Cyber Apocalypse Overblown? Study Shows AI-Found Vulnerabilities Are Rarely Exploited

New research from VulnCheck suggests AI-assisted vulnerability discovery is not yet driving a surge in real-world cyberattacks, challenging fears sparked by frontier models such as Anthropic's Mythos

4
Cyber Apocalypse Overblown? Study Shows AI-Found Vulnerabilities Are Rarely Exploited
Security, Compliance & RiskNews

Published: July 29, 2026

Kristian McCann

New research from VulnCheck is casting doubt on the impending AI cyber onslaught by examining whether vulnerabilities identified with AI are translating into a greater number of real-world attacks.

The analysis includes findings tied to Anthropic’s Project Glasswing and suggests the impact of AI-led vulnerability discovery may, so far, be more limited than early fears surrounding frontier models such as Mythos indicated.

That does not mean the security implications have disappeared. AI is helping researchers identify weaknesses at a much greater scale, but the latest data places renewed emphasis on a key distinction for organizations: whether a newly identified flaw can actually be exploited to cause meaningful impact.

How VulnCheck Assessed the Findings

VulnCheck built its analysis using publicly attributed AI-assisted disclosures connected to Anthropic’s Project Glasswing and the Berkeley Vulnerability Research Initiative.

The company then cross-referenced the identified vulnerabilities against its Known Exploited Vulnerability database, which tracks flaws with evidence of active exploitation. This allowed researchers to assess whether AI-assisted discoveries were appearing in attacker activity at a materially different rate than vulnerabilities identified through other approaches.

The review covered 1,061 vulnerability discoveries. Fourteen appeared in VulnCheck’s exploited vulnerability records, resulting in a 1.3% confirmed exploitation rate.

VulnCheck also assessed the publicly available disclosure trail associated with Project Glasswing. Anthropic has reported 23,019 vulnerability candidates, although only 126 had been published as CVEs at the time of the analysis. One of those CVEs had been confirmed as exploited in the wild.

Mythos Raised the Stakes for AI Security Testing, but Was It Overblown?

The arrival of Mythos intensified a broader security debate over how AI could alter the balance between attackers and defenders. Companies were already preparing for AI systems to support phishing, malware development, and reconnaissance, but automated vulnerability discovery introduced a more direct concern: AI could be used to probe systems continuously for overlooked weaknesses.

That concern was heightened by Anthropic’s reporting that early participants had uncovered hundreds of vulnerabilities, including issues that had remained undetected for years. The prospect of models systematically examining code and infrastructure for hidden defects created fresh urgency for organizations with large software estates, legacy environments, and limited security testing capacity.

As a result, interest surged around Anthropic’s Mythos and its slightly diluted model, Fable 5, as companies sought to use AI to analyze vulnerabilities across their digital estates before attackers did.

This momentum also prompted Google and Microsoft to release their own vulnerability-focused AI capabilities this month, placing greater emphasis on making security testing less expensive and more frequent. The commercial logic is clear: if AI can reduce the cost of identifying weaknesses, security teams may be able to test more systems more often rather than relying on periodic assessments.

Yet VulnCheck’s research introduces an important qualification. Finding a vulnerability is not the same as demonstrating that it can be exploited in a way that creates meaningful business impact. If a large proportion of AI-discovered issues are difficult to weaponize, require unusual conditions, or have limited practical value, the immediate threat may be less dramatic than the warnings that accompanied Mythos.

That distinction matters for security leaders. High volumes of findings can still create pressure for already stretched teams, particularly if organizations lack a reliable way to prioritize what deserves urgent attention. The challenge is increasingly likely to be separating weaknesses that represent theoretical exposure from those that can enable a realistic attack path.

AI Changes the Workflow, not the Fundamentals

VulnCheck is careful to note that its findings do not diminish the value of AI-assisted vulnerability research. The data suggests AI is helping researchers increase the volume of vulnerabilities they can identify, which remains highly valuable for defenders, provided they can validate and remediate the most consequential findings quickly.

However, the findings do suggest that AI-discovered flaws do not currently appear to be inherently more likely to be exploited than those identified through traditional methods. Attackers, meanwhile, continue to rely heavily on well-established targets. VulnCheck identified 495 known exploited vulnerabilities in the first half of 2026, with content management systems accounting for around one-third of the total. Network edge devices also remained a frequent target, reflecting the enduring value of exposed and widely deployed infrastructure.

AI platforms themselves are becoming part of that attack surface. As businesses deploy more AI applications, agents, integrations, and model-serving infrastructure, adversaries have new systems to target. The security question is therefore expanding beyond whether criminals can use AI to find vulnerabilities to whether the rapidly growing AI software stack is being built and maintained securely.

For organizations, the near-term priority is unlikely to be treating every AI-found vulnerability as an emergency. Instead, security teams need to assess exploitability, understand how weaknesses may be chained together, and validate whether remediation has reduced genuine exposure.

Project Glasswing and the wider Mythos debate have shown that AI can materially accelerate security research. The evidence so far, however, indicates that these findings have not produced the surge in real-world exploitation that many feared.

Agentic AIGenerative AIGenerative AI Security​Security and Compliance
Featured

Share This Post