AI finds many software flaws, but hackers exploit few

3dnews.ru (Russian)

Despite fears that advanced AI models finding software vulnerabilities would lead to mass exploitation by cybercriminals, practice has shown otherwise. Less than 0.5% of vulnerabilities found by Anthropic's AI in the Glasswing project were actually used in attacks. Specifically, hackers exploited only one of 225 officially registered CVE vulnerabilities linked to the project, according to researcher Patrick Garrity from VulnCheck. The single exploited flaw was a critical SQL-injection vulnerability in the Ghost platform (CVE-2026-26980), as of Monday, September 21. Garrity noted a big difference between discovering vulnerabilities and their usefulness to attackers. Additionally, research from 1Password's Off-by-1 lab showed AI models fully fixed vulnerabilities in only 26% of cases, often creating new problems instead.


With a significance score of 3.7, this news ranks in the top 8.1% of today's 33088 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: