Research
AI Minute Newsroom
2026-08-03
AI found 1,061 security holes this year. Attackers have used 14 of them.
VulnCheck's half-year exploitation report counted 1,061 vulnerabilities credited to AI-assisted discovery — drawing on datasets including Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative — and found only 14 of them, 1.3%, confirmed exploited in the wild. That is essentially the same rate as flaws found the old-fashioned way. The calmer headline hides a sharper one: across all 495 known exploited vulnerabilities in the first half of 2026, the median gap between a flaw being published and being attacked fell from 120 days in 2025 to 80.
Why it mattersThe fear that AI bug-hunting would hand attackers a ready-made arsenal has not shown up in the data — finding a flaw and weaponising one remain separate jobs, and most discoveries are simply never worth an attacker's time. What did change is the clock. Whoever patches your systems now has about two and a half months after disclosure rather than four, and that shift applies to every vulnerability, whether a machine or a person found it.
✓ Verified · 3 sources
Read in the app — free, in 9 languages
Related stories
A model learned to write without the method that trains every AI.
2026-10-06Mathematicians cracked five open problems using an ordinary chat box.
2026-10-05Untuned models solved agent tasks their polished versions could not.
2026-10-04Pretraining on everyday photos got a model to 70% on a reasoning test.
2026-10-04An AI trained for $8,000 beat Stratego's greatest player.
2026-10-03