How this was built, and what to distrust
Sourcing
Data was collected across five independent research passes — Patch Tuesday, CVE macro trends, AI-discovery evidence, attacker/exploitation trends, and CWE type shifts — each required to return both the signal and the counter-signal. Every figure traces to a named, dated source. Two independent sources were sought for each annual CVE total.
What we corrected
An early recall-based pass produced anomalous 2026 Patch Tuesday totals (July "621", June "208"). These were re-verified against live Zero Day Initiative, Tenable, and Krebs pages and corrected to 569 and 200 Microsoft CVEs. The "622" figure some outlets ran for July includes third-party and Chromium republished advisories; this site uses Microsoft's own new-CVE count throughout for consistency.
Known limitations
- Monthly CVE granularity is thin — most trackers render counts in JavaScript. Annual figures are solid; intra-year monthly series are partial.
- 2016–2021 annual totals rest largely on one renderable source (cvedetails), counted by CVE-ID year; marked medium-confidence in the data.
- Zero-day-in-the-wild counts are Google/Mandiant telemetry, self-revised each year — not independently corroborated.
- No dataset cleanly isolates an AI-attributable effect from structural confounders. Every "AI caused X" claim here is labeled as asserted vs demonstrated.
- Breach data carries its own traps, kept explicit on the Breaches page: ITRC changed methodology in 2020 (breaches/records → compromises/victim notices — the victim metric is not continuous and is never charted across the break); ITRC silently restates prior-year totals by a few events between editions (this site uses as-originally-reported figures, restatements noted in the data file); DBIR counts track its changing contributor base, not world breach volume (vector percentages are the trend signal, raw counts are not); DBIR editions before 2021 and IBM's 2016 figure were omitted rather than published unverified.
Stance
This site is deliberately neutral. It does not conclude that AI "favors" attackers or defenders. It reports what the disclosure, exploitation, and type data show, separates that from what vendors claim, and marks the questions the data can't answer. The raw data files behind every chart are public in Substrate.
The standing analysis
The Analysis page re-asks the same questions across every dataset — are breaches rising because of AI, what mechanisms the data supports, and what it can't answer. It is bound to the data by a build gate: adding a data source without covering it in the analysis fails the build, so the synthesis cannot silently go stale.