Glostarep

Anthropic Project Glasswing Finds 10,000 Flaws

Anthropic Project Glasswing Finds 10,000 Flaws

AI can now find software vulnerabilities faster than humans can fix them. Anthropic’s Project Glasswing has uncovered more than 10,000 high-severity software flaws in its first month of operation. The Anthropic Project Glasswing initiative uses Claude Mythos Preview, the company’s most advanced and still-unreleased AI model, to find vulnerabilities before bad actors do. The gap between what the model discovers and what developers can patch is already alarming.

What Anthropic Project Glasswing Found

The numbers are stark. The model has dramatically increased the speed of vulnerability discovery across critical infrastructure, cloud platforms, browsers, enterprise software, and open-source projects. The model identified 6,202 high- or critical-severity vulnerability candidates affecting more than 1,000 open-source projects. The initial scanning phase yielded 23,019 candidate findings. When 1,900 of these findings were reviewed by external security firms, 1,726, or 90.8 per cent, were confirmed as valid true positives.

Of those, 1,094 are confirmed high- or critical-severity flaws. Only 97 have been patched. That last number is the story. Discovery has outpaced remediation by a factor of more than ten to one. Cloudflare said it found 2,000 vulnerabilities across critical systems, including 400 classified as high- or critical-severity.

The Most Serious Flaw Found So Far

The most notable finding so far is a critical flaw in WolfSSL (CVE-2026-5194, CVSS score 9.1), a widely used embedded TLS library, that could allow an attacker to forge certificates and impersonate a legitimate service. WolfSSL is deployed across IoT devices, automotive systems, and industrial control environments where a certificate forgery vulnerability carries consequences well beyond conventional web security. Beyond vulnerability hunting, the Anthropic Project Glasswing initiative also produced a direct financial result. A Glasswing partner bank leveraged the AI model to detect and prevent a fraudulent $1.5 million wire transfer after an unknown threat actor breached a customer’s email account and made spoof phone calls.

The Patch Crisis and What Anthropic Wants Next

The Project Glasswing results highlight a concern that the security industry has warned about for years. Anthropic urges software developers to shorten patch cycles and deliver security fixes faster, especially as models with similar capabilities to Mythos may soon become widely available. It also calls on network defenders to speed up patch testing and deployment.

Anthropic considers Mythos-class models too risky for broad public release because no organisation, including itself, currently has safeguards strong enough to stop large-scale misuse. For now, access remains limited through Project Glasswing and selected security programs. Partners include Amazon Web Services, Apple, Google, Microsoft, NVIDIA, CrowdStrike, JPMorgan Chase, and Palo Alto Networks. Anthropic is also expanding the program to include more partners and some governments.

At the same time, it continues building stronger safeguards before any wider release of Mythos-class systems. Overall, the gap between AI-driven discovery and human response is becoming clearer, and discovery is currently moving faster.

Leave a Comment

Your email address will not be published. Required fields are marked *