Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild

July 29, 2026

The Average Cost of a Data Breach Rises to $5 Million

July 29, 2026

How Synthetic Identity Fraud is Coming for Machine Identities

July 29, 2026
Facebook X (Twitter) Instagram
Wednesday, July 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild
Cyber Security

Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild

Team-CWDBy Team-CWDJuly 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Software vulnerabilities discovered using AI tools are being exploited at the same rate as those discovered without the use of AI, a VulnCheck researcher has found.

In VulnCheck’s State of Exploitation H1 2026 report, Patrick Garrity, vulnerability researcher, observed that 14 of the 1061 vulnerabilities attributed to AI-assisted discovery have been confirmed as exploited in the wild.

This represents 1.3% of vulnerabilities identified using AI, roughly matching the overall exploitation rate of all vulnerabilities for the reported period.

The researcher also found that while Anthropic reported more than 23,000 findings through its Project Glasswing, only 126 have resulted in published CVEs and just one has been confirmed as exploited in the wild.

These findings add nuance to warnings from some quarters that AI tools like Anthropic’s Mythos and other frontier models could trigger a ‘vulnpocalypse,’ flooding the security landscape with a wave of newly discovered, mass-exploited vulnerabilities.

Garrity said that for now, vulnerability intelligence shows evidence that the use of frontier AI models is “more likely to give cyber defenders an advantage in strengthening software than to give attackers an advantage in discovering vulnerabilities before the software producers do.”

KEV Exploitation Growth Lags Behind Rising CVE Volume

VulnCheck identified nearly 500 known exploited vulnerabilities (KEVs) in the first half of 2026.

These appear to be being exploited faster than ever before, with the median time from CVE publication to KEV falling from 120 days in 2025 to 80 days during the first half of 2026. 

However, the research found that 23.43% of KEVs recorded in the first half of 2026 showed evidence of exploitation on or before the day the CVE was published, a slight drop from the 28.93% of one-day and zero-day KEVs observed in 2025.

Additionally, exploitation activity early in the CVE lifecycle remained steady, with roughly 200 CVEs becoming exploited within 31 days in the first half of 2026.

“Early exploitation activity has not scaled at the same pace as CVE issuance,” said Garrity.

Content management systems (CMS) remained the most targeted technology category, accounting for 163 KEVs, one-third of all recorded KEVs.

They are followed by network edge devices (68), operating systems (44) and server software (40).

Meanwhile, AI products are emerging as a new attack surface, with known exploitation affecting model-building tools, workload-scaling platforms, AI gateways, agents and workflow automation.

The VulnCheck report includes every KEV added to VulnCheck’s own KEV catalog during the first half of 2026, based on CVE publication date and earliest evidence of exploitation.

The AI-discovered vulnerabilities mentioned in this report come from both Garrity’s own recording of vulnerabilities reported through Anthropic’s Project Glaswing and telemetry from the Berkeley Vulnerability Research Initiative.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe Average Cost of a Data Breach Rises to $5 Million
Team-CWD
  • Website

Related Posts

Cyber Security

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard

July 28, 2026
Cyber Security

AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface

July 23, 2026
Cyber Security

Employees Are Misusing AI tools at Work

July 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How the always-on generation can level up their cybersecurity game

September 11, 2025

Managing risks to your loved one’s digital estate

April 2, 2026

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.