AI Agent Discovers 21 FFmpeg Vulnerabilities for Minimal Cost

An autonomous security tool discovered two dozen zero-days in a foundational open-source library for a bounty under $1,000. Chrome released 429 patches in a single update. Together, these developments expose how economically unviable traditional bug-hunting has become against algorithmic exploitation. Vulnerability discovery is now outpacing vendor remediation capacity, forcing a structural shift in who bears the cost of security work as AI agents commoditize the researcher's role. The economics of security labor are collapsing faster than policy or practice can adapt.