
Palo Alto Networks has introduced NOVA, a fully autonomous AI-powered vulnerability research system designed to discover, validate and document previously unknown software vulnerabilities.
The results are striking. During a two-month evaluation, NOVA analysed 3,915 open-source software projects and identified 14,090 previously unknown vulnerabilities. About 99.4% had not been publicly reported, while nearly 40% were rated High or Critical under CVSS 4.0.
The bigger point is not just the number of findings. It is how much of the research process AI can now handle. NOVA can review source code, identify potential flaws, generate and validate proof-of-concept exploits, prepare disclosure reports and suggest patch candidates.
That moves AI beyond being a tool for individual security tasks toward a system that can handle large parts of the vulnerability research workflow.
Software vulnerabilities are moving beyond traditional bug hunting
NOVA’s findings also challenge the idea that automated security research mainly works on bugs that are easy to find through traditional techniques.
According to the research, 92% of NOVA’s findings were broader logic and semantic vulnerabilities. These included access control and authorisation flaws, path traversal, code injection, prototype pollution and server-side request forgery.
That matters because these types of software vulnerabilities have traditionally required more manual analysis. The research suggests that frontier AI is becoming capable of examining the logic and behaviour of software in ways that can uncover less obvious security weaknesses.
The testing also found value in using multiple AI models. Every model identified vulnerabilities that other models missed. Combining different models therefore improved vulnerability coverage, especially across larger and more complex software projects.
Open-source software security flaws can spread further
The research highlights another concern: software supply chains.
NOVA identified 5,421 supply-chain findings, including 1,280 vulnerabilities in dependency packages. These resulted in 4,141 downstream software exposures. The system validated 2,776 of those exposure paths using working proof-of-concept exploits.
The numbers show why open-source software security flaws can become a wider problem. A vulnerability in one commonly used component may affect multiple applications that depend on it.
For organisations, the challenge is therefore not limited to finding flaws in their own code. Understanding where vulnerable dependencies are used becomes equally important.
Zero-day vulnerabilities could shrink the response window
The research points to a broader shift in cybersecurity. If AI can discover and validate unknown vulnerabilities previously in days rather than months, security teams may have less time to assess risk and deploy mitigations.
This changes the pressure around Zero-Day Vulnerabilities. Discovery is becoming faster, but disclosure, validation and remediation processes still need to keep pace.
The issue is not simply how many flaws AI can find. It is whether organisations can quickly determine which findings matter, understand their exposure and act before those weaknesses become a bigger problem.
Read More:
Why Technology is Now a Strategic Differentiator
ASIRT Synergy Biz Conclave 2026 Highlights Cybersecurity, Networking and Channel Opportunities
From Brazil to Bharat: Nine Months of Witnessing India Rewrite the Tech Playbook
How AI and Performance Intelligence Build Better Sales Teams
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us