vulnerability counts mean less now

first, i think this is such a good post and i highly recommend reading it.

Before 2026, I kept a record of many of my CVE numbers, and every vulnerability represented a train of thought to me. In 2026, I stopped keeping a complete record of them, even though there were more than in all the previous years combined.

Zhiniang Peng, A Year of Hacking with LLMs.

this quote is spot on about where vulnerability research is heading. vulnerability counts have already hurt much of the razzle dazzle as a measure of researcher skill. reaching for higher impact, like pre-auth rce, still represents amazing work. don’t get me wrong. it just feels different than it once did.

i love the idea of relooking at areas we maybe thought were out of grasp in the past. Peng describes asking a model to prove his unpublished cryptographic scheme secure and getting an attack back instead. the model then extended that structural weakness to related constructions. his own scheme had never had a completed proof.

i think this brings us back to curiosity. there are old ideas worth testing again and assumptions worth questioning with tools we did not have before.