How this was built, and what to distrust
Sourcing
Data was collected across five independent research passes — Patch Tuesday, CVE macro trends, AI-discovery evidence, attacker/exploitation trends, and CWE type shifts — each required to return both the signal and the counter-signal. Every figure traces to a named, dated source. Two independent sources were sought for each annual CVE total.
What we corrected
An early recall-based pass produced anomalous 2026 Patch Tuesday totals (July "621", June "208"). These were re-verified against live Zero Day Initiative, Tenable, and Krebs pages and corrected to 569 and 200 Microsoft CVEs. The "622" figure some outlets ran for July includes third-party and Chromium republished advisories; this site uses Microsoft's own new-CVE count throughout for consistency.
Known limitations
- Monthly CVE granularity is thin — most trackers render counts in JavaScript. Annual figures are solid; intra-year monthly series are partial.
- 2016–2021 annual totals rest largely on one renderable source (cvedetails), counted by CVE-ID year; marked medium-confidence in the data.
- Zero-day-in-the-wild counts are Google/Mandiant telemetry, self-revised each year — not independently corroborated.
- No dataset cleanly isolates an AI-attributable effect from structural confounders. Every "AI caused X" claim here is labeled as asserted vs demonstrated.
Stance
This site is deliberately neutral. It does not conclude that AI "favors" attackers or defenders. It reports what the disclosure, exploitation, and type data show, separates that from what vendors claim, and marks the questions the data can't answer. The raw data files behind every chart are available on request.