Seems AI Powered Vulnerability Discovery Is Over Hyped
As Is Tradition
Anthropic would have you believe that the power of Claude Mythos and Project Glasswing have to detect unpatched vulnerabilities is so great that it should never be made publicly available. They have suggested that doom would follow as nefarious programmers would take advantage of the fertile new field of vulnerabilities. Well, those that were given access to the closed Mythos model and Project Glasswing have been finding vulnerabilities, but not ones which are realistically exploitable.
VulnCheck and the Berkeley Vulnerability Research Initiative took a look at 1,061 publicly attributed AI-assisted vulnerability discoveries, as in vulnerabilities that have been made publicly available, and a whopping 14 vulnerabilities have been confirmed as exploited in the wild. That monstrous 1.3% is essentially the exact same percentage of active exploits as boring old human discovered vulnerabilities. It seems that while Project Glasswing can find these vulnerabilities faster than a human it’s no more effective than we are.
That’s not to say there is no danger in AI powered vulnerability testing, as OpenAI and Hugging Face found out. There are more details on what happened in that specific example below.
The result: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset.
More Tech News From Around The Web
- We now have a better understanding how OpenAI hacked into Hugging Face @ Ars Technica
- Hugging Face rebuilt a third of its infrastructure after OpenAI agents ran amok @ The Register
- GrapheneOS Defends Data-Wiping Function That Blocked US Border Search @ Slashdot
- Apple Retires iPhone Upgrade Program For Klarna-Backed Leases @ Slashdot
- Omada Fusion Gateway 2.5G Ecosystem and Software @ ServeTheHome
- Thingino Teaches Cheap IP Cameras New Tricks @ Hackaday


