{"id":121587,"date":"2026-07-28T15:40:11","date_gmt":"2026-07-28T15:40:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/121587\/"},"modified":"2026-07-28T15:40:11","modified_gmt":"2026-07-28T15:40:11","slug":"ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/121587\/","title":{"rendered":"AI-assisted security tools are finding more bugs, but the threat level has not changed"},"content":{"rendered":"<p>AI systems like Anthropic\u2019s <a href=\"https:\/\/cyberscoop.com\/tag\/project-glasswing\/\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a> and <a href=\"https:\/\/cyberscoop.com\/microsoft-ai-cybersecurity-project-perception\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft\u2019s MDASH<\/a> are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a <a href=\"https:\/\/www.vulncheck.com\/blog\/state-of-exploitation-1h-2026\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a> Tuesday.\u00a0<\/p>\n<p>Concerns remain high about <a href=\"https:\/\/cyberscoop.com\/tag\/artificial-intelligence-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">AI<\/a>-discovered <a href=\"https:\/\/cyberscoop.com\/tag\/vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">vulnerabilities<\/a> fueling more attacks, but VulnCheck\u2019s review of exploitation data shows that those fears are unfounded, at least so far.\u00a0<\/p>\n<p>Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period.\u00a0<\/p>\n<p>\u201cWhile AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,\u201d Garrity wrote.<\/p>\n<p>While AI\u2019s contribution to actively exploited vulnerabilities was muted in the first half of the year, it\u2019s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing <a href=\"https:\/\/cyberscoop.com\/project-glasswing-anthropic-ai-open-source-software-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">rolled out in April<\/a>, while Microsoft\u2019s MDASH and <a href=\"https:\/\/cyberscoop.com\/openai-daybreak-gpt-5-5-anthropic-mythos-cybersecurity\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI\u2019s Daybreak<\/a> were both unveiled in May.<\/p>\n<p>The upward trend in Microsoft\u2019s monthly <a href=\"https:\/\/cyberscoop.com\/tag\/patch-tuesday\/\" rel=\"nofollow noopener\" target=\"_blank\">Patch Tuesday<\/a> indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company\u2019s July security update contained an <a href=\"https:\/\/cyberscoop.com\/microsoft-patch-tuesday-july-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">all-time-record of 622 vulnerabilities<\/a>, besting the previous record-breaking <a href=\"https:\/\/cyberscoop.com\/microsoft-patch-tuesday-june-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">June update with 206 vulnerabilities<\/a>.<\/p>\n<p><a href=\"https:\/\/cyberscoop.com\/tag\/vulncheck\/\" rel=\"nofollow noopener\" target=\"_blank\">VulnCheck<\/a>\u2019s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.<\/p>\n<p>The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products \u2014 an emerging attack surface \u2014 at almost 6%.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1785253211_658_MattKapko.jpg\" alt=\"Matt Kapko\"\/><\/p>\n<p>\n\t\t\tWritten by Matt Kapko<br \/>\n\t\t\tMatt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"AI systems like Anthropic\u2019s Project Glasswing and Microsoft\u2019s MDASH are aiding in the discovery of vulnerabilities, filling the&hellip;\n","protected":false},"author":2,"featured_media":121588,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,53,25,111,22959,530,61497,320,157,23294,338,61498,318],"class_list":["post-121587","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-anthropic","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-daybreak","tag-exploit","tag-known-exploited-vulnerabilities-kev","tag-microsoft","tag-openai","tag-patch-tuesday","tag-project-glasswing","tag-vulncheck","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=121587"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121587\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/121588"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=121587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=121587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=121587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}