AI-found bugs aren't proving any easier to exploit despite the hype

sbulaev1 pts0 comments

AI-found bugs aren't proving any easier to exploit despite the hype

Jump to main content

Search

REG AD

SECURITY

AI-found bugs aren't proving any easier to exploit despite the hype

VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage

Carly Page

Carly<br>Page

Published<br>tue 28 Jul 2026 // 16:26 UTC

Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected.<br>In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability (KEV) database.<br>The result: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset.

REG AD

That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs. Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit.

REG AD

The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data.<br>Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched.<br>But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck.<br>"AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.<br>Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality.

MORE CONTEXT

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

It blocked us at 'hello!' Anthropic Fable 5 refusing innocuous prompts

Anthropic spins a Fable of a tamer, safer Mythos

"The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."<br>Meanwhile, attackers haven't exactly been sitting idle. VulnCheck identified 495 known exploited vulnerabilities during the first half of 2026, with content management systems accounting for roughly one-third of them and network edge devices remaining a firm favorite. AI products themselves are also becoming an increasingly attractive target, as attackers look beyond using AI and start hunting for weaknesses in the rapidly expanding AI software stack.<br>In other words, AI may be changing vulnerability research, but it hasn't yet produced the exploitation apocalypse some predicted. ®

ai and ml<br>vulnerability<br>security<br>anthropic

REG AD

AI and ML

War machines can run amok with AI in control

Tour of the AI kill chain maps the risks of ubiquitous surveillance and flawed algorithms

Security

Microsoft and Wiz mind-meld agents catch more than 90% of bugs

Secret to their success: Using the right model for the right security job

AI has changed data architecture, but storage hasn't caught up

SPONSORED FEATURE: AI's hunger for data outstrips storage smarts, leaving GPUs famished

AI and ML

AI is storage’s biggest opportunity - and biggest threat

Faster access and more secure recoveries are driving business, but mishaps and attacks can endanger data

columnists

Digital sovereignty is real in Europe. The UK? Not so much

Trump's unpredictability is pushing governments and businesses toward open source while Britain remains glued to US tech

ai and ml

College prof hides prompt to catch AI cheaters, finds human nature is pretty much as we thought

32 of 35 students were caught in his nonsense...

vulnerability anthropic security assisted attackers data

Related Articles