TechTarget·4 min read·hard

Glasswing results put AI 'vulnpocalypse' to the test

B
Ben Lutkevich
Glasswing results put AI 'vulnpocalypse' to the test
✦AI Summary

Research into Anthropic's AI-assisted vulnerability discovery tool, Project Glasswing, suggests that AI-found security flaws are rarely exploited in the wild. Experts argue that the 'vulnpocalypse' fear was overstated, highlighting a bottleneck in human triage for patching.

Why it matters

Understanding the real-world impact of AI in cybersecurity helps organizations prioritize resources and manage the actual risks posed by automated vulnerability discovery.

✦Dive DeeperCreate a free account to unlock

When Anthropic introduced Project Glasswing in April, the tech industry braced for impact. Five months in, DevSecOps teams are wading through the glut of discoveries to find out what's worth patching – and so far, it isn't much, according to one cybersecurity researcher.

Anthropic updated its Vulnerability Disclosure ledger for the first time in August. A small percentage of initial Mythos vulnerability findings made it into the ledger, and fewer than 1% of the vulnerabilities Mythos found were marked as fixed, according to Patrick Garrity, a security researcher at vulnerability prioritization tool maker Vulncheck.

Garrity and Vulncheck have also been tracking whether vulnerabilities discovered with AI are actually exploited in the wild. This research combined vulnerabilities attributed to Anthropic's model with data from the Berkeley Vulnerability Research Initiative and correlated them with Vulncheck's known-exploited vulnerability data.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyai
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in