公司动向The Decoder5/10

AI finds plenty of security flaws, but almost none of them get exploited

By Thomas Joos

AI finds plenty of security flaws, but almost none of them get exploited
图源:The Decoder

AI 摘要

VulnCheck counted how often security flaws found by AI actually get exploited. Out of 1,061 AI-discovered vulnerabilities in the first half of 2026, just 14 saw confirmed attacks. That's 1.3 percent, the same rate as vulnerabilities overall. But exploits are landing faster, with the median dropping

原文正文

AI finds plenty of security flaws, but almost none of them get exploited

VulnCheck counted how often the security flaws that AI turns up are ever used in an attack. For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen showed confirmed exploitation. That's 1.3%, roughly the same rate as vulnerabilities overall. Anthropic's Project Glasswing produced more than 23,000 findings, which led to 126 published entries and a single confirmed attack.

Attacks are landing faster, though. Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 200 were attacked within a month, even as the total number of reported vulnerabilities keeps climbing.

Website content management systems take the most hits, accounting for a third of all cases. Garrity flags AI products themselves as a growing attack surface, including model-building tools and agent interfaces. The sheer volume of findings, in other words, tells defenders very little about actual risk.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.

Subscribe now

阅读原文
AI finds plenty of security flaws, but almost none of them get exploited · AI Daily