Skip to main content
CybersecurityVulnerability Management

AI-Assisted Bug Discovery Falls Short of Expected Exploit Wave

Researcher's workstation with laptop, books, and notes, under bright lighting, with a focused yet inactive atmosphere.

Claude Mythos may have identified 23,019 vulnerability candidates.

VulnCheck's cross-check with the KEV database

VulnCheck took a measurable cut at the question of whether AI-assisted discovery is producing a ready-made assault wave. The firm "analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability (KEV) database." The result was stark: just 14 vulnerabilities — 1.3 percent of the sample — have been confirmed as exploited in the wild.

That 1.3 percent figure, VulnCheck reported, is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset." In other words, the raw numbers show a big increase in reported candidates, but not an increased rate of confirmed exploitation compared with historical baselines from VulnCheck's data.

Anthropic's Project Glasswing: volume versus public trace

Project Glasswing has drawn attention for scale. Anthropic's public tally suggests Claude Mythos may have identified 23,019 vulnerability candidates. But the public trace of what followed is thin: VulnCheck notes that only 126 of those candidates have been published as CVEs, and that just one has been confirmed exploited in the wild. Anthropic's public disclosure record, VulnCheck added, "has seen little movement since Project Glasswing launched."

That gap — tens of thousands of candidates vs. a few hundred CVEs and a single confirmed exploit — is central to the debate over whether AI is currently shifting advantage toward attackers or primarily accelerating the pace of discovery for both sides.

How Patrick Garrity of VulnCheck frames the findings

Patrick Garrity, a security researcher at VulnCheck, characterizes the data as cautionary about the headlines. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," he wrote, but "the data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Garrity continued that "the data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today."

He qualified that view: "That doesn't mean the risk is imaginary. It means the impact has been real but modest." In short, AI is increasing discovery volume, and that matters — but the current record does not show a corresponding surge in confirmed exploitation.

Known exploited vulnerabilities in the first half of 2026

VulnCheck's work also placed AI-assisted findings alongside the broader landscape of active exploitation. The firm identified 495 known exploited vulnerabilities during the first half of 2026. Content management systems accounted for roughly one-third of those cases, and network edge devices "remain a firm favorite" for attackers. The report further notes that AI products themselves are increasingly attractive targets as attackers pivot from merely using AI toward hunting weaknesses in the expanding AI software stack.

What this means for defenders, attackers, and vendors

  • Defenders and security teams: The increase in discovered flaws — even those not yet weaponized — creates more items to triage and patch. VulnCheck's framing suggests defenders have a practical window to remediate before criminals exploit newly discovered issues.
  • Attackers and threat actors: AI appears to be lowering the cost of discovery, but the evidence so far does not show AI-discovered bugs are inherently more exploitable; attackers still prioritize familiar targets such as content management systems and network edge devices.
  • Vendors and disclosure programs: Project Glasswing's large candidate list and Anthropic's limited public CVE tally highlight the operational challenge of converting raw findings into coordinated disclosure and patching — a step that materially affects whether a vulnerability ever becomes a confirmed in-the-wild exploit.

The arithmetic in VulnCheck's analysis matters: more flagged candidates does not automatically equal more exploited systems. For now, the record shows a surge in discovery volume — and a modest, not apocalyptic, increase in confirmed exploitation. The unanswered practical question the data leaves on the table is familiar: of the tens of thousands of candidates unearthed, which will move from candidate to CVE to confirmed exploit — and on what timetable? How quickly disclosure and patching keep pace will determine whether the modest impact observed so far tightens into a larger problem.

https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving_any_easier_to_exploit_despite_the_hype/5279637