AI-discovered bugs have sparked fears of a major new wave of cyberattacks. However, new research suggests that vulnerabilities found with AI are not currently more likely to be exploited than flaws discovered through traditional methods.

VulnCheck reviewed more than 1,000 AI-assisted vulnerability discoveries and found that only 1.3% had been confirmed as exploited in the wild. That rate broadly matches the overall exploitation rate for vulnerabilities reported this year.

Research questions the AI vulnerability hype

AI companies have repeatedly warned that advanced models could make it easier for criminals to discover and weaponise software flaws. Anthropic, for example, limited access to its Mythos model after saying it had identified thousands of vulnerabilities across major operating systems and browsers.

The company argued that widespread access to such tools could increase cyber risks. Yet some security experts questioned whether stronger vulnerability discovery would immediately translate into more successful attacks.

Isaac Evans, the founder and chief executive of software security firm Semgrep, described Mythos as a real technical advance. Still, he said concerns about its immediate real-world impact went beyond the available evidence.

New data from VulnCheck supports that more cautious view.

Only 14 AI-found flaws were exploited

VulnCheck analysed 1,061 vulnerabilities linked to AI-assisted discovery from Anthropic’s Project Glasswing and the Berkeley Vulnerability Research Initiative.

Researchers then compared those findings with the company’s Known Exploited Vulnerability database. Of the 1,061 AI-assisted discoveries, only 14 had confirmed evidence of exploitation in the wild.

That equals an exploitation rate of roughly 1.3%. According to VulnCheck, this figure is close to the rate for all vulnerabilities recorded during the first half of the year.

The findings do not show that AI-discovered bugs are inherently more dangerous or more attractive to attackers.

Thousands of candidates do not mean thousands of threats

Anthropic has reported more than 23,000 vulnerability candidates through Project Glasswing. However, only 126 of those reports have resulted in published CVEs so far.

Just one of those confirmed vulnerabilities has been exploited in the wild, according to the research.

This gap highlights an important point. Finding a potential weakness is not the same as identifying a confirmed, exploitable security flaw.

Many discovered issues may prove difficult to exploit, require unusual conditions or have limited security impact. Others may be fixed before attackers have an opportunity to use them.

AI can still help both attackers and defenders

The research does not suggest that AI-driven vulnerability discovery is harmless. Advanced models can increase the number of potential bugs researchers identify, and that capability could eventually benefit attackers as well as defenders.

For now, the clearest benefit may be on the defensive side. Security teams can use AI-assisted tools to find and fix weaknesses earlier, before they become part of an attacker’s toolkit.

VulnCheck said the current evidence shows a real but modest impact. The data does not support claims that AI-found flaws have already created a dramatically larger pool of readily exploitable bugs.

The exploitation rate could change over time

The picture may change as frontier cyber models become more powerful and widely available. Greater access could help less-skilled attackers identify flaws, develop exploits or adapt existing attack methods.

However, the current numbers offer little evidence of a sudden surge in AI-driven exploitation. At present, AI-discovered bugs appear to face roughly the same real-world exploitation challenges as vulnerabilities found by human researchers.

Time will show whether that rate rises. Until then, organisations should focus on patching known flaws quickly, maintaining strong vulnerability management and using AI tools to improve their own security testing.


0 responses to “AI-Discovered Bugs Are Not Yet a Cybercrime Goldmine, Study Finds”