A VulnCheck study has shown that using artificial intelligence to find software bugs has not led to an increase in cyberattack effectiveness: vulnerabilities discovered by AI are exploited in only 1.3% of cases, which is comparable to traditional methods.

image

What happened

According to VulnCheck data, the probability of successfully exploiting vulnerabilities found using AI is only 1.3%. This is also supported by the results of the Anthropic Glasswing project, which identified more than 23,000 potential vulnerability candidates, of which only one turned out to be actually exploitable.

Context

Amid the marketing hype surrounding the concept of AI-driven exploits, there is an opinion about an imminent 'cyber apocalypse' due to the automation of hacking. However, current AI technologies act more as a tool for scaling search (volume up), increasing the number of findings, but not increasing their qualitative level or the probability of a successful breach (quality/exploitability up).

Why it matters for the industry

For the cybersecurity industry, this means a shift in focus from fighting automated attacks to developing tools for filtering and verifying massive amounts of data. There is growing demand for automated analysis (triage) systems and reducing the number of false positives, as well as for protecting the AI stack infrastructure itself.

Why it matters for users

For regular users and readers, this is a signal that the panic surrounding 'instant hacking of everything and everyone' by AI is not yet supported by real numbers. Automating bug discovery does not mean automatic automation of their exploitation, which gives defenders a temporary advantage in response speed.

What remains unknown / limitations

The paradigm may change if automatic exploit generation methods make a qualitative leap comparable to the current quality of vulnerability discovery.

Sources

Author

Look at AI, Editorial Team