AI transforms software security focus from discovery to judgment

News provided byEcho · 2 min read

NEW YORK, Sept. 3, 2026, A new report from Echo, a company dedicated to securing the software supply chain, has highlighted a critical shift in the industry. According to Echo's Mythos Readiness Report, artificial intelligence (AI) has transformed the landscape of vulnerability discovery, making judgment and response the new bottlenecks in software security.

The report, which combines Echo's proprietary platform data, a comprehensive study of 250 widely used open source container projects, and survey responses from over 80 security leaders in the United States, reveals that organizations are struggling more with addressing known vulnerabilities rather than discovering new ones. Echo’s findings show that the vulnerabilities attackers exploit most often are not the newly discovered ones but those that have long been known within the industry.

Echo's Chief Technology Officer, Eylam Milner, explained, "AI hasn't just made it faster to find a vulnerability; it's made it faster to be wrong about one. The industry has spent years optimizing for detection, but this report underscores that detection is no longer the constraint. It's judgment, and it doesn't scale the way model inference does."

The report details the rapid advancements in AI-driven vulnerability discovery. Anthropic's Claude Mythos, a cutting-edge model, has demonstrated a 90-fold increase in exploit success between consecutive model generations. Additionally, turning a known vulnerability into a working exploit can now cost less than $2,000 and can be executed in under a day. However, Echo researchers found that only one of the eight "Critical" findings Mythos originally rated held up under independent review, and fewer than 10% of the model's 23,019 candidate findings have undergone any external validation.

Echo's research also highlights the growing gap between the number of known vulnerabilities and the rate at which they are fixed. In the past two years, CVE counts have increased by 145%, and 89% of known vulnerabilities already have a fix available. The real challenge, Echo found, is in the propagation of these fixes. Roughly 40% of fixable vulnerabilities remain unresolved for more than six months, and most successful attacks do not exploit new disclosures but rather weaponize known vulnerabilities after their initial public disclosure, often weeks, months, or even years later.

Echo's survey of security leaders corroborates these findings. Thirty-seven percent cited "detecting more than we can fix" as their organization's biggest obstacle to improving software supply chain security, while only 11% said additional detection or scanning would be their next investment priority.

Echo introduces a four-stage readiness framework: Exposed, Aware, Responsive, and Proactive. This framework helps organizations assess their security posture and identify where they stand in the transition from detection to protection. According to Echo's research, most organizations are currently in the second stage, where visibility has outpaced the ability to act on what is found.

The full report, including Echo's independent analysis of Claude Mythos, the CISO survey results, and the readiness framework, is available now at echo.ai/link-to-report.

Echo is committed to creating a trusted source for agentic-ready software, providing continuously vetted, hardened, and maintained versions of the open-source containers, libraries, VMs, and OS packages organizations rely on. To date, Echo has screened more than 24 million package versions, blocked more than 3,000 malicious packages before they reached customers, and eliminated more than 1.5 million known vulnerabilities across the artifacts it maintains.

Talk to the desk

Want your company on the wire?

File your first press release free, or talk to us about a plan built for regular volume and placement.

Contact us