It's never clear what's "real" vs. marketing for the LLM companies, but Mozilla at least has made a big deal publicly about the "unprecedented" number of "latent security bugs" they've found using tools like Mythos:
https://blog.mozilla.org/en/firefox/privacy-security/ai-secu...
https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin...
To be honest, I'm not sure how many (if any) of them have actually been exploited, but in any case, it seems like the cost to at least find a vulnerability anymore has really dropped dramatically.