** Abstract digital illustration showing AI analyzing computer code to find hidden security vulnerabilities

AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code

😊 Feel Good

An AI security agent just found 21 hidden vulnerabilities in FFmpeg, a video software used by billions of devices worldwide, including one bug that sat undetected for 23 years. The discovery cost just $1,000 and signals a new era where artificial intelligence can spot dangerous security flaws faster and cheaper than ever before.

A tiny AI agent just accomplished what human security experts missed for more than two decades.

The autonomous program, created by startup depthfirst, scanned 1.5 million lines of code in FFmpeg, the media software that powers video playback in nearly every app and device you use. It found 21 previously unknown security vulnerabilities, each one a potential doorway for hackers. The entire operation cost around $1,000.

One bug had been hiding in plain sight since 2003. For 23 years, it sat dormant in code that millions of developers looked at, tested, and used. Several others had lurked undetected for 15 to 20 years.

The AI didn't just flag suspicious code. It produced working proof-of-concept attacks for each vulnerability, the kind of detailed evidence that helps programmers understand exactly what needs fixing. Most of the bugs involve memory errors that could let attackers crash systems or potentially take control of devices.

This breakthrough arrived the same week Google Chrome released its largest security update ever, patching 429 vulnerabilities in a single release. While those weren't all AI-discovered, Google recently overhauled its bug bounty program to handle the surge of AI-generated security reports flooding in.

AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code

Other AI agents are joining the hunt too. Google's Big Sleep found its own set of FFmpeg bugs last year. Anthropic's Mythos model uncovered a 16-year-old flaw for about $10,000. Days ago, another autonomous tool caught a serious Redis security hole that had gone unnoticed for over two years.

The Bright Side

Finding security vulnerabilities used to require expensive teams of expert hackers spending months combing through code. Now AI agents can do similar work in days or weeks for a fraction of the cost.

That democratization means smaller open-source projects, which often rely on volunteer developers with limited budgets, can finally afford thorough security audits. The software protecting your photos, videos, and personal data can become safer faster.

The FFmpeg team has already fixed most of the discovered bugs, with patches rolling out to users now. Chrome updates automatically for most people, bringing those 429 fixes without anyone lifting a finger.

This isn't about replacing human security researchers. It's about giving them a tireless assistant that can scan millions of lines of code while they focus on the complex analysis and creative problem-solving that machines still can't match. Together, they're making the digital world more secure than either could alone.

The age of AI-powered security has arrived, and it's finding the needles in haystacks that kept us vulnerable for decades.

More Images

AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code - Image 2
AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code - Image 3
AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code - Image 4
AI Discovers 21 Hidden Software Bugs in 23-Year-Old Code - Image 5

Based on reporting by Google News - Technology

This story was written by BrightWire based on verified news reports.

Spread the positivity!

Share this good news with someone who needs it

More Good News