VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
Fewer than 2% of AI-assisted vulnerability discoveries have been weaponized so far. Also, that we know of.
Though it’s really a script kiddie thing. Any teenager can point an LLM at a codebase and start picking out vulns. Writing an exploit is a level harder. And actually using it offensively in the wild is even harder. So, it makes sense that right now we just see people reporting vulns.
AI-found bugs aren’t proving any easier to exploit despite the hype
Yeah, that’s what the state-sponsored hackers want you to believe…
/s
AI discovering new zero-days isn’t the real issue though.
AI’s ability to seamlessly implement every single known vulnerability is the problem that can attack us at scale.
An AI trained on devices, software versions, and vulnerabilities could literally identify targets just by the hardware. It would passively identify and attack anything with out of date security software.
It’s inevitable and we won’t know it exists until one day some crazy number of the network routers in the world all stop working more or less at the same time.
That sounds plausible but is in direct contradiction to the contents of the article.



