Quantro Security Report Finds AI Agents Can Exploit Vulnerabilities in Minutes for Under $3
Quantro Security announced in a press release that autonomous AI agents can convert publicly disclosed vulnerabilities into verified working exploits in about 11 minutes for a median compute cost of $2.83. The findings are based on testing 3,029 disclosed CVEs, where AI agents successfully built and verified exploits for 2,183 of them, or 72 percent.
The study used the Quantro Exploit Harness, a system of AI agents that automatically ingests vulnerabilities, develops proofs of concept, and verifies successful execution without human input. Independent verification of the methodology and findings was conducted by Loginsoft.
The report highlights that 73 percent of the AI exploitable vulnerabilities carried an Exploit Prediction Scoring System score below 0.25, indicating that these flaws are often deprioritized by enterprise patching programs. Additionally, 89 percent of these were missing from the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.
To help organizations assess and mitigate these threats, Quantro Security is releasing two free tools, AI-XI (AI Exploitability Index) and AI-Recon (AI Native Exposure Scanner), designed to evaluate exploitability and exposure through the perspective of an AI attacker.
We hope you enjoyed this article.
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly, AI Policy Brief or Daily AI Brief.
Also, consider following us on social media:
More from: Cybersecurity
More from: AI Safety
Subscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Market report
2025 State of Data Security Report: Quantifying AI’s Impact on Data Risk
The 2025 State of Data Security Report by Varonis analyzes the impact of AI on data security across 1,000 IT environments. It highlights critical vulnerabilities such as exposed sensitive cloud data, ghost users, and unsanctioned AI applications. The report emphasizes the need for robust data governance and security measures to mitigate AI-related risks.
Read more