Observed Signal · Aug 3, 2026 · Research Report · Source: t3n · Impact: 2/5 · Sentiment: Neutral

Only 1% of AI-found Vulnerabilities Were Exploited

Executive Signal Summary

Security researchers analyzing AI-assisted vulnerability reports found that only a very small share of flaws discovered by AI were actively exploited. Vuln Check examined 1,061 AI-related reports using datasets that included cybersecurity reports referencing Anthropic and data from the Berkeley Vulnerability Research Initiative. Of those reports, only 14 vulnerabilities showed evidence of active exploitation. The researchers note that AI increases the number of discovered vulnerabilities and can help defenders find and fix issues, but the time between disclosure and exploitation has shortened—from about 120 days in 2025 to 80 days in the first half of 2026—so defenders must remain vigilant as the technology and threat dynamics evolve.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Study quantifies AI-driven vulnerability discovery and exploitation rates; relevant to security posture but not an industry-shifting platform change.

SIGNAL RADAR

Track Anthropic Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Vuln Check analyzed 1,061 AI-related vulnerability reports.
  • Only 14 of the more than 1,000 reported vulnerabilities showed evidence of active exploitation.
  • Datasets included reports mentioning Anthropic and records from the Berkeley Vulnerability Research Initiative.
  • Time from public disclosure to exploitation shortened from ~120 days in 2025 to ~80 days in H1 2026.
  • GitHub made changes to its bug-bounty program in response to increased AI-generated vulnerability reports.

Connected Companies & Entities

6 Entities mapped

“The data go back to April 2026, when Anthropic announced Project Glasswing....”

“This has already led, among other things, to GitHub making changes to its bug-bounty program....”

“The article was published by the German technology publisher t3n....”

“The page notes external content from Podigee GmbH that complements the editorial offering on t3n.de....”

“The page notes external content from TargetVideo GmbH that complements the editorial offering on t3n.de....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Aug 3, 2026
Original Coverage Title: “Sicherheitsexperten zeigen: Nur ein Prozent der durch KI aufgedeckten Schwachstellen wurde wirklich ausgenutzt”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

AI & CybersecuritySep 30, 2026

Google Report: AI Doubles Software Vulnerability Disclosures

Google's Threat Intelligence Group reports that the number of disclosed software vulnerabilities has doubled within months, rising from 5,045 in January 2026 to 10,740 by August 2026. The report attributes this surge to the increasing use of AI agents in security research, which uncover different types of flaws than traditional scanners. Notably, 50% of AI-found vulnerabilities lead to remote code execution, compared to 26% for conventionally discovered ones. The report also highlights a rise in exploitation of known 'N-day' vulnerabilities, from 28 in all of 2025 to 75 between January and August 2026, likely accelerated by AI-assisted exploit creation. Additionally, vulnerabilities in AI infrastructure itself are growing, with over 1,500 reports in 2026, focusing on orchestration frameworks like Langflow and inference servers such as vLLM and Ollama. The report advises prioritizing patches based on threat intelligence and recommends AI-powered code reviews for software vendors.

Read assessment
API SecurityFeb 18, 2026

APIs: The Most Vulnerable Attack Surface Exposed

Wallarm published the 2026 API ThreatStats Report, analysing 2025 API attack telemetry, published vulnerabilities, confirmed exploitation, and disclosed API-related breaches. Wallarm examined 67,058 published 2025 vulnerabilities and found 11,053 (17%) were API-related; CISA KEV additions in 2025 were 43% API-related. The report identified 2,185 AI-related vulnerabilities with 786 (36%) overlapping APIs, and found AI-platforms/tooling accounted for 15% of API-related breaches in 2025. Model Context Protocol (MCP) emerged as a fast-growing API/AI control-plane risk (315 MCP-related vulnerabilities; 14% of AI vulns; 270% growth Q2→Q3). Wallarm reports that most API vulnerabilities are trivial and remote to exploit (97% exploitable with a single request; 98% easy/trivial; 99% remotely exploitable; 59% require no authentication). The analysis emphasises repeatable identity, access-control and exposure failures driving large-scale automated exploitation.

Read assessment
InfrastructureJul 17, 2026

AI and Patch Tuesday Reveal New Security Risks

A July 14 Patch Tuesday from Microsoft delivered a record volume of fixes (~570 CVEs), including two zero-days actively exploited before patches (CVE-2026-56155 and CVE-2026-56164). The article explains triage steps and stresses cross-checking CISA's KEV list. It also highlights emergent attack surfaces from agentic coding tools: Wiz's GhostApproval and the AI Now Institute's Friendly Fire demonstrate how coding agents can be tricked into writing to sensitive paths or executing injected repo code. Separately, China's NVD flagged multiple Anthropic Claude Code releases for suspicious telemetry; Anthropic says anti-distillation logic was removed in a later build. Finally, an NSA-led advisory (AA26-194A) warns that Russian-linked actors continue to exploit known, already-patched device CVEs and bad configurations, underscoring that rapid patching, least privilege, egress visibility, and secure configuration remain critical defenses.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.