< Back to all clusters
[TECHNOLOGY] · 10 sources

AI-driven cyber threats see rise in exploitation despite low success rates

A study of AI‑discovered software flaws found that out of 1,061 vulnerabilities identified in the first half of 2026, only 14 (about 1.3%) were confirmed to be exploited, a rate similar to overall vulnerability exploitation. The median time from disclosure to first confirmed exploit fell to 80 days, down from 120 days the previous year, and roughly 23% were exploited on or before disclosure. Anthropic’s Project Glasswing contributed more than 23,000 findings, resulting in 126 published entries and a single confirmed attack. Content‑management systems accounted for the largest share of hits.

At the same time, AI is increasingly being used as both a weapon and a high‑value target. CrowdStrike’s Threat Hunting Report recorded an 89% surge in AI‑enabled attacks in 2025, with adversary groups leveraging AI throughout the attack chain and targeting AI infrastructure itself. Notable campaigns included credential theft to access frontier‑model APIs and “cost‑harvesting” attacks that inflate victims’ AI usage bills. A North Korean crew linked to the Lazarus Group, dubbed “Famous Chollima,” demonstrated the most advanced AI usage, creating fake companies, AI‑generated websites, and supply‑chain compromises that ranked as the second most common MITRE ATT&CK technique.

Entities: Adam Meyers · Anthropic · CrowdStrike · Famous Chollima · Lazarus Group