Finding More Vulnerabilities Isn't the Goal Anymore
If you went to engineering school, you know one of the first things they teach you is how to calculate complex formulas by hand. This isn't to haze new students, it's to teach you how to think. When the software used to calculate a building's cooling system returns a bizarre answer, a trained engineer knows how to spot it. School is where you learn to identify when the math is not math-ing.
That is the point of expertise. We don't hire professionals expecting them to do everything manually. We hire them because they have the depth of experience to fill knowledge gaps, challenge answers that don't make sense, and sanity-check whether we're actually accomplishing what we set out to do.
For most of application security history, finding the vulnerability was the hard part.
Organizations hired people who knew how to break things, bought tools to help them find more issues, and built entire programs around achieving better coverage and catching problems earlier in development. The assumption underneath all of it was reasonable: if we can find more vulnerabilities earlier, we'll be more secure.
That core assumption is breaking as fast as you can say AI.
Not because finding vulnerabilities doesn't matter, it obviously does. But because AI is making discovery dramatically cheaper and faster at the exact moment the industry is producing more software than ever before. We are entering a world where we can uncover far more problems than any organization has the capacity to understand or fix.
And let's be honest: another 10,000 findings sitting in a backlog doesn't make anyone 10,000 findings safer.

We Don't Have a Finding Problem
Chris Hughes recently wrote about this in his article, AppSec in the Age of Agents. FIRST is projecting roughly 59,000 new CVEs in 2026, while large organizations are already drowning in vulnerability backlogs in the hundreds of thousands. Hughes' point is clear: AI is industrializing vulnerability discovery while software development itself accelerates. More code creates more opportunities for vulnerabilities, while sharper security tooling uncovers even more of them.
It creates a strange, almost surreal cycle when you step back and look at it.
We use AI to write more code. We use AI to review more code. We use AI to find vulnerabilities in that code. Then we increasingly use AI to generate patches for the vulnerabilities AI found in code that AI helped create in the first place.
At some point, counting the number of findings stops being a useful measurement of security.
Daniel Miessler has been highlighting a related concept for years: context. Traditional application security spends far too much time listing vulnerabilities and not nearly enough time asking what can actually hurt the business. Agentic security will soon make it possible to continuously run asset management, attack-surface management, and vulnerability management at a scale humans simply can't match.
That direction makes total sense. But the really interesting part happens after the machine finds something. Because finding a vulnerability and understanding the real-world risk it creates are two completely different jobs.
A Critical Isn't Always Critical
You see this constantly in penetration testing.
A vulnerability can carry a terrifying CVSS score, yet sit in an environment that dramatically limits what an attacker can actually achieve with it. Conversely, a finding that looks mundane on paper might, when chained with something else, hand an attacker a direct path to sensitive customer data or admin rights. A scanner doesn't get that nuance. Neither does a static severity label.
CISA has been making a similar point, guidance from CISA warns that CVSS represents theoretical severity rather than real-world impact. It calls for prioritization based on actual exploitation, exploitability, reachability, and business context.
This becomes critical when the marginal cost of finding another bug drops to near zero. If an engineering team has 5,000 open findings today and AI drops another 15,000 in their lap tomorrow, congratulations are hardly in order. Someone still has to figure out what actually matters.

The Bottleneck Is Moving
This is where the AppSec conversation gets slightly backwards.
There is enormous excitement around AI replacing parts of security testing, and much of it is well-earned, the capabilities are getting remarkably good.
Hughes cites research showing DARPA's AI Cyber Challenge driving AI-assisted vulnerability discovery costs down to roughly $152 per vulnerability across 54 million lines of code. Other researchers have demonstrated agents producing working exploits at surprisingly low compute costs. Caveate, while the individual token cost is lower, the volume of agents running perpetually actually increases costs but that’s not today’s subject.
Gartner's 2026 Hype Cycle for Application Security reflects this shift as well. F5's summary of the report describes AI simultaneously expanding the application attack surface and enabling technologies like agentic security testing, behavioral exploit detection, and risk-based scoring.
All of this points to the exact same reality: discovery is getting easier.
That doesn't mean security gets easier. The bottleneck simply moves.
Daniel Miessler made an observation about AI and security professionals that hits the nail on the head: as AI gets better, deep expertise actually becomes more critical because someone still needs to judge whether the output is right. Judging the output becomes the core job.
The valuable question isn't "Did we find it?"
It's "Does it matter?"
Can someone actually exploit it? What does it connect to? What's the blast radius? Is this an isolated bug or evidence of an architectural flaw? Did the proposed fix eliminate the attack path, or did we just close a ticket?
When you break down those questions, you start speaking a language that aligns directly with executive leadership instead of saying "here is a bug that might cause a problem." Giving the "so what, now what" helps determine if an issue is material enough to focus on.
Measuring the Wrong Thing
One of the most telling data points in Hughes' article came from research by Gecko Security. Researchers traced 569 publicly disclosed findings in n8n and GitLab back to only 105 distinct root causes. In n8n, 67% of public disclosures were repeats of previously disclosed issues; for GitLab, it was 58%.
Think about that for a second.
We could celebrate finding 569 vulnerabilities. Or we could ask why we allowed 105 underlying problems to generate 569 vulnerabilities in the first place. Those two perspectives lead to completely different security programs. The first optimizes for throughput (find it, ticket it, fix it, close it). The second asks why the house keeps catching fire. That's where AppSec needs to go.

What to Do Differently
No one is suggesting throwing away scanners or stopping investment in AI security tools. Companies shouldn't stop finding vulnerabilities. Use the hell out of the technology.
Let AI scan millions of lines of code. Let it correlate findings, help write unit tests, spot patterns humans would never have time to find, and draft quick fixes. But change what the humans are accountable for. Instead of spending top security talent validating thousands of individual alerts, put their time into understanding attack paths, architecture, business logic, and recurring failure modes. When the same authorization flaw pops up six times, don't aim for six beautifully documented tickets. Put a senior security engineer in a room with the development team to figure out why the framework allowed that mistake six times. When something gets fixed, don't just mark the ticket resolved, have someone try the attack again. And when prioritizing what gets fixed first, look at what an attacker can actually accomplish, not simply which box happens to have the highest severity score.
This is also why penetration testing has to evolve. The value of a penetration test cannot be measured by the thickness of the report or the number of findings inside it. If AI makes vulnerability discovery dirt cheap, selling human hours to manually reproduce what a machine already found isn't a viable future.
Human testers need to move up the stack.
Use automation. Use the AI. Then experienced humans interpret what those findings mean together following the attack path, testing weird business logic, auditing architecture, working directly with developers on the fix, and coming back to break it again.
Findings Are Cheap. Judgment Isn't.

There is endless debate right now about whether AI will replace security engineers, developers, and penetration testers. That might be the least interesting question on the table.
AI is going to make parts of all those jobs incredibly cheap. And that's a good thing.
There is a massive amount of repetitive work in security that shouldn't require an expensive human being. Miessler describes much of this as "scaffolding": gathering context, maintaining tooling, and stitching together workflows so experts can do the actual work. AI can strip away that overhead. So let it.
The goal isn't to protect the old way of doing application security. It's to figure out what becomes valuable when the old constraints vanish. The answer is human judgment: knowing which vulnerability matters, understanding how three minor weaknesses chain together into one devastating attack path, recognizing when a bug is actually a system architecture problem, catching when an AI-generated fix looks right but isn't, and sitting down with an engineer to explain not just what to change, but why.
The next generation of AppSec programs will have no shortage of findings.
The organizations that win will be the ones that turn all that noise into fewer actual problems.
Finding more isn't the goal anymore. Fixing what matters is.
Reach out to Howl@wolfpacksecurity.co to learn more about Wolfpack Security
About Wolfpack Security
Wolfpack Security is an application security consultancy built around a simple idea: finding vulnerabilities is only useful if you know what to do with them. Our senior security practitioners work alongside engineering and security teams to test applications, APIs, cloud environments, networks, and AI systems, then help teams understand what actually matters and how to fix it.
We believe the future of security is human-led and technology-enabled. We use AI and automation to move faster and expand what our testers can see, while relying on experienced practitioners for the work that requires context, creativity, and judgment. The goal isn't a longer report or more findings. It's fewer real-world risks.

