AI-assisted security tools are finding more bugs, but the threat level has not changed

AI-assisted security tools are finding more bugs, but the threat level has not changed
AI-assisted vulnerability discovery from systems like Anthropic’s Project Glasswing and Microsoft’s MDASH produced 1,061 flaws in the first half of 2026, but VulnCheck found they were not more likely to be exploited than other disclosed vulnerabilities. The report also notes that exploitation is happening faster after CVE publication, with content management systems, network edge devices, operating systems, server software, and AI products among the most targeted categories. #ProjectGlasswing #MDASH #Daybreak #VulnCheck #CVE

Keypoints

  • AI tools discovered 1,061 vulnerabilities in the first half of 2026.
  • Only 14 of those AI-discovered flaws were exploited in the wild.
  • VulnCheck found no evidence that AI-discovered vulnerabilities are more likely to be exploited.
  • Exploitation after CVE publication accelerated from 120 days to 80 days.
  • Content management systems were the most frequently exploited technology category.

Read More: https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/