Cybersecurity Research

AI-Powered Scanning Uncovers Over 14,000 Hidden Flaws in Open-Source Software

Unit 42 · 4 Aug 2026
Key Takeaway Keep all software, plugins, and open-source components updated promptly, since AI-driven research shows there are far more hidden vulnerabilities than businesses may realise.

Cybersecurity researchers at Unit 42 have revealed how advanced AI technology is transforming the way software vulnerabilities are found. Using a system called NOVA, they were able to automatically scan open-source software components and uncover more than 14,000 previously unknown security flaws, many of which could potentially be exploited by attackers before official fixes exist.

This matters for Australian small businesses because most modern software, whether it's a website plugin, a business app, or backend systems, relies heavily on open-source code. If a vulnerability is discovered before a patch is available, it becomes a 'zero-day' risk that attackers can exploit. The scale of this discovery, over 14,000 issues, highlights just how much hidden risk exists in the software supply chain that businesses depend on every day.

While this research is aimed at helping the security community identify and fix problems faster, it also demonstrates that AI tools can be used to find weaknesses at a much larger and faster scale than manual methods. This means businesses need to stay vigilant about applying software updates and patches as soon as they become available, since the pool of undiscovered vulnerabilities is likely larger than previously assumed.

open-source security zero-day vulnerabilities AI in cybersecurity software supply chain patch management
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.