AI-found bugs aren’t proving any easier to exploit despite the hype
New research from security firm VulnCheck suggests that AI-assisted vulnerability discovery is not making bugs meaningfully easier for attackers to exploit, despite fears it would give criminals a major edge. The findings challenge the narrative surrounding Anthropic's Project Glasswing, which had warned that AI tools like Claude Mythos could enable attackers to hijack systems, steal data or disrupt operations at scale.
VulnCheck analysed 1,061 publicly attributed AI-assisted vulnerability discoveries from Project Glasswing and the Berkeley Vulnerability Research Initiative, finding just 14 (1.3 percent) had been confirmed as exploited in the wild — almost identical to the exploitation rate across all vulnerabilities generally. Of the 23,019 vulnerability candidates identified by Claude Mythos, only 126 have become published CVEs and just one has been confirmed exploited. VulnCheck researcher Patrick Garrity said the technology clearly has value for both attackers and defenders by increasing the volume of flaws found, but concluded that claims about frontier AI capabilities have been "overhyped relative to the evidence available today," adding that the impact "has been real but modest." Separately, VulnCheck recorded 495 known exploited vulnerabilities in the first half of 2026, with content management systems and network edge devices remaining common targets, while AI products themselves are increasingly being targeted by attackers.
- Only 1.3% of AI-found bugs have been exploited in the wild
- Anthropic's Project Glasswing hype not matched by real-world attacks
- Researcher says AI's security impact is "real but modest," not overblown