BotBeat
...
← Back

> ▌

AnthropicAnthropic
RESEARCHAnthropic2026-07-28

VulnCheck Study: Only 1.3% of AI-Discovered Vulnerabilities Actually Exploited in Wild

Key Takeaways

  • ▸Only 1.3% of AI-discovered vulnerabilities have been confirmed as exploited in the wild, contradicting claims that frontier AI models are handing attackers a major advantage
  • ▸Project Glasswing's 23,019 identified vulnerability candidates have resulted in just 126 CVE publications and 1 confirmed exploit, revealing a massive gap between discovery and real-world impact
  • ▸AI is accelerating vulnerability discovery volume rather than increasing the exploitability rate—the same proportion of AI-found bugs are weaponized as traditional methods
Source:
Hacker Newshttps://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving-any-easier-to-exploit-despite-the-hype/5279637↗

Summary

VulnCheck research challenges the prevailing narrative around AI-assisted vulnerability discovery, revealing that fewer than 2% of vulnerabilities identified through AI tools have been weaponized by attackers. The study analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and Berkeley's research, cross-referencing them against known exploited vulnerabilities. Only 14 vulnerabilities (1.3%) showed confirmed exploitation—a rate nearly identical to traditional vulnerability discovery methods. Anthropic's much-publicized Project Glasswing, which identified 23,019 vulnerability candidates, has produced just 126 published CVEs and one confirmed real-world exploit, suggesting the dramatic security threat narrative has outpaced reality. Researchers argue AI's primary value lies in increasing vulnerability discovery volume rather than producing more exploitable flaws, ultimately benefiting defenders who can patch before attackers strike.

  • Security rhetoric around frontier AI capabilities has significantly outpaced evidence, though researchers stress this does not eliminate real risks to defenders

Editorial Opinion

The VulnCheck findings provide essential calibration to an increasingly hyperbolic debate around AI and cybersecurity. While frontier models like Claude Mythos can identify vastly more vulnerabilities than humans, raw discovery volume without exploitation tells a different story about actual security impact. The data suggests AI may ultimately benefit defenders more than adversaries—flooding security teams with patchable flaws before attackers can weaponize them. This doesn't mean AI-assisted attack is risk-free, but it does mean the doomsday scenarios deserve skepticism until the exploitation numbers catch up to the discovery claims.

Generative AIMachine LearningCybersecurityAI Safety & Alignment

More from Anthropic

AnthropicAnthropic
UPDATE

Anthropic Releases ACP v2 Protocol in Draft with Major Developer Improvements

2026-07-28
AnthropicAnthropic
PARTNERSHIP

Bun Runtime Now Auto-Generates Claude.md Files by Default

2026-07-28
AnthropicAnthropic
INDUSTRY REPORT

Model Distillation Creates Hidden Cost Crisis for Frontier AI Labs

2026-07-28

Comments

Suggested

AirwarsAirwars
RESEARCH

Anatomy of an AI Kill Chain: How Autonomous Systems Are Replacing Human Decision-Making in Warfare

2026-07-28
OpenAIOpenAI
POLICY & REGULATION

The Worst Way to Regulate AI

2026-07-28
AmazonAmazon
INDUSTRY REPORT

Big Tech's Record Debt Binge for AI Infrastructure Fuels Bubble Concerns

2026-07-28
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us