You joke of course, but finding new exploits with automation a real thing, scary effective with GPT-6 Astra as it recently scored a 100% on ExploitBench. Literally, the method of measuring how good it is has become insufficient. Anyway, we know Microsoft is automating these same kinds of tasks internally as well. Should we really complain that they aren't taking months or years? I think verifying AI patches actually work is the key point here, for both security and reliability, where the code came from doesn't matter if it works. So far the last patch and this patch hasn't brought the world to a screeching halt due to the shear number of fixes.