Anthropic says Project Glasswing found more than 10,000 serious software vulnerabilities in its first month
The Facts
- Anthropic said Project Glasswing found more than 10,000 high- or critical-severity software vulnerabilities in about its first month.
- The vulnerabilities were found using Anthropic's unreleased Claude Mythos Preview model in collaboration with about 50 partners.
- Anthropic says the project is focused on software it considers critical or systemically important infrastructure.
- Anthropic and partner accounts cited in coverage say many participants found hundreds of serious vulnerabilities, and some reported bug-finding rates increased by more than tenfold.
- Cloudflare was cited as finding about 2,000 issues in critical internal systems, including roughly 400 classified as high- or critical-severity.
- Anthropic says the main constraint is no longer discovering vulnerabilities but verifying, disclosing, and patching them.
- Anthropic says it is withholding most technical details about the newly found vulnerabilities for now because many issues have not yet been disclosed or patched.
How left and right are reading this
- Both agree
- Serious flaws are being uncovered at unusual scale in software Anthropic describes as critical infrastructure, and neither framing treats detection alone as the achievement; the real challenge now is responsibly verifying, disclosing, and patching vulnerabilities that remain largely undisclosed.
- They split on
- Less a disagreement than a question of emphasis: the alarming extent of weaknesses in systemically important software, versus the operational reality that faster discovery only helps if verification, disclosure, and patching keep pace.
Context
What is Project Glasswing?
Project Glasswing is Anthropic's collaborative cybersecurity effort, launched last month, to use AI to help secure critical software before increasingly capable AI systems can be misused against defenders anthropic.com,International Busin….
Who is involved in the project?
Anthropic says it is working with about 50 partners through Project Glasswing, including cybersecurity and infrastructure organizations; coverage also cites Cloudflare as one participant and says select companies were given access to Claude Mythos Preview International Busin…,anthropic.com,Financial Express.
Why haven't the vulnerabilities been described in detail?
Anthropic says most findings cannot yet be publicly detailed because vulnerabilities still need to be verified, disclosed, and patched, and releasing specifics too early could put users at risk anthropic.com,THE DECODER.
View all 14 sources
Wire services (1)
Independent coverage (13)
About these frames
See this differently than someone you know would? Two ways to keep it going.
The dial works on any URL — paste an article you read elsewhere this week.