VulnCheck Data Deflates the AI-Bug Panic: 1.3% of AI-Found Vulns Exploited, Identical to the Baseline Rate
The Register reported on 2026-07-28 that VulnCheck analyzed 1,061 AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative and found only 14 — 1.3% — confirmed exploited in the wild, matching the exploitation rate across all vulnerabilities regardless of origin. Project Glasswing alone generated 23,019 vulnerability candidates, of which just 126 became published CVEs and exactly one was confirmed exploited. VulnCheck researcher Patrick Garrity says AI-assisted discovery 'clearly has value for both attackers and defenders' but that AI raises discovery volume, not exploitation likelihood. This is a useful counterweight to the same week's agent-intrusion and Codex Security coverage.
↳ Follow the thread