NEWS 10 000 vulnerabilities. No break. No false anxieties. The new Claude model finds bugs 10 times faster than people write patches

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,278
The company shares the success of Project Glasswing in a month.
1779612515188.png
Anthropic заявилаsaid that Project Glasswing has already found more than 10 000 high- and critical hazard vulnerabilities in key software. The project was launched a month ago as a joint initiative with about 50 partners: the goal is to strengthen the important code in advance before powerful AI models begin to massively use to search for and operate errors.

The main conclusion of the first weeks sounds unpleasant for the entire security industry: a narrow place has shifted. Previously, developers and researchers rested on the speed of search for new vulnerabilities. Now Claude Mythos Preview finds them so quickly that there are not enough people to check, responsible disclosure and prepare corrections.

Anthropic does not disclose the technical details of most finds. The industry has a strict order for a long time: usually a new vulnerability is publicly told 90 days after detection or about 45 days after the patch release, if the correction appears earlier. Such a period is necessary for users to have time to upgrade before the details get to the attackers. Therefore, the company now gives aggregated figures and individual examples, and not a full analysis of all errors.

Project Glasswing partners serve software systems on which the Internet and critical infrastructure depend. During the first month, most participants found hundreds of high-risk or critical vulnerabilities in their code. Several companies reported that the speed of bug search increased by more than 10 times. Cloudflare, for example, the model found 2000 bugs in critical systems, of which 400 received a high or critical estimate. In Cloudflare itself, the share of false positives was considered better than that of human testers.

Similar results were shown by external checks. The UK’s AI Institute said the Mythos Preview was the first model to pass both of its cyber polygons from beginning to end. Such polygons imitate multi-step attacks, where it is not enough to find one mistake: you need to build a chain of action. Mozilla during testing Mythos Preview found and fixed 271 vulnerabilities in Firefox 150. This is more than 10 times more than the team found in the Firefox 148 with Claude Opus 4.6.

Independent XBOW platform called Mythos Preview a noticeable step forward compared to existing models on web operation tests. The industrial sets of ExploitBench and ExploitGym, which measure AI’s ability to develop exploits, also brought Mythos Preview first among proven models.

The first consequences are already visible in patches. In the latest release of Palo Alto Networks, the fixes were more than 5 times more than usual. Microsoft has warned that the number of new patches will rise for some time. Oracle has also begun to find and close vulnerabilities in its products and clouds noticeably faster than the same.

Mythos Preview was useful not only for code analysis. In one of the banks participating in Project Glasswing, the model helped to detect and stop the fraudulent transfer for $ 1.5 million. Before that, the attacker compromised the client’s mail and used fake phone calls.

Separately, Anthropic checks open source code. In recent months, the company has scanned more than 1000 open-source projects, which hold a significant part of the Internet and its own infrastructure Anthropic. The model found 23 019 potential vulnerabilities at all levels of danger. Of these, 6202 she rated as high or critical.

Part of the finds has already been checked by 6 independent security companies and Anthropic itself. Of the 1752 high- or critical vulnerabilities, 90.6% were real problems, and 62.4% confirmed the original seriousness. In absolute numbers, these are 1587 real vulnerabilities and 1094 confirmed mistakes of high or critical levels. If the current share of confirmation is maintained, even without new finds, Mythos Preview can bring to the surface almost 3,000 serious vulnerabilities in the open source.

One example is wolfSSL, an open cryptographic library that uses billions of devices. Mythos Preview has built an exploit for an error that allows you to fake certificates. In a practical scenario, an attacker could raise a fake bank or mail service website that would look legitimate for an ordinary user. The vulnerability has already been closed, it was assigned the number CVE-2026-5194, and the technical analysis Anthropic promises to publish in the coming weeks.

Checking such finds requires a lot of handmade work. First, experts reproduce the problem, re-estimate the danger, check the presence of corrections and only then prepare a detailed report for the developers of the project. Anthropic emphasizes that open-source escorts have to be treated carefully: they are already littered with low-quality reports generated by AI. Several teams asked Anthropic to slow down the disclosure because they needed more time on patches. On average, a serious vulnerability found by Mythos Preview is closed in 2 weeks.

Sometimes developers ask to transfer bugs directly, without additional verification. So Anthropic has already revealed 1129 untested finds, of which 175 models rated as high or critical. A total of 530 serious vulnerabilities were transmitted to the escorts. Another 827 confirmed problems Anthropic plans to solve as soon as possible.

There are fewer patches than the errors found. Of the 530 high- or critical vulnerabilities transferred, 75 were closed and 65 received public notifications. Anthropic explains the gap to 3 reasons. First, many of the findings are still inside the 90-day window of coordinated disclosure. The second: part of the projects corrects errors without public ballots, so patches have to be searched separately. The third is more important than the rest: even the cautious rate of disclosure is already overloading the security ecosystem.

For developers, there is an intermediate dangerous period. Mythos Preview models drastically reduce the time and cost of finding vulnerabilities, but the release and installation of fixes are still slower. In the future, such systems can help wite a secure code before the release. Now the industry has received many new finds, and the usual processes of verification and updates do not keep up with the speed of AI.

Anthropic advises developers to shorten patch release cycles, give users more quickly and simplify the installation of updates. Organizations that protect networks need to speed up testing and deploy patches, as well as not to postpone the basic measures: tight default settings, multifactor authentication and full-fledged journals to investigate incidents. Such measures reduce the risk even when a separate patch is not yet established.

The company has already begun to give some of the tools to the defenders. Claude Security was released in a public beta for Claude Enterprise clients. The service scans codebases, searches for vulnerabilities and offers corrections. In the first 3 weeks, Claude Opus 4.7 was used to close more than 2100 vulnerabilities. In corporate code, the process is faster than in open-source projects, because companies rule their own systems, and do not wait for voluntary accompanying and a coordinated disclosure procedure.

Anthropic has also launched the Cyber Verification Program. The program allows security professionals to use models for legal tasks, including the study of vulnerabilities, penetration testing and imitation of attacks, without some of the restrictions that are needed to protect against abuse. For qualified customers, the company opens the tools that it itself used with Mythos Preview: sets of instructions for repeating tasks, strapping for analyzing the code base, launching subagents, sorting out of findings and preparing reports, as well as a threat model constructor that helps to understand which parts of the project are more interesting to the attacker.

Partners also begin to share their best practices. Cisco has opened the Foundry Security Spec so that other teams can build similar evaluation systems. Anthropic is collaborating with the Open Source Security Foundation’s Alpha-Omega project to help accompany open-source projects process and sort error reports. The company also supported the development of ExploitBunch and ExploitGym and promises to scan open-source packages that will be taken into operation.

Anthropic has not yet released the Mythos class model in the public domain. The company directly associates this with the lack of enough strong defenses against abuse: if the model of this level is available without serious restrictions, the operation of vulnerable software will become cheaper and easier for a much larger number of people. Project Glasswing should give a head start to the defenders: first strengthen critical systems, and then expand access to the strongest models.

Further, Anthropic plans to expand Project Glasswing along with key partners, including U.S. governments and allied countries. The company promises a general release of models of the Mythos class only after the emergence of more reliable protective mechanisms. While the main result of the first weeks is as follows: AI is already able to massively find serious mistakes, and the security industry urgently needs to learn how to quickly check, correct and deploy patches.
 
5,698Threads
76,013Messages
5,838Members
ECOCOINLatest member
Top Bottom