cd /news/artificial-intelligence/ai-assisted-security-tools-are-findi… · home topics artificial-intelligence article
[ARTICLE · art-77163] src=cyberscoop.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

AI-assisted security tools are finding more bugs, but the threat level has not changed

AI-assisted security tools like Anthropic's Project Glasswing and Microsoft's MDASH discovered 1,061 vulnerabilities in the first half of 2026, but only 14 (1.3%) were exploited in the wild, matching the overall exploitation rate, according to a VulnCheck report released Tuesday. The findings suggest AI-discovered bugs are not inherently more exploitable, though the trend may shift as major models launched in April and May 2026 ramp up. Meanwhile, average time to exploitation after CVE publication dropped from 120 days in 2025 to 80 days in H1 2026, and content management systems accounted for nearly one-third of exploited vulnerabilities.

read2 min views5 publishedJul 28, 2026
AI-assisted security tools are finding more bugs, but the threat level has not changed
Image: Cyberscoop (auto-discovered)

AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report Tuesday.

Concerns remain high about AI-discovered vulnerabilities fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far.

Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period.

“While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote.

While AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing rolled out in April, while Microsoft’s MDASH and OpenAI’s Daybreak were both unveiled in May. The upward trend in Microsoft’s monthly Patch Tuesday indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an all-time-record of 622 vulnerabilities, besting the previous record-breaking June update with 206 vulnerabilities.

VulnCheck’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.

The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products — an emerging attack surface — at almost 6%.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @vulncheck 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-assisted-security…] indexed:0 read:2min 2026-07-28 ·