Drooid Logo
Back to story perspectives

Full Breakdown

Anthropic’s Project Glasswing Unveils AI-Driven Surge in Software Vulnerabilities

5/23/2026, 8:47:41 PM

First-Month Findings

Project Glasswing, using Anthropic’s Claude Mythos Preview model, reported more than 10,000 high-or critical-severity software flaws in its inaugural month. Independent review confirmed 1,094 of these as verified high-or critical-severity, prompting 97 upstream patches and 88 advisories. A banking partner also stopped a $1.5 million wire fraud attempt.

Background and Participants

Anthropic launched Glasswing last month, granting early access to about 50 partners—Cloudflare, Mozilla, Cisco, Oracle, Palo Alto Networks, Microsoft, and a major bank. The White House and Pentagon have engaged on supply-chain risk and policy.

Key Numbers

  • High/critical candidates: 6,202; validated high/critical: 1,094.
  • Independent review: 1,752 high/critical findings, 90.6 % valid.
  • Open-source scan: ~23,019 total vulnerabilities, 6,202 high/critical.

Why It Matters

AI-driven discovery shifts the security bottleneck from detection to verification and patching. Palo Alto Networks and Microsoft report five-fold growth in patch releases; open-source maintainers ask for slower disclosure to manage remediation.

Official Responses

Anthropic urged faster patch cycles, recommending quicker testing, hardened defaults, multi-factor authentication, and logging. Oracle moved to monthly critical-patch cycles. Cisco’s Anthony Grieco said the model cuts false positives but needs robust “harness” environments. The White House is consulting AI labs on safeguards; the Pentagon labeled Anthropic a supply-chain risk.

Criticism and Opposition

Security experts say the threat may be overstated. Isaac Evans of Semgrep cited a “big communication gap between practitioners and policymakers.” Others note the real challenge is validating and fixing the flood of bugs, not AI discovery. Limited compute and guardrails restrict broader adoption.

Conflicting Reports and Gaps

Sources differ on reviewed high/critical findings—1,726 vs 1,752—and on total vulnerabilities, ranging from 10,000 to 23,019. Public data on false-negative rates and long-term remediation remain unavailable.

Verbatim Quotes

  • “The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity,” — Anthropic spokesperson
  • “I think there’s a really big communication gap between practitioners and policymakers,” — Isaac Evans, CEO, Semgrep
  • “If you have a Formula One car but you’ve only ever driven a bike, you might be able to get it to go straight,” — Anthony Grieco, SVP, Cisco
  • “Our adversaries have gotten really good without AI,” — Cynthia Kaiser, former senior FBI cybersecurity official, Halcyon

What’s Next

Anthropic will expand Glasswing to more partners and governments while finalizing a Cyber Verification Program that lets security teams use the model without guardrails for legitimate research. Stronger safeguards will precede any public release of Mythos-class systems as the industry adapts patch-management.