Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

AI-assisted security tools are finding more bugs, but the threat level has not changed

Дата публикации: 28-07-2026 15:08:42

Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones.
The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop.


Основное содержимое страницы с новостью.

AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report Tuesday. 

Concerns remain high about AI-discovered vulnerabilities fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far. 

Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period. 

“While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote.

While AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing rolled out in April, while Microsoft’s MDASH and OpenAI’s Daybreak were both unveiled in May.

The upward trend in Microsoft’s monthly Patch Tuesday indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an all-time-record of 622 vulnerabilities, besting the previous record-breaking June update with 206 vulnerabilities.

VulnCheck’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.

The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products — an emerging attack surface — at almost 6%.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI is finding bugs faster than Microsoft can fix them013.4130-07-2026
2The AI code vulnerabilities that grow with your app08.8223-07-2026
3Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics0624-06-2026
4Безопасники бьют тревогу. В сервисах ИИ двукратный рост ИТ-уязвимостей117.7803-08-2026
5The Hidden Cost of AI Security Scanners0720-05-2026
6AI models keep getting caught cheating08.9821-07-2026
7Google gives developers an AI bug hunter that also writes patches07.8824-07-2026
8GitHub revamps bug bounty program with new VIP tier, payout changes013.3823-07-2026
9OpenAI Expands GPT-5.5-Cyber as AI Pushes Vulnerability Patching Into a New Era5724-06-2026
10AI Agents Are Creating a New Enterprise Security Gap0503-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.97. Источник: www.cyberscoop.com.