by

Anthropic’s bug doom has not happened

Project Glasswing may have identified tens of thousands of potential security flaws in its AI, but the robot locust swarm has yet to arrive.

New research from VulnCheck suggests AI-assisted vulnerability discovery is not producing the wave of real-world attacks many doom merchants expected.

VulnCheck analysed 1,061 publicly attributed AI-assisted discoveries from Anthropic’s Project Glasswing and the Berkeley Vulnerability Research Initiative.

It then cross-referenced the lot against its Known Exploited Vulnerability database. The result was 14 vulnerabilities confirmed as exploited in the wild, or 1.3 per cent. That is almost identical to the exploitation rate across all vulnerabilities in VulnCheck’s dataset.

The finding is awkward for the idea that frontier AI is dramatically handing attackers instantly weaponisable bugs. Instead, the data suggests AI is better at increasing the number of flaws researchers can find than making them more attractive to crooks.

The report gives Anthropic’s much-hyped Project Glasswing a sharp prod in the ribs.

Anthropic unveiled Glasswing in April with warnings that AI-assisted vulnerability discovery could help attackers hijack systems, disrupt operations or steal data.

Claude Mythos may have identified 23,019 vulnerability candidates. Yet VulnCheck says only 126 have been published as CVEs, just one has been confirmed exploited in the wild and Anthropic’s disclosure ledger has not exactly been sprinting.

VulnCheck security researcher Patrick Garrity said: “AI-assisted vulnerability discovery clearly has value for both attackers and defenders. The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods.”

In other words, the machine is finding more holes, but it has not magically turned every script kiddie into a hoodie-wearing cyber warlord.

Garrity did not claim the risk had vanishedbut he did say the sales-pitch fog has raced ahead of the evidence.

“The data so far, including Anthropic’s own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today,” Garrity said.

 

 

TOPICS:
ai security  ·  anthropic  ·  claude mythos  ·  CVE  ·  cybersecurity  ·  exploited vulnerabilities  ·  Project Glasswing  ·  VulnCheck  ·  vulnerability discovery

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews