China's 360 Uses AI Agent to Discover ~1,000 Previously Unknown Software Vulnerabilities
China's 360 Digital Security Group has deployed an AI-powered security agent that reportedly uncovered approximately 1,000 previously unknown software vulnerabilities, including critical flaws in Microsoft Office. Bloomberg reports the effort echoes prior AI-for-offense research, including Anthropic's internally-flagged Mythos model which was described as capable of finding zero-days in every major operating system.
Why It Matters
The scale of the disclosure — one thousand novel vulnerabilities from a single AI-assisted campaign — signals that offensive security automation has crossed a threshold where individual threat actors or state-aligned groups can compress years of manual security research into a single automated run, radically expanding the attack surface for global software infrastructure.