Timeline

Anthropic's Project Glasswing finds 10,000+ vulnerabilities via AI-assisted audits

Fixing a high- or critical-severity bug found by Mythos took two weeks on average, and some open-source maintainers asked Anthropic to slow its pace of disclosures.

  • Security & misuse
  • Notable

A month into Project Glasswing, Anthropic published its first update on the programme, reporting that around 50 partners scanning their own codebases with the unreleased Claude Mythos Preview model had collectively identified more than 10,000 high- or critical-severity vulnerabilities across systemically important software. Individual partner figures varied widely: Cloudflare reported roughly 2,000 bugs found, about 400 of them high or critical severity, while Mozilla reported 271 Firefox vulnerabilities.

The update’s central argument was about a bottleneck shifting rather than about the raw count. Anthropic said the constraint on software security had moved from how quickly vulnerabilities could be found to how quickly they could be verified, disclosed and patched: fixing a high- or critical-severity bug surfaced by Mythos took two weeks on average, and some open-source maintainers, facing a sudden volume of reports with limited staff, asked Anthropic to slow the pace of disclosure. Of a sample of findings independently assessed by security firms, Anthropic said 90.6% were confirmed as valid, with 62.4% of those rated high or critical severity. As a worked example, the update pointed to CVE-2026-5194, a certificate-forgery flaw in the wolfSSL cryptography library that Mythos found and that was patched before public disclosure.

The report reframed Glasswing’s early results as evidence for a specific claim: that AI-assisted vulnerability discovery was outpacing the human and institutional capacity to act on what it found, shifting the practical risk in software security from detection to remediation capacity.