Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

AI-found bugs aren't proving any easier to exploit despite the hype

⁨28⁩ ⁨likes⁩

Submitted ⁨⁨3⁩ ⁨weeks⁩ ago⁩ by ⁨supersquirrel@sopuli.xyz⁩ to ⁨technology@lemmy.zip⁩

https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving-any-easier-to-exploit-despite-the-hype/5279637

source

Comments

Sort:hotnewtop
  • Multiplexer@discuss.tchncs.de ⁨3⁩ ⁨weeks⁩ ago

    Some good news today, at last.

    Although one might want to insert the WWII airplane hit distribution picture here, especially with regard to exploits used by governments, as those are not part of the disclosed sets and targeted attacks are also in general much less likely to show up using simple attack monitoring.

    source
    • 01189998819991197253@infosec.pub ⁨3⁩ ⁨weeks⁩ ago

      This one?

      Image

      source
      • Mikina@programming.dev ⁨3⁩ ⁨weeks⁩ ago

        In this case, it’s more like this.

        Image

        source
  • chicken@lemmy.dbzer0.com ⁨3⁩ ⁨weeks⁩ ago

    Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit.

    Makes sense, if AI can find an exploit, then everyone is going to know about it pretty soon.

    source
  • BussyGyatt@feddit.org ⁨3⁩ ⁨weeks⁩ ago

    Huh? The claim is that it will find volumes more vulnerabilities than a human with the same amount of time, not that the vulnerabilities it finds will be somehow more exploitable? big “I knew we had lost the war when the generals’ reports of glorious victories came nearer and nearer the capital” energy. And really, since AI produces so many false positives (hallucinations) we really ought to expect a lower-than-competent-human rate of finding exploits. The real question is “can we patch vulnerabilities faster than ai can find them?” and the answer, for now, is apparently yes.

    source