News

Cyber risk goes parabolic: critical software vulnerabilities top 600 a month

What's going on? Andreessen Horowitz published a chart of Epoch AI data on critical and high-severity vulnerabilities (CVEs) reported by 21 major software vendors, including Apple, AWS, Microsoft, Google, Nvidia and SAP. Critical vulnerabilities never cleared 100 a month in four years. Since spring 2026 they have climbed past 600 a month, and high-severity ones have passed 2,000.

The attacker's view: a16z paired the chart with David George's interview of Kevin Mandia, the Mandiant founder who came back to start Armadin once AI arrived. Armadin's AI agents attack customer networks from the outside, with no source code, before criminals do. Mandia says the company has found more than 90 zero-days in production at Fortune 500 customers since January, and that AI attacks hunt for logic flaws in custom applications and "exhaust all routes all the time." His verdict on the old playbook: "everything I did is dead."

Caveat: Epoch AI notes that reporting procedures, labeling and cadence vary substantially between vendors.

Source: a16z on X · a16z interview with Kevin Mandia

More top stories