New research from VulnCheck challenges the idea that AI will trigger a cyber crisis. The company studied whether AI-discovered software flaws are leading to more real-world attacks. Its findings suggest a calmer picture than many security leaders expected.
The study reviewed 1,061 AI-assisted vulnerability discoveries. Only 14 appeared in exploited vulnerability records. That creates a confirmed exploitation rate of 1.3 percent. The data suggests attackers rarely use these AI-found flaws today.
However, the issue still matters for telecom and unified communications teams. Networks now depend on cloud platforms, APIs, edge devices, and collaboration tools. A single weak point can affect voice, messaging, meetings, or customer services.
VulnCheck based its research on public AI-assisted disclosures. These included findings linked to Anthropic Project Glasswing and the Berkeley Vulnerability Research Initiative. Researchers then checked those entries against known exploited vulnerabilities.
Project Glasswing created major interest across the security industry. Anthropic reported 23,019 vulnerability candidates from the initiative. Yet only 126 had become published CVEs during VulnCheck’s analysis. Just one had confirmed exploitation in the wild.
This matters because a discovered flaw does not always create danger. Attackers need a practical path to use it. Some issues require rare conditions. Others may cause limited damage, or need several weaknesses combined together.
The debate grew louder around Mythos, Anthropic’s advanced cybersecurity model. Many experts feared automated discovery would give criminals unlimited scanning power. That concern felt reasonable, especially for large enterprises with old systems.
At the same time, defenders can also use these tools. AI can scan code, review configurations, and highlight hidden risks faster. Security teams may test more often, instead of waiting for periodic reviews.
Microsoft and Google have also introduced vulnerability-focused AI capabilities. Their goal is to reduce the cost of security testing. Smaller models may help enterprises run checks more frequently.
For VoIP providers, UCaaS teams, and carriers, this creates a practical challenge. More findings can help security programs mature. Yet too many alerts can overwhelm engineers and delay urgent fixes.
VulnCheck’s analysis points toward smarter prioritization. Teams should ask whether a flaw can be exploited. They should also check whether it affects exposed systems or critical services.
Attackers still favor familiar targets. VulnCheck found 495 known exploited vulnerabilities in early 2026. Content management systems accounted for about one-third of those cases. Network edge devices also remained frequent targets.
AI platforms now add another layer of risk. Businesses are deploying agents, integrations, and model-serving systems quickly. These tools must follow the same security discipline as other applications.
The message for technology leaders is balanced. AI can accelerate vulnerability research and improve defense. Yet current evidence does not show a sudden wave of AI-driven exploitation.
Security teams should avoid panic. Instead, they should validate findings, rank exposure, and fix what matters most. That approach gives telecom and IT teams a stronger path forward.

