Ad
Skip to content
Read full article about: AI finds plenty of security flaws, but almost none of them get exploited

VulnCheck counted how often the security flaws that AI turns up are ever used in an attack. For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen showed confirmed exploitation. That's 1.3%, roughly the same rate as vulnerabilities overall. Anthropic's Project Glasswing produced more than 23,000 findings, which led to 126 published entries and a single confirmed attack.

Attacks are landing faster, though. Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 200 were attacked within a month, even as the total number of reported vulnerabilities keeps climbing.

Time from vulnerability disclosure to first confirmed exploit in the first half of 2026. About 23 percent were exploited on or before the day of disclosure, and the median dropped from 120 to 80 days. | Image: VulnCheck

Website content management systems take the most hits, accounting for a third of all cases. Garrity flags AI products themselves as a growing attack surface, including model-building tools and agent interfaces. The sheer volume of findings, in other words, tells defenders very little about actual risk.

Read full article about: Sorry for the outages: Bot spam is pushing our servers to the limit

Since May 17, our site has been hard to reach, and we want to say sorry for the trouble, especially to our subscribers. The cause is a heavy wave of bots crawling our pages and pushing our servers to their limit. Over the weekend, the database connection dropped several times, which led our hosting provider to block a user agent. That cut down the spam, but it also locked some of you out of the site.

We are working at full speed on a lasting fix and would welcome help from anyone in the community with the right know-how. Since the bot spam is so severe, with Perplexity in particular on our radar, we may have to put up with further outages until things are stable again.

Read full article about: Happy holidays from our team and here's to another year of making sense of AI

Hey everyone,

2025 is wrapping up, and we wanted to say thanks. This year, we published over 1,700 articles and 50 newsletters. We hope some of them were useful to you.

With our relaunch done, we're looking forward to 2026—staying on top of things and digging deeper where it matters.

If you have ideas or feedback, we'd love to hear from you: hello@the-decoder.com

And if you want to support our work, a subscription helps a lot.

Thanks for reading. Happy holidays! 🎄

Matthias, Max & Jonathan

Nano Banana Pro prompted by THE DECODER

Some notes on what's new

Hey guys, you’ve probably noticed we’ve changed a thing or two about this website. If you don’t like it yet, give it a chance, it might grow on you.

Two things are important: First, a stronger focus to let you just scroll through the main feed and still grasp the most relevant information. Second, with that comes a return to more blog-style publishing overall. We’ve also added a system we call “Context on Demand”.

Read full article about: Optics AI or Not is free and can detect AI-generated images and audio

"AI or Not" is able to detect AI-generated images and audio with 95 percent accuracy, according to developer Optic. Based on a proprietary algorithm, AI or Not can identify images from Midjourney, Stable Diffusion, DALL-E or even classic GANs as AI-generated. Uploaded images are not kept longer than necessary for analysis, according to Optic. However, the team is collecting feedback on the algorithm's performance - presumably to improve it further. In addition to images, the service can also recognize AI-generated music and other audio snippets. AI or Not for images and audio is free for small amounts of images. The company also offers an API that can be used to analyze larger data sets.