Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI-assisted vulnerability discovery can produce more findings, but a larger finding count does not tell a security team which assets are exposed or what needs immediate action. Teams need to validate whether a vulnerability is exploitable in their environment, what their controls do about it, and how much the affected asset matters to the business—then use that evidence to guide remediation.

Why more vulnerability findings do not automatically mean more organizational risk

A vulnerability record, evidence of exploitation in the wild, and a confirmed exposure in a particular organization are different things. A CVE count measures published vulnerability records under a given source’s rules; it is not a count of attacks or of reachable, exploitable assets. Likewise, a severity score such as CVSS provides a common baseline, not a complete assessment of impact in a specific environment.

As Sila Ozeren Hacioglu, a Security Research Engineer at Picus Security, put it in her contributed article: “The CVSS gives you a common severity baseline. It can’t give you the context that determines impact to your organization.” That context includes the affected asset, whether an attacker can reach it, its business importance, and which security controls apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This distinction matters more as AI helps surface potential flaws. More candidates can increase the triage burden without establishing that the candidates are valid, exploitable, or equally urgent. The useful question is not simply how many vulnerabilities were found, but which exposures, on which assets, require immediate action.

#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

What recent figures do—and do not—show

Several reports describe vulnerability and exploitation activity in the first half of 2026, but their totals do not match. The figures below use different sources and definitions; they should not be averaged or treated as interchangeable measurements.

Source and date Reported figure What the figure counts
The Hacker News contributed article by Sila Ozeren Hacioglu, September 14, 2026 35,853 CVEs published in H1 2026; 495 catalogued as exploited; 116 reportedly attacked on disclosure day The article’s reported publication, exploited, and disclosure-day attack counts.
Zero Day Clock, accessed October 7, 2026 35,850 vulnerability records published in H1 2026; 487 newly listed as exploited; 137 already listed as exploited by publication day Its dashboard bases counts on CVE publication dates and catalogue listing dates.
VulnCheck, July 28, 2026 495 KEVs; 23.43% of its H1 2026 KEVs showed evidence of exploitation on or before CVE publication VulnCheck’s own KEV dataset and timing measure. Exploitation evidence may emerge after disclosure.

The differences are not resolved by the available reporting. Inclusion rules, evidence sources, and the meaning of “on disclosure day” or “already exploited” may differ. Zero Day Clock also cautions that CVE publication totals and exploited listings are not equivalent series; broader CVE assignment affects publication counts. Treat each number as a source-specific measurement, not as a universal rate of organizational exposure.

VulnCheck also reported that the median time from CVE publication to KEV inclusion fell from 120 days in 2025 to 80 days in H1 2026. These are its reported medians for those periods, not a prediction of how quickly every vulnerability will be recognized as exploited.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

AI-attributed findings are not automatically more dangerous

In its July 28, 2026 analysis, VulnCheck attributed 1,061 vulnerabilities to AI-assisted discovery and reported confirmed in-the-wild exploitation for 14 of them, or 1.3%. VulnCheck said that rate was roughly in line with its overall H1 exploitation rate and cautioned that the evidence does not show AI-discovered vulnerabilities are inherently more likely to be exploited. The practical implication is to assess each finding on evidence and context rather than treating AI attribution as a risk score.

Discovery totals are not the same as validated exposures

Anthropic’s Frontier Red Team dashboard, with a snapshot dated October 2, 2026, reported 29,439 model-found findings, 6,123 externally reviewed, and 5,674 confirmed valid among those externally reviewed. It also reported 6,157 findings disclosed to maintainers and 516 patched upstream.

These counts describe different stages, not a single funnel with equivalent units. Anthropic says disclosed findings are a subset of model-found findings; its stated true-positive rate applies only to manually reviewed findings. A valid finding may be outside a maintainer’s threat model or not typically reachable. The patch count is neither a CVE count nor evidence that fixes have been installed across affected deployments. Candidate totals therefore cannot be read as confirmed exploitable exposures in organizations.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Three forms of validation answer different questions

Hacioglu’s contributed article proposes a three-part validation framework. It is a practical proposal, not an independently established standard. The methods can inform one remediation decision, but every exposure does not require all three.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Exploitability validation: can this vulnerability be exploited here?

This assessment considers whether the vulnerable component and its surrounding conditions make exploitation feasible in the organization’s environment. It can help assess cases where no working public exploit is available and assets where a live exploit attempt would be unsafe. The result should describe the evidence and assumptions—for example, affected version, reachability, configuration, and prerequisites—rather than convert uncertainty into a simple yes or no.

2. Security-control validation: would defenses block or detect an attack?

Testing can examine whether relevant prevention and detection controls block, detect, or miss an attack path. This answers a different question from whether the underlying flaw exists or can be exploited: it concerns the behavior of controls under a defined scenario. Picus describes breach-and-attack simulation as a way to test security controls; that vendor description is not independent evidence of a product’s efficacy.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

3. Authorized penetration testing: can an attacker use the exposure in this environment?

A penetration test can safely exercise real exploits and chain exposures to demonstrate possible movement through a specific, authorized environment. That can produce direct, environment-specific evidence, but a usable exploit may not yet exist, and testing may be inappropriate for production, restricted, business-critical, or air-gapped systems. Picus markets an autonomous penetration-testing product; that product claim should be distinguished from the broader method of authorized penetration testing.

Method Evidence it can provide Important constraint
Exploitability validation Whether the vulnerability appears exploitable under the organization’s conditions, including when a live test is unsuitable. Conclusions depend on available evidence and the accuracy of environment details.
Security-control validation Whether specified controls block, detect, or miss a defined attack scenario. A test result applies to the scenario and controls tested; it is not a blanket assurance about all defenses.
Authorized penetration testing Whether a real exploit or chained path can demonstrate risk in the tested environment. Requires authorization and safety controls; a suitable exploit may not exist, and some assets should not be live-tested.

The comparison describes the kinds of evidence these methods can provide, not measured rankings or guarantees. Choose the method that fits the asset, question, and acceptable risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to turn findings into a remediation decision

  1. Identify the affected asset. Confirm the software, version, configuration, ownership, and business function. A vulnerability in a reachable internet-facing service may warrant a different response from the same flaw on an isolated system.
  2. Establish exposure conditions. Determine whether an attacker can reach the component and whether the reported exploit prerequisites apply. Record what is known, what is assumed, and what remains unverified.
  3. Check exploitation evidence. Use a clearly defined source and date for claims about exploitation in the wild. A catalogue listing is useful evidence, but it does not by itself prove that the asset in question is exploitable or has been attacked.
  4. Select a validation method. Assess exploitability when a live attempt is unavailable or unsafe; test control behavior when the question is whether defenses work; use authorized penetration testing when a safe, scoped demonstration of an exploit or chain is appropriate. Use more than one method only when the remaining decision depends on additional evidence.
  5. Set priority using organizational context. Bring together severity, reachability, asset importance, exploitation evidence, and control results. These factors inform urgency; no single score or test replaces the organization’s risk decision.
  6. Remediate and revalidate. After a fix or mitigation, check the relevant outcome. Confirm that the vulnerable condition is addressed and, where applicable, that controls behave as expected. A closed ticket should correspond to a checked remediation result, not merely a change in status.

Choosing a method when testing is constrained

  • No usable exploit exists: Exploitability assessment may still help evaluate conditions and exposure; do not claim a live demonstration that was not possible.
  • The asset cannot safely undergo a live test: Use non-disruptive evidence and control validation where appropriate, and document what those methods did not establish.
  • The key uncertainty is defensive coverage: Test whether the specified controls block or detect the relevant scenario rather than assuming that a high severity score describes control performance.
  • A possible attack path spans multiple weaknesses: A scoped, authorized penetration test may establish whether the chain is feasible in that environment, subject to safety constraints.
  • The fix is reported complete: Recheck the condition that drove remediation so the organization knows whether exposure was actually reduced.

What the broader testing figures can tell you

The September 14, 2026 contributed article attributes two figures to Omdia: 95% of organizations reportedly rank penetration testing as a top or high priority, while 32% of average attack surface is reportedly tested yearly. The linked report landing page did not expose the survey sample, field dates, or methodology, so these figures should be treated as attributed estimates rather than fully inspectable survey results. They may illustrate a gap between stated priority and annual testing coverage, but they do not establish how much validation any particular organization needs.

Make evidence—not volume—the basis for action

AI-assisted discovery can add to the pool of findings defenders must evaluate. It does not remove the need to determine whether a candidate is valid, whether an attacker can reach and exploit it, what controls do, and how much the affected asset matters. A disciplined process connects those distinct forms of evidence to a shared remediation decision and checks whether the fix worked.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.