rather satisfying outcome here: a tool finds a weakness, people verify it, a fix ships and users receive better software. The final step lacks the cinematic appeal of a hacker in a dark room, but it is the bit that helps.
MAD Bugs belongs to Calif
Security researchers at Calif launched Month of AI-Discovered Bugs, announcing a series of findings through the end of April. Their approach pairs AI models with human expertise.
Their March 30 account covered Vim and GNU Emacs. These are separate research reports from Anthropic’s February total and the Mozilla collaboration.
The Vim project’s advisory for CVE-2026-34714 describes a chain involving modelines and a sandbox escape. In affected builds, opening a specially crafted file could cause commands to run with the user’s privileges. The advisory’s technical description identifies patch 9.2.0272 as the fix.
For Emacs, Calif’s report describes a file inside a directory containing attacker-controlled Git metadata. Automatic version-control operations could then trigger command execution. This is more specific than saying that every ordinary text file is a trap.
Calif says the Emacs maintainers declined its proposed intervention and attributed the issue to Git. That is the researchers’ account of the response. It highlights a difficult trust boundary between tools; it does not tell us that maintainers are indifferent to security.
The FreeBSD exploit started from a published advisory
FreeBSD published its advisory for CVE-2026-4747 on March 26, crediting Nicholas Carlini using Claude at Anthropic. It describes a buffer-validation flaw in RPCSEC_GSS and provides correction details. The kernel exposure depends on the relevant module and service configuration; simply owning a FreeBSD machine is not the complete attack scenario.
Calif then reported an exploit-development experiment on March 31. Starting from that already public advisory, it says Claude helped construct a test environment and produced working remote-root exploits.
The reported duration was about eight hours of elapsed time, with roughly four hours of active model work. The published prompt history includes human direction and corrections. Describing the exercise as an uninterrupted, unaided discovery of the original vulnerability would miss both the starting material and the human involvement.
Even with those limits, turning an advisory into a demonstrated exploit is significant. It is simply a different result from independently discovering a new bug. The distinction tells us more about the capability than the phrase “AI hacked an operating system over lunch.”
Finding more bugs creates more work—and opportunities
It is reasonable to worry that faster analysis can increase pressure on maintainers. The useful response is to improve the quality of reports and help with verification, fixes and testing. Sending someone a mountain of plausible-sounding warnings is not the same as helping them secure a project.
These examples also do not prove that anyone with a chatbot can reproduce the same results on any target. Models, access, research skills, tools and safeguards all affect what is possible. The broader competition in AI coding has the same practical theme: the surrounding workflow matters.
For users, the immediate action remains familiar. Install supported security updates. Vim users and FreeBSD administrators should check the linked advisories against their versions and configurations. Browser users should keep their supported release updated rather than treating Firefox 148 as a version to remain on indefinitely.
AI-assisted research is producing useful evidence. Whether that evidence improves security depends on what happens next: confirmation, coordination, a correct patch and deployment. The cat may enjoy watching the cursor move by itself, but someone still has to check what it clicked.




