AI & Threat Landscape

The AI vulnerability explosion: automate or drown

AI has collapsed the cost of finding vulnerabilities to almost nothing. What used to take a researcher years of expertise and expensive tooling now takes a junior developer with an LLM and a fuzzer. The researcher pool is not growing from thousands to tens of thousands. It is going from thousands to millions.

0K25K50K75K100K125K 201720202022202420262028 Published CVEs per year AI-driven projection
Published CVEs per year, historical through 2024 and AI-driven projection to 2028. Roughly 3x today's volume in four years.

The numbers already moved. 2024 saw about 40,000 published CVEs, a 38% jump over 2023, the largest single-year increase in the history of the program. Projections put 2026 near 55,000 and 2028 past 125,000.

Finding vulnerabilities is a solved problem. It is solved to the point of drowning. The real problem is telling which ones matter.

Discovery was never the bottleneck for medical devices

A modern device already carries millions of known vulnerabilities across its stack: firmware, embedded software, a web app, a mobile app, and the networks between them. Almost none are exploitable in that specific product. A few could hurt a patient. The job was never to list them. The job is to separate the few from the many, and in a regulated product you cannot just assert that separation. You have to evidence it.

AI makes this worse in a specific way. Variant finders take one published CVE and locate the same pattern across every related library. Exploit generators turn a description into a working PoC. Lower-quality disclosures arrive at higher volume, each one still requiring an evidenced disposition under CRA and postmarket timelines.

Pentesting is bound by the economics of human labor

A traditional penetration test is a payroll problem. One or two testers, two to four weeks, a scope trimmed until it fits the invoice. A human spends hours coaxing a single interface to misbehave, and every one of those hours is billed. When attention is priced by the hour, coverage is decided by the budget, not by the attack surface. That is how the industry landed on the annual pentest: not because devices change once a year, but because that is what the labor market allows.

AI discovery has no such bound. It has not been proven smarter than a strong human researcher, and it does not need to be. It works in minutes, runs around the clock, and the marginal attempt costs close to nothing. A tester who is merely as good as a human, at a fraction of the cost and a thousand times the frequency, does not tie the game. It changes the sport.

Play that forward. Discovery volume grows by orders of magnitude: from researchers, from variant finders, from anyone with a model and a target. And that volume breaks the next process in line, triage. Manually triaging machine-generated findings repeats the exact economic mistake that broke pentesting: human hours spent on output machines produce for free. At sufficient volume it is not just unaffordable. It is not worth doing at all.

The only response that scales is to stop touching findings by hand. Automate the context: which component the finding lives in, which interface reaches it, whether the graph connects it to anything a patient depends on. Automate the attempted verification: try it against the device, capture what executed and what could not, and move on. That is the design behind AI Pentesting, where the agentic harness generates and runs the attempts continuously, and Exploitability Verification, where every claim is settled on the running product instead of in a triage meeting.

The response is two layers, not more scanners

AI splits vulnerability work into two layers. The first is discovery, now effectively free. The second is contextual verification: determining which findings are actually exploitable against a specific device rather than theoretically present in it. The second layer is where the value moved, and it is the layer almost nobody has automated.

That is what we do. We build a digital twin of the device, run discovery continuously, and verify exploitability against the real attack surface, including on real hardware through TestLink™. What is reachable is exposure. What is not is evidence. Developers see the handful that need a fix. Everything else is dismissed with the reasoning captured for regulatory review.

The avalanche is real. The thing that matters is knowing which flakes are the avalanche.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about the AI vulnerability explosion.

Why are CVE counts rising so fast?

AI collapsed the cost of finding vulnerabilities. Work that took a researcher years of expertise and expensive tooling now takes a junior developer with an LLM and a fuzzer, so the researcher pool goes from thousands toward millions. 2024 saw about 40,000 published CVEs, a 38% jump over 2023.

How many CVEs are projected by 2028?

Projections put 2026 near 55,000 published CVEs and 2028 past 125,000, roughly three times today's volume in four years. Variant finders and exploit generators add to that, since one published CVE can be pattern matched across every related library and a description can be turned into a working proof of concept.

If AI finds vulnerabilities faster, why is that a problem for device makers?

Discovery was never the bottleneck. A modern device already carries millions of known vulnerabilities across firmware, embedded software, a web app, a mobile app and the networks between them, and almost none are exploitable in that specific product. The job is separating the few from the many, with evidence.

Why does manual triage break under AI-generated findings?

Manually triaging machine-generated findings repeats the economic mistake that broke pentesting: human hours spent on output that machines produce for free. At sufficient volume it is not just unaffordable, it is not worth doing at all. The response is to automate the context and the attempted verification.

What are the two layers of vulnerability work after AI?

AI split the work into discovery, now effectively free, and contextual verification, which decides which findings are actually exploitable against a specific device rather than theoretically present in it. The value moved to the second layer, and the second layer is the one almost nobody has automated.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON