In 2026, OpenStack published more security advisories than in the previous eight years combined. AI models are analysing software on a massive scale, uncovering vulnerabilities that in some cases date back decades. How do we, as a community, respond to this?