{"slug": "ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not", "title": "AI-assisted security tools are finding more bugs, but the threat level has not changed", "summary": "AI-assisted security tools like Anthropic's Project Glasswing and Microsoft's MDASH discovered 1,061 vulnerabilities in the first half of 2026, but only 14 (1.3%) were exploited in the wild, matching the overall exploitation rate, according to a VulnCheck report released Tuesday. The findings suggest AI-discovered bugs are not inherently more exploitable, though the trend may shift as major models launched in April and May 2026 ramp up. Meanwhile, average time to exploitation after CVE publication dropped from 120 days in 2025 to 80 days in H1 2026, and content management systems accounted for nearly one-third of exploited vulnerabilities.", "body_md": "# AI-assisted security tools are finding more bugs, but the threat level has not changed\n\nAI systems like Anthropic’s [Project Glasswing](https://cyberscoop.com/tag/project-glasswing/) and [Microsoft’s MDASH](https://cyberscoop.com/microsoft-ai-cybersecurity-project-perception/) are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a [report](https://www.vulncheck.com/blog/state-of-exploitation-1h-2026) Tuesday.\n\nConcerns remain high about [AI](https://cyberscoop.com/tag/artificial-intelligence-ai/)-discovered [vulnerabilities](https://cyberscoop.com/tag/vulnerabilities/) fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far.\n\nPatrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period.\n\n“While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote.\n\nWhile AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing [rolled out in April](https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnerabilities/), while Microsoft’s MDASH and [OpenAI’s Daybreak](https://cyberscoop.com/openai-daybreak-gpt-5-5-anthropic-mythos-cybersecurity/) were both unveiled in May.\n\nThe upward trend in Microsoft’s monthly [Patch Tuesday](https://cyberscoop.com/tag/patch-tuesday/) indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an [all-time-record of 622 vulnerabilities](https://cyberscoop.com/microsoft-patch-tuesday-july-2026/), besting the previous record-breaking [June update with 206 vulnerabilities](https://cyberscoop.com/microsoft-patch-tuesday-june-2026/).\n\n[VulnCheck](https://cyberscoop.com/tag/vulncheck/)’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.\n\nThe intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products — an emerging attack surface — at almost 6%.", "url": "https://wpnews.pro/news/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not", "canonical_source": "https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/", "published_at": "2026-07-28 15:08:42+00:00", "updated_at": "2026-07-28 15:26:46.943121+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-research"], "entities": ["VulnCheck", "Anthropic", "Project Glasswing", "Microsoft", "MDASH", "OpenAI", "Daybreak", "Patrick Garrity"], "alternates": {"html": "https://wpnews.pro/news/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not", "markdown": "https://wpnews.pro/news/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not.md", "text": "https://wpnews.pro/news/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not.txt", "jsonld": "https://wpnews.pro/news/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not.jsonld"}}