Skip to the content
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
LOG IN

Less Than 5% Exploitable: AI-Found Bugs Small Escalation to Cyber Threats

Recent discussions surrounding artificial intelligence have frequently highlighted concerns that automated systems would dramatically alter the cyber threat landscape. A common argument has been that advanced artificial intelligence platforms would uncover tens of thousands of software flaws and convert them into immediate, weaponised cyber attacks. High-profile initiatives, such as Project Glasswing, demonstrated that capabilities like Claude Mythos could identify more than twenty-three thousand candidate flaws across complex software environments.

However, recent empirical data reveals a far more reassuring reality for business executives and technology leaders. Research indicates that although artificial intelligence can surface software flaws at a substantial volume, these discoveries are not proving any easier to exploit than those found using traditional methods. In fact, real-world findings show that less than five percent of artificial intelligence identified bugs are actually being weaponised.

Analysing the Real-World Exploitation Rates

A comprehensive study by vulnerability intelligence firm VulnCheck evaluated over one thousand attributed artificial intelligence security discoveries. The investigation revealed that only fourteen of these candidate vulnerabilities, representing just 1.3%, had actually been exploited in the wild.

This rate is virtually identical to the background exploitation rate observed across all software vulnerabilities in general datasets. Despite predictions that frontier artificial intelligence would tilt the balance sharply in favour of malicious actors, the empirical evidence demonstrates that candidate flaws identified by automated systems are no more likely to be exploited than those discovered by human security researchers.

Consider the outcome of Project Glasswing as a practical example. Although the project surfaced tens of thousands of potential vulnerabilities, only one hundred and twenty-six have been published as common vulnerabilities and exposures, and just a single bug has been confirmed as exploited in the wild.

The Gap Between Flaw Discovery and Weaponisation

The primary impact of artificial intelligence in software analysis is an increase in finding volume rather than exploitation capability. Identifying a potential weakness in source code is merely the first step in a complex process. Developing a reliable, functional exploit from a initial code anomaly requires considerable time, deep expertise, and substantial engineering effort.

For organisation leaders, this distinction offers important operational insights:

  • Increased Finding Volume: Automated tools generate a substantial quantity of candidate findings, which can increase operational noise if security teams lack clear triaging procedures.
  • Consistent Exploitation Timelines: Because turning a flaw into a weaponised exploit remains difficult, defenders retain a crucial window of opportunity to rectify security gaps.
  • Focus on Remediation Prioritisation: The primary challenge for modern organisations is no longer finding potential flaws, but efficiently validating, prioritizing, and applying fixes to high-risk areas.

Current data suggests that artificial intelligence offers significant advantages to defensive teams, giving organisations the opportunity to resolve vulnerabilities long before cyber criminals can weaponise them.

Strategic Cyber Security Actions for Organisations

While the immediate risk of automated cyber attacks may be overhyped relative to the available evidence, maintaining strong defensive practices remains essential. Business leaders can consider several practical measures to enhance their overall security posture and manage software vulnerabilities effectively:

  • Adopt Risk-Based Patching: Rather than attempting to address every automated finding simultaneously, consider implementing a prioritised approach that focuses on verified flaws with confirmed exploit activity or available proof of concept code.
  • Engage Expert Penetration Testers: Automated analysis frequently identifies theoretical risks. Utilizing skilled penetration testing professionals allows organisations to validate which weaknesses pose actual operational risk to their environments.
  • Maintain Regular System Updates: Establishing disciplined update schedules across software, operating systems, and third-party tools helps close potential security gaps before malicious actors can attempt exploitation.
  • Enhance System Monitoring: Implementing continuous log monitoring and security management helps detect anomalous activity early, ensuring swift response if an exploitation attempt occurs.

How Vertex Can Support Your Organisation

Understanding emerging technologies like artificial intelligence and their impact on cyber security requires practical expertise and clear guidance. At Vertex, we are dedicated to providing clear, effective security solutions tailored to your operational requirements. Our team of expert penetration testers and security professionals can assist your organisation in evaluating system risks, validating potential flaws, and implementing practical defensive controls.

Whether you require a technical audit, manual penetration testing, or comprehensive security management, Vertex is here to assist in building a resilient digital environment.

To discuss how our team can support your organisation, please contact the expert team at Vertex today or visit the Vertex Cyber Security website.

CATEGORIES

AI - Vulnerability

TAGS

AI discovered bugs - artificial intelligence cyber threats - Project Glasswing - Software Security - vulnerability exploitation

SHARE

SUBSCRIBE

PrevPreviousThe Anthropic $1.5 Billion Settlement: Should Artificial Intelligence Supply Chains Face Ethical Regulations?
NextThe 200 Percent Breach Surge: How Artificial Intelligence Is Automating Cyber Attacks Across Every BusinessNext

Follow Us!

Facebook Twitter Linkedin Instagram
Cyber Security by Vertex, Sydney Australia

Your partner in Cyber Security.

Terms of Use | Privacy Policy

Accreditations & Certifications

iso27001-certified
blank
iso277001-certified
blank
blank
blank
  • 1300 229 237
  • Suite 10 30 Atchison Street St Leonards NSW 2065
  • 477 Pitt Street Sydney NSW 2000
  • 121 King St, Melbourne VIC 3000
  • Lot Fourteen, North Terrace, Adelaide SA 5000
  • Level 2/315 Brunswick St, Fortitude Valley QLD 4006, Adelaide SA 5000

(c) 2026 Vertex Technologies Pty Ltd (ABN: 67 611 787 029). Vertex is a private company (beneficially owned by the Boyd Family Trust).

download (2)
download (4)

We acknowledge Aboriginal and Torres Strait Islander peoples as the traditional custodians of this land and pay our respects to their Ancestors and Elders, past, present and future. We acknowledge and respect the continuing culture of the Cammeraygal people of the Eora nation and their unique cultural and spiritual relationships to the land, waters and seas.

We acknowledge that sovereignty of this land was never ceded. Always was, always will be Aboriginal land.