0
Deep & Emerging Tech·July 30, 2026·1 min read

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Share

AI-assisted bug hunting has Chrome patching twice a week and fixing more issues in two updates than in the prior 23—defense is now operating at model speed. Security teams should prepare for a world where both attackers and defenders iterate this fast, and where your real bottleneck is patch deployment and testing, not vulnerability discovery.

Deep & Emerging Tech

Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Four compromised npm packages over 18 months—via social engineering of maintainers—reinforces that your software supply chain risk now includes upstream humans, not just code. Lock down dependency policies, pin and mirror critical packages, and assume popular OSS components are active targets for state-linked actors.