roundup AI hunts bugs, breaks benchmarks, and undercuts course creators
AI-powered bug hunting triggered a 3.5x CVE surge. UK AISI says benchmarks underestimate agents by 60%. Course creators report 50%+ revenue drops from LLMs.
The big picture
AI is quietly shifting power in three directions at once: finding more security holes than humans ever did, proving it’s more capable than we measured, and hollowing out adjacent industries that existed to teach developers how to code.
AI is hunting bugs at industrial scale — and the numbers are staggering
Epoch AI data shows June 2026 produced roughly 1,500 high-severity and critical CVEs from just 21 organizations — more than 3.5 times the previous monthly record — and the timing lines up directly with the launch of AI-powered bug-hunting programs. The Decoder. This isn’t incremental. If one month’s AI bug-hunting yields 3.5x the prior record, the security industry’s triage capacity is already behind. Expect patch queues to grow faster than teams can respond.
Meanwhile, the UK’s AI Security Institute looked at seven standard AI benchmarks and found they systematically underestimate what agents can actually do — because the evaluations cap how many tokens the model is allowed to use. Give agents ten times the token budget and software engineering success rates jump about 25 percentage points. The Decoder. The AISI conclusion — that real frontier progress is roughly 60% steeper than published benchmarks suggest — should make anyone who’s been reassured by benchmark plateaus uncomfortable. The yardstick was wrong.
The two stories connect: we’ve been underestimating what these agents can do, and now we have the CVE pile to prove it.
The developer learning economy is taking a direct hit
Josh Comeau, a well-known developer educator, reported that his latest course launch is tracking at roughly one-third of a typical launch’s sales, and his existing courses are down significantly year over year. He attributes it to two compounding forces: developers are uncertain whether their jobs will exist in six months, so they’re not investing in skills; and even if they wanted to learn, LLMs now provide personalized tutoring for free. Simon Willison’s Weblog. He adds that other course creators he’s spoken with are seeing the same thing — revenue down 50% or more.
This is a canary. Paid tutorials and courses have always been a proxy for developer career confidence and learning investment. When that dries up, it signals something bigger than one creator’s bad quarter. If you’re building tools or content for developers, this trend is worth watching closely.
Open source AI finally gets a map
Current AI, a non-profit founded at the Paris AI Action Summit in early 2025 and backed by $400 million in committed capital, published its Open Source AI Gap Map v0.1. It indexes 421 products — 266 software tools and libraries, 85 models, 50 datasets, and 20 hardware projects — across 14 categories and three stack layers (model components, product/UX, and infrastructure). Another 24,400 artifacts sit in an uncategorized long tail. Simon Willison’s Weblog. A structured index of what exists and what’s missing in the open-source AI stack is genuinely useful — less so for daily work, more for anyone trying to figure out where to build or where to fund. The uncategorized long tail being 58x larger than the catalogued portion tells you how early this effort is.
Quick hits
- Midjourney’s dunk-tank ultrasound scanner got a 20-minute behind-the-scenes YouTube tour from an engineer at the company, who described it as ultrasound probes “hacked apart and slapped on a glorified hot tub” — still no clinical validation data. The Verge
- Netflix is using an ElevenLabs-generated Gene Wilder voice for its Willy Wonka reality show, with family consent — the latest in a string of posthumous AI voice productions. The Verge
- Tidal will stop paying royalties on tracks it identifies as 100% AI-generated starting now, and will add visible labels starting July 15th — no ban, just demonetization. The Verge
- Libby (the library ebook app) is adding reader-facing AI content filters so you can avoid AI-generated books — a sign that the signal-to-noise problem in publishing is now a product feature. The Verge
- MIT Tech Review notes that LLMs reliably output “7” when asked for a random number between 1 and 10 — a startup is trying to solve the groupthink-in-probability-distributions problem. MIT Technology Review
Sources
- The Decoder — AI bug hunting CVE surge
- The Decoder — UK AISI benchmark underestimation
- Simon Willison’s Weblog — Josh Comeau course revenue
- Simon Willison’s Weblog — Open Source AI Gap Map
- The Verge — Midjourney medical scanner
- The Verge — Netflix Gene Wilder AI voice
- The Verge — Tidal AI music policy
- The Verge — Libby AI content filter
- MIT Technology Review — LLM groupthink