AI & Threat Landscape

The AI vulnerability explosion: automate or drown

AI has collapsed the cost of finding vulnerabilities to almost nothing. What used to take a researcher years of expertise and expensive tooling now takes a junior developer with an LLM and a fuzzer. The researcher pool is not growing from thousands to tens of thousands. It is going from thousands to millions.

0K25K50K75K100K125K 201720202022202420262028 Published CVEs per year AI-driven projection
Published CVEs per year, historical through 2024 and AI-driven projection to 2028. Roughly 3x today's volume in four years.

The numbers already moved. 2024 saw about 40,000 published CVEs, a 38% jump over 2023, the largest single-year increase in the history of the program. Projections put 2026 near 55,000 and 2028 past 125,000.

Finding vulnerabilities is a solved problem. It is solved to the point of drowning. The real problem is telling which ones matter.

Discovery was never the bottleneck for medical devices

A modern device already carries millions of known vulnerabilities across its stack: firmware, embedded software, a web app, a mobile app, and the networks between them. Almost none are exploitable in that specific product. A few could hurt a patient. The job was never to list them. The job is to separate the few from the many, and in a regulated product you cannot just assert that separation. You have to evidence it.

AI makes this worse in a specific way. Variant finders take one published CVE and locate the same pattern across every related library. Exploit generators turn a description into a working PoC. Lower-quality disclosures arrive at higher volume, each one still requiring an evidenced disposition under CRA and postmarket timelines.

The response is two layers, not more scanners

AI splits vulnerability work into two layers. The first is discovery, now effectively free. The second is contextual verification: determining which findings are actually exploitable against a specific device rather than theoretically present in it. The second layer is where the value moved, and it is the layer almost nobody has automated.

That is what we do. We build a digital twin of the device, run discovery continuously, and verify exploitability against the real attack surface, including on real hardware through TestLink™. What is reachable is exposure. What is not is evidence. Developers see the handful that need a fix. Everything else is dismissed with the reasoning captured for regulatory review.

The avalanche is real. The thing that matters is knowing which flakes are the avalanche.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo