• Sources: The Register, HN 49089211
  • Summary: The Register reports a VulnCheck analysis of 1,061 publicly attributed AI-assisted vulnerability discoveries drawn from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, cross-referenced against VulnCheck's known-exploited-vulnerability database. 14 of the 1,061, or 1.3 percent, are confirmed exploited in the wild. The article separately reports that of 23,019 vulnerability candidates from Claude Mythos, 126 have been published as CVEs and one is confirmed exploited, with little movement in the disclosure record since launch. The analysis was shared with The Register and has no public URL of its own, so the dataset behind the figures cannot be checked here. The scope is those two programs rather than AI-assisted discovery in general.
  • Why it matters: It puts a measured bound on the AI-found-vulnerability wave this digest has tracked since the Redis releases and the 432-CVE kernel batch, and the bound says the change is discovery volume rather than exploitation rate.
  • Follow-up: Watch for VulnCheck publishing the dataset or the methodology under its own URL.

send feedback on this story