CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AI-assisted security tools are finding more bugs, but the threat level has not changed

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3369

As cited

Copy frozen at (site build).

vulnerabilities

AI-assisted security tools are finding more bugs, but the threat level has not changed

AI-assisted vulnerability discovery tools like Project Glasswing and Microsoft's MDASH identified over 1,000 vulnerabilities in the first half of 2026, but VulnCheck data shows these AI-discovered flaws are exploited at rates (1.3%) matching those of traditionally discovered vulnerabilities. However, the full impact remains uncertain because the major AI models only launched in April and May, and the volume of disclosed vulnerabilities is accelerating significantly, with Microsoft's July Patch Tuesday reaching a record 622 flaws.

Why it matters: Defenders and tool vendors should monitor whether AI-discovered vulnerabilities become disproportionately targeted as exploit attacks accelerate; content management systems, network edge devices, and AI products themselves are the most exploited categories, and time-to-exploitation is shrinking to an average of 80 days.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

AI-assisted security tools are finding more bugs, but the threat level has not changed

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

AI-assisted security tools are finding more bugs, but the threat level has not changed

Artificial intelligence (AI)-assisted vulnerability discovery tools like Anthropic's Project Glasswing and Microsoft's MDASH identified 1,061 vulnerabilities in the first half of 2026, but VulnCheck found that only 1.3% of AI-discovered vulnerabilities were exploited in the wild, matching the exploitation rate for all disclosed vulnerabilities. Exploitation timelines have accelerated to an average of 80 days from CVE publication compared to 120 days in 2025, with content management systems representing nearly one-third of actively exploited vulnerabilities. Microsoft's July Patch Tuesday brought a record 622 vulnerabilities, suggesting AI discovery may dramatically increase the volume of disclosed flaws in coming months.

Why it matters: Defenders managing vulnerability prioritization should track that AI-discovered flaws currently show no elevated exploitation risk relative to traditionally found vulnerabilities, though the accelerating pace from discovery to weaponization and the rising volume of disclosures will demand faster patching cycles.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

AI-assisted security tools are finding more bugs, but the threat level has not changed

Artificial intelligence (AI)-assisted vulnerability discovery tools like Anthropic's Project Glasswing and Microsoft's MDASH identified 1,061 vulnerabilities in the first half of 2026, but VulnCheck found that only 1.3% of AI-discovered vulnerabilities were exploited in the wild, matching the exploitation rate for all disclosed vulnerabilities. Exploitation timelines have accelerated to an average of 80 days from CVE publication compared to 120 days in 2025, with content management systems representing nearly one-third of actively exploited vulnerabilities. Microsoft's July Patch Tuesday brought a record 622 vulnerabilities, suggesting AI discovery may dramatically increase the volume of disclosed flaws in coming months.

Why it matters: Defenders managing vulnerability prioritization should track that AI-discovered flaws currently show no elevated exploitation risk relative to traditionally found vulnerabilities, though the accelerating pace from discovery to weaponization and the rising volume of disclosures will demand faster patching cycles.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary