Key insights
- Anthropic's Project Glasswing, utilizing AI, identified thousands of software vulnerabilities in critical infrastructure. While improving cybersecurity, the news also highlights the pervasive risks within the software ecosystem. The increased detection rate could lead to short-term market concerns about software security, but long-term benefits from improved security practices.

Investing.com -- Anthropic reported Friday that its Project Glasswing initiative has identified more than 10,000 high- or critical-severity vulnerabilities in systemically important software during its first month of operation.
The artificial intelligence company and approximately 50 partners used Claude Mythos Preview to scan critical software infrastructure. Anthropic said the initiative’s progress is now limited by the speed at which vulnerabilities can be verified, disclosed, and patched rather than by discovery rates.
Cloudflare found 2,000 bugs across its critical-path systems, with 400 classified as high- or critical-severity. The company reported its bug-finding rate increased by more than ten times. Several other partners reported similar increases in vulnerability detection rates.
The UK’s AI Security Institute said Mythos Preview is the first model to solve both of its cyber ranges end to end. Mozilla found and fixed 271 vulnerabilities in Firefox 150 while testing Mythos Preview, more than ten times the number found in Firefox 148 with Claude Opus 4.6.
Anthropic scanned more than 1,000 open-source projects using Mythos Preview, finding 6,202 estimated high- or critical-severity vulnerabilities out of 23,019 total. Of the 1,752 high- or critical-rated vulnerabilities assessed by independent security research firms, 90.6% were confirmed as valid and 62.4% were verified as high- or critical-severity.
One detected vulnerability was in wolfSSL, a cryptography library used by billions of devices. The exploit would allow an attacker to forge certificates to host fake websites for banks or email providers. The vulnerability was assigned CVE-2026-5194 and has been patched.
Anthropic disclosed 530 high- or critical-severity bugs to maintainers, with 75 now patched and 65 given public advisories. The company said a high- or critical-severity bug found by Mythos Preview takes two weeks to patch on average.
Palo Alto Networks included over five times more patches than usual in its latest release. Microsoft said the number of new patches it releases will continue trending larger. Oracle is finding and fixing vulnerabilities across its products multiple times faster than before.
Anthropic released Claude Security in public beta for Claude Enterprise customers three weeks ago. The tool has been used to patch over 2,100 vulnerabilities using Claude Opus 4.7.
The company formed a partnership with the Open Source Security Foundation’s Alpha-Omega project to assist maintainers in processing bug reports. Anthropic has not released Mythos-class models to the public, citing the need for stronger safeguards to prevent misuse.
This article was generated with the support of AI and reviewed by an editor. For more information see our T&C.