Ivanti and AI shopping agents drive surge in reported software vulnerabilities
Ivanti announced it is now using artificial intelligence to locate software flaws, saying the technology will enable faster detection of issues that traditional tools miss. The company expects a rise in the number of reported vulnerabilities and associated patches, noting that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) already tracks dozens of actively exploited Ivanti flaws.
Security experts warned that autonomous AI shopping agents, which can access user accounts, payment systems and APIs, create new attack vectors. Techniques such as prompt‑injection could allow attackers to manipulate agents into unauthorized purchases or data exfiltration, dramatically expanding the attack surface.
Together, these developments underscore growing concerns that AI, while enhancing functionality, may also accelerate the discovery and exploitation of software vulnerabilities across enterprise and consumer e‑commerce platforms.