{"data":{"id":"1f88f0e3-346f-452d-a85d-f98257f7e07a","title":"AI can find zero-days but still can’t reliably write secure code","summary":"Large language models (LLMs, AI systems trained on massive amounts of text) are getting better at finding zero-day vulnerabilities (previously unknown security flaws) and creating exploits, but they are not improving at writing secure code or creating reliable patches for those vulnerabilities. Studies show that AI-generated code contains security flaws at roughly double the rate of human-written code, with 44% of AI code containing at least one known OWASP Top 10 vulnerability (a list of the most dangerous code weaknesses), yet AI still produces syntax-correct code 99% of the time, raising questions about why AI excels at some security tasks but fails at others.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://www.csoonline.com/article/4210735/ai-can-find-zero-days-but-still-cant-reliably-write-secure-code.html","publishedAt":"2026-08-18T08:25:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI"],"affectedVendorsRaw":["Anthropic","OpenAI","Veracode","Software Improvement Group","Xint.io","Theori","1Password"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-18T08:25:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}