AI Pulse by Inblix

AI found 23,000 bugs; attackers used 1. That's the real vulnerability story

The Decoder · Aug 2, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: AI found 23,000 bugs; attackers used 1. That's the real vulnerability story

Here’s a number that should reset the conversation around AI and cybersecurity: 23,000. That’s how many findings Anthropic’s Project Glasswing churned out. And the number of those that led to a confirmed real-world attack? One. Just one.

VulnCheck’s Patrick Garrity ran the data for the first half of 2026 and found 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen were ever exploited. That 1.3% exploitation rate is dead average — almost exactly what you’d see across all reported vulnerabilities, AI-discovered or not. So the machines are incredibly loud, and not necessarily more relevant.

The speed of attacks is what’s actually changed. The window between public disclosure and first confirmed exploitation has collapsed from 120 days to just 80 days year-over-year. Roughly 200 flaws got hit within a month of disclosure. Attackers aren’t waiting around, even if they’re ignoring the vast majority of what AI finds. The volume of noise is going up while the signal stays flat.

What should actually worry defenders? Garrity points to AI products themselves — model-building tools, agent interfaces — as a growing attack surface that nobody has a good handle on yet. Web CMS platforms still account for a third of all exploited cases, but the infrastructure we’re building to run AI is becoming the soft underbelly. The takeaway from VulnCheck’s data isn’t that AI is bad at finding vulnerabilities. It’s that counting findings is a terrible way to measure risk. Most of what these systems surface will never matter. The trick now is figuring out which 1.3% will.

💡 Key Takeaways

  1. Anthropic's Project Glasswing produced over 23,000 security findings that led to only one confirmed real-world attack, matching the overall 1.3% exploitation rate for all vulnerabilities
  2. The time from vulnerability disclosure to first exploitation dropped from 120 days to 80 days, with about 200 flaws attacked within a month of going public
  3. AI tools and agent interfaces are emerging as an unmanaged attack surface while website CMS platforms still account for a third of all exploited vulnerabilities
  4. The sheer volume of AI-generated findings tells defenders almost nothing about actual risk, making prioritization the real challenge

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles