Fewer than 0.5 per cent of the vulnerabilities linked to Anthropic or Project Glasswing are being exploited in the wild, according to VulnCheck researcher Patrick Garrity, who tracked 225 flaws found by Glasswing and found just one with confirmed exploitation. The finding cuts against the working assumption that AI-assisted bug discovery will translate directly into a larger exploited-vulnerability base — the CVEs are real and the volume is climbing, but the population that attackers bother with is a rounding error against it, and the likely reason is that the vulnerabilities AI tooling surfaces skew toward the complex and the hard-to-reach rather than toward the exposed, trivially triggerable classes that opportunistic actors actually use. It is a useful counterweight to the week's other AI-security results, which concern agent sandboxing and credential handling rather than newly disclosed flaws, and it argues that defenders should prioritise on exploitability evidence rather than on the provenance of the find. The caveat is the observation window: a near-zero exploitation rate over a short period says something about attacker behaviour so far, not about the eventual risk in a codebase, and the ratio will move if a single high-value flaw in the set acquires a public proof of concept.
| Attribute | Detail |
|---|---|
| Sector | AI & Frontier Technology |
| Date | 2026-09-22 |
| Source | The Register |
| Reliability | Tier 2 |