AI has collapsed the cost of finding vulnerabilities to almost nothing. What used to take a researcher years of expertise and expensive tooling now takes a junior developer with an LLM and a fuzzer. The researcher pool is not growing from thousands to tens of thousands. It is going from thousands to millions.
The numbers already moved. 2024 saw about 40,000 published CVEs, a 38% jump over 2023, the largest single-year increase in the history of the program. Projections put 2026 near 55,000 and 2028 past 125,000.
Finding vulnerabilities is a solved problem. It is solved to the point of drowning. The real problem is telling which ones matter.
A modern device already carries millions of known vulnerabilities across its stack: firmware, embedded software, a web app, a mobile app, and the networks between them. Almost none are exploitable in that specific product. A few could hurt a patient. The job was never to list them. The job is to separate the few from the many, and in a regulated product you cannot just assert that separation. You have to evidence it.
AI makes this worse in a specific way. Variant finders take one published CVE and locate the same pattern across every related library. Exploit generators turn a description into a working PoC. Lower-quality disclosures arrive at higher volume, each one still requiring an evidenced disposition under CRA and postmarket timelines.
AI splits vulnerability work into two layers. The first is discovery, now effectively free. The second is contextual verification: determining which findings are actually exploitable against a specific device rather than theoretically present in it. The second layer is where the value moved, and it is the layer almost nobody has automated.
That is what we do. We build a digital twin of the device, run discovery continuously, and verify exploitability against the real attack surface, including on real hardware through TestLink™. What is reachable is exposure. What is not is evidence. Developers see the handful that need a fix. Everything else is dismissed with the reasoning captured for regulatory review.
The avalanche is real. The thing that matters is knowing which flakes are the avalanche.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.