AI finds plenty of security flaws, but almost none of them get exploited
By Thomas Joos

AI 摘要
VulnCheck counted how often security flaws found by AI actually get exploited. Out of 1,061 AI-discovered vulnerabilities in the first half of 2026, just 14 saw confirmed attacks. That's 1.3 percent, the same rate as vulnerabilities overall. But exploits are landing faster, with the median dropping
原文正文
AI finds plenty of security flaws, but almost none of them get exploited
VulnCheck counted how often the security flaws that AI turns up are ever used in an attack. For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen showed confirmed exploitation. That's 1.3%, roughly the same rate as vulnerabilities overall. Anthropic's Project Glasswing produced more than 23,000 findings, which led to 126 published entries and a single confirmed attack.
Attacks are landing faster, though. Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 200 were attacked within a month, even as the total number of reported vulnerabilities keeps climbing.
Website content management systems take the most hits, accounting for a third of all cases. Garrity flags AI products themselves as a growing attack surface, including model-building tools and agent interfaces. The sheer volume of findings, in other words, tells defenders very little about actual risk.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
Subscribe now