Overview
Artificial intelligence is changing vulnerability research at a pace that is difficult for traditional security processes to match. Anthropic says its Project Glasswing initiative identified at least 129,000 verified software vulnerabilities between April and July 2026, with more than 33,000 classified as critical or high severity. The company has now expanded its Cyber Verification Program (CVP), providing vetted cybersecurity organisations with different levels of access to advanced AI models for defensive research, penetration testing and specialised security testing. The development represents an important shift in the cybersecurity landscape. AI is no longer simply helping security researchers write scripts or analyse logs. It is increasingly capable of discovering relationships between weaknesses, validating vulnerabilities and accelerating the research process itself.
AI Is Increasing the Volume of Discovery
Traditional vulnerability research can require significant specialist knowledge and considerable time. AI can change that equation by examining large amounts of source code, identifying suspicious patterns and connecting weaknesses across different parts of an application. Anthropic says Project Glasswing and its open-source scanning efforts identified more than 134,000 verified vulnerabilities during the periods covered by its reporting. But volume alone does not equal risk. VulnCheck’s analysis of 300 vulnerabilities attributed to Anthropic or Project Glasswing found that only two had been exploited in the wild. That represents approximately 0.67% of the vulnerabilities examined. This distinction is critical. AI may dramatically increase the number of vulnerabilities that can be discovered, but organisations still need to determine which weaknesses are reachable, exploitable, exposed and capable of producing meaningful business impact.
The Defensive Advantage Comes With a Dual-Use Problem
Anthropic’s Cyber Verification Program recognises the dual-use nature of advanced cyber capabilities. Its different access tiers provide progressively broader capabilities, from defensive vulnerability analysis to authorised red-team activity and specialised safety testing. This creates an unusual security dilemma. The same capability that allows a defender to identify an overlooked vulnerability can potentially reduce the effort required for an attacker to discover and exploit the same weakness. Security organisations therefore have to consider not only what an AI system can discover, but also how that capability is governed and who is authorised to use it. The expansion of controlled access is consequently as much a governance development as a technical one.
More Vulnerabilities Require Better Prioritisation
The emergence of AI-assisted vulnerability discovery could overwhelm traditional remediation processes if every finding is treated equally. A security programme receiving thousands of additional findings cannot simply create thousands of additional patching tickets. Context becomes more important: internet exposure, authentication requirements, exploitability, privilege requirements, sensitive data access and the vulnerability’s position within an attack path all influence the actual risk. The focus therefore needs to move from vulnerability counting to exposure management. An AI-generated finding should be treated as an input into a validation and prioritisation process rather than an automatic declaration of compromise or critical business risk.
AI Can Also Create New Vulnerabilities
There is another side to the equation. The same technology being used to identify security weaknesses is increasingly being used to generate software. The supplied research cites findings from Veracode indicating that approximately 44% of tested AI code-generation tasks introduced a risky security vulnerability, while the average security pass rate remained around 56%. That creates a potentially dangerous feedback loop: AI can find vulnerabilities faster while simultaneously increasing the volume of AI-generated code that requires security validation. Automated development therefore cannot be separated from automated security assurance.
Expert in the Cloud Insight
AI is changing the economics of cybersecurity. Finding vulnerabilities may become considerably faster and cheaper, but validating their significance, understanding their attack paths and safely remediating them remain engineering and governance challenges. The organisations best positioned to benefit from AI-assisted security will not necessarily be those generating the largest number of findings. They will be those capable of turning those findings into validated risk reduction. AI may make vulnerability discovery abundant; the real competitive advantage will be knowing which vulnerabilities actually matter.
Leave a Reply