VulnCheck finds only 1.3% of AI-assisted bugs were actually exploited
R_D · x · 2026-07-29
A VulnCheck analysis of 1,061 publicly attributed AI-assisted vulnerability discoveries found that only 14, or 1.3%, were confirmed exploited in the wild — nearly the same rate as vulnerabilities overall.
- The report says AI is increasing the volume of bugs researchers can find, but not the share that attackers can actually weaponize.
- It specifically questions the narrative around Anthropic’s Project Glasswing, which reportedly surfaced 23,019 vulnerability candidates.
- Of those, only 126 have become CVEs, and just one is confirmed exploited so far.
- The data suggests frontier models may be better at discovery than at accelerating real-world attacks.
More from Safety
- US Airlines Ban Humanoid Robots from Flights Citing Battery and Safety Risks — carlosdponx · 2026-07-29
- ResearchArena tests whether monitors can catch sabotage in automated AI R&D — maksym_andr · 2026-07-29
- Polymarket prices a 60% chance of a state data-center moratorium by year-end — Polymarket · 2026-07-29
- AI “pacing” systems could become a leveraged control layer, the author warns — TinfoilTricorn · 2026-07-29
- Research Discusses MoE Security Flaw: Safety Layers Might Be AI's Biggest Zero-Day Threat — JimR_Ai_Research · 2026-07-29
- What Anthropic’s alignment-faking paper shows — and what it does not — Passelume · 2026-07-29