Anthropic has published the first update on Project Glasswing, its cybersecurity initiative running with roughly fifty partners. In one month, the program identified more than 10,000 critical or high-severity vulnerabilities in open-source software. The numbers redefine what an AI-powered audit can produce at scale.
Key Takeaways
- Over 10,000 critical or high-severity vulnerabilities found in one month across 1,000+ open-source projects
- Cloudflare discovered 2,000 bugs (400 critical/high) with a false positive rate better than human testers
- Of 530 bugs reported to maintainers, only 75 have been patched and 65 received public advisories
Have an AI Sum Up This Article
ChatGPTThe Numbers: What Glasswing Produced in Thirty Days
Project Glasswing brings together roughly 50 partners around one goal: identifying vulnerabilities in critical software before AI models can exploit them. In one month, the program surfaced 6,202 critical or high-severity vulnerabilities across more than 1,000 open-source projects. Including results from all partners, the total reaches over 10,000 critical or high-severity vulnerabilities discovered. Anthropic keeps widening its security network, Mythos rolling out to 100 US partners.
The accuracy of those findings has been validated: of 1,752 vulnerabilities assessed by security firms, 90.6% were confirmed as valid. That precision rate places Glasswing’s AI tools above many traditional human audit processes. Some partners reported bug-finding rates more than ten times higher than before.
Cloudflare’s results illustrate what becomes possible. The company found 2,000 bugs, 400 of them critical or high-severity, with a false positive rate better than its human testers. Mozilla identified 271 vulnerabilities in Firefox 150, a significantly higher count than what the previous Claude model had produced on Firefox 148.
These results arrive as Anthropic crosses a historic financial milestone, reporting its first profitable quarter. Project Glasswing fits squarely into that momentum: the initiative converts technical capability into a concrete commercial argument for organizations managing critical software infrastructure. For context, see our earlier piece on Horizon: Anthropic Maps the New AI Cyberattack Playbook.
Mythos Preview and Claude Security: The Tools at the Core
The UK AI Security Institute independently validated the performance of Mythos Preview, the model powering the program. According to the institute, Mythos Preview is the first model to solve their cyber range simulations end-to-end. On the academic benchmarks ExploitBench and ExploitGym, Mythos Preview ranked as the top performer in its class. That Mythos model runs elsewhere too, Claude Mythos protecting critical infrastructure.
Alongside vulnerability research, Anthropic launched Claude Security in public beta for Enterprise customers. In three weeks, more than 2,100 vulnerabilities were patched through the tool. The suite includes scanning capabilities, threat model builders, and custom instructions for security teams.
These tools build on years of AI safety research. The recent arrival of high-profile researchers at Anthropic strengthens the credibility of this direction: the company is building the most capable models while simultaneously developing the mechanisms to limit their risk of exploitation.
This update follows coordinated disclosure practices: certain technical details were withheld until patches are widely deployed. That caution is consistent with the nature of the program itself, which operates in an environment where the window between discovery and exploitation can be extremely short.
Also on Horizon:
- NTSB Shuts Down Dockets After AI Revives Pilots’ Voices
- Meta Lays Off 8,000 Workers to Fund AI
- OpenAI IPO Is Targeting September 2026
530 Bugs Reported, 75 Patched: The Disclosure Bottleneck
The most revealing aspect of this update may be the least headline-grabbing. Of 530 critical or high-severity vulnerabilities reported to open-source project maintainers, only 75 have been patched and 65 received a public advisory. That figure exposes a structural bottleneck in the software vulnerability correction chain.
The problem is not detection: Project Glasswing has shown that it can be industrialized. The problem is downstream. Open-source project maintainers are often volunteers or small teams without the resources to absorb a dense flow of security reports. AI can find thousands of flaws; it cannot force their correction.
In the short term, those 455 unpatched critical or high-severity vulnerabilities remain exploitable. For organizations that depend on these open-source projects, that is an open risk window. Prioritizing these fixes will become a pressing question for security teams in the weeks ahead.
In the medium term, Project Glasswing raises a broader governance question. If AI can generate thousands of vulnerability reports, who funds the fixes? Anthropic, with its industrial partners and 50 participating organizations, has demonstrated detection capability. The next critical step will be building economic models that fund the entire correction cycle, not just the discovery phase.
Follow the story on Horizon.



Pingback: Claude Security Now Scans Code With Mythos 5 - Horizon IA