AI Just Found 10,000 Bugs Nobody Can Patch Yet

Abstract visualization of AI scanning software infrastructure for vulnerabilities
KEY POINTS
  • Anthropic’s Mythos Preview, working with roughly 50 Project Glasswing partners, has surfaced more than 10,000 high- or critical-severity vulnerabilities in weeks.
  • Cloudflare alone found 2,000 bugs (400 high- or critical-severity); Mozilla discovered 271 vulnerabilities in Firefox 150 — more than 10x what it found in Firefox 148 with Claude Opus 4.6.
  • The bottleneck has flipped: finding vulnerabilities is now easy, while verifying, disclosing, and patching them is the new choke point.
  • Anthropic released Claude Security in public beta, and Claude Opus 4.7 has already been used to patch 2,100+ vulnerabilities in three weeks.

For decades, the rate of software defense was capped by one number: how fast humans could find bugs. Project Glasswing’s first month-on-month update from Anthropic suggests that ceiling has effectively collapsed. With one frontier model and around 50 partners, more than 10,000 high- or critical-severity vulnerabilities have been pulled out of the world’s most critical software in weeks — and the people responsible for fixing them are visibly struggling to keep up.

The 10,000-Bug Wall

Partner results that reset the baseline

Project Glasswing launched in April 2026 as a coalition that included AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. One month in, Anthropic reports that most partners have each found hundreds of critical- or high-severity vulnerabilities in their own codebases. Several said their bug-finding rate jumped by more than 10x.

Cloudflare disclosed it had found 2,000 bugs across critical-path systems — 400 of them high- or critical-severity — at a false-positive rate its team considers better than human testers. The UK’s AI Security Institute reported that Mythos Preview is the first model to solve both of its cyber ranges (simulated multistep cyberattacks) end-to-end. Mozilla, scanning Firefox 150 with Mythos Preview, found and fixed 271 vulnerabilities — more than ten times what it surfaced in Firefox 148 with Claude Opus 4.6.

Trend Insight — When the same model finds 10x the bugs a previous flagship model did inside the same browser, this isn’t an incremental capability gain. It is a regime change for offensive and defensive security, and it is arriving faster than industry response cycles assume.


Open-Source Code Under the Microscope

23,019 findings — and a 90.6% true-positive rate

Beyond its private partners, Anthropic has been pointing Mythos Preview at more than 1,000 open-source projects that underpin much of the modern internet. The model has so far estimated 6,202 high- or critical-severity vulnerabilities (out of 23,019 total when medium and low are included). Of the 1,752 high- or critical-rated findings independently triaged by six external security firms, 90.6% turned out to be valid true positives, and 62.4% were confirmed as either high- or critical-severity.

One illustrative case: in wolfSSL — an open-source cryptography library used by billions of devices — Mythos Preview constructed an exploit allowing an attacker to forge certificates, the kind that would let a bad actor host a perfectly legitimate-looking fake bank or email site. The flaw was assigned CVE-2026-5194 and has since been patched. The aggregate trajectory points to nearly 3,900 confirmed high- or critical-severity OSS vulnerabilities, even if scanning stopped today.

Trend Insight — Several maintainers have asked Anthropic to slow the rate of disclosure because they cannot keep up. That sentence alone should reshape how we talk about “AI for security” — the volunteer base of open-source maintenance is the immediate bottleneck.


A New Bottleneck in Cybersecurity

Patching, disclosure, and the next window of risk

According to Anthropic, only 75 of the 530 high- or critical-severity bugs it has reported so far have been patched, and 65 of those carry public advisories. Average time to patch a high- or critical-severity Mythos Preview finding: about two weeks. Meanwhile, vendor patch volumes are visibly swelling. Palo Alto Networks shipped over 5x its usual patch count in a recent release. Microsoft has said its Patch Tuesday volume will “continue trending larger for some time.” Oracle is finding and fixing vulnerabilities multiple times faster than before.

There is also a sharper near-term concern. Mythos-class capabilities are not unique to Anthropic — comparable models will reach other developers soon, and not all will ship with safeguards. To get ahead of that curve, Anthropic released Claude Security in public beta for Claude Enterprise customers. In three weeks since launch, Claude Opus 4.7 has been used to patch more than 2,100 vulnerabilities inside enterprise codebases. The company is also opening its internal Glasswing tooling — skills, scanning harness, threat model builder — to qualifying customer security teams on request.

Trend Insight — The actionable read for engineering and security leaders today: shorten patch testing cycles, harden default configurations, enforce MFA, and assume the discovery side of the equation is no longer your friction point. The next 12 months will reward operational maturity over heroic bug-hunting.


Related

Sources

  1. Anthropic — Project Glasswing: An initial update (May 22, 2026)
  2. Cloudflare Blog — Cyber frontier models in production
  3. Mozilla Blog — AI security and zero-day vulnerabilities

AI Biz Insider · AI Trends EN · aibizinsider.com


AI Biz Insider에서 더 알아보기

구독을 신청하면 최신 게시물을 이메일로 받아볼 수 있습니다.

코멘트

댓글 남기기

AI Biz Insider에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기

AI Biz Insider에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기