Anthropic Holds Glasswing; Under 1% of Bugs Patched

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic postponed the public release of Project Glasswing, an AI vulnerability-discovery model, and granted early access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and patch bugs before adversaries do.
- Mythos Preview, the model behind Glasswing, found vulnerabilities across every major operating system and browser — including a 27-year-old bug in OpenBSD and a 72.4% success rate in the Firefox JS shell — while chaining four independent bugs into an exploit sequence that bypassed browser renderer and OS sandboxing.
- Claude Opus 4.6 failed at autonomous exploit development almost entirely, according to the article, making the Mythos jump a step-change rather than an incremental one.
- The discovery-to-patch gap is the article's central alarm: fewer than 1% of vulnerabilities found by Mythos were patched, and median time from disclosure to weaponized exploit fell from 771 days in 2018 to single-digit hours by 2024.
- Autonomous AI attacks are already operational — a threat actor used an LLM-powered chain against FortiGate appliances to compromise 2,516 organizations across 106 countries, and XBOW became HackerOne's top-ranked researcher in 2025.
- The piece is authored by a Picus Security engineer, frames the bottleneck as validation and remediation rather than discovery, and promotes the company's Autonomous Validation Summit on May 12 and 14 with Frost & Sullivan, Kraft Heinz, and Glow Financial Services.
Why it matters: Anthropic's Glasswing crystallizes an inversion: AI has solved the finding problem while fewer than 1% of discovered bugs get patched. For defenders, the bottleneck shifts from 'can we find bugs?' to 'can we process the findings?' — and CVSS-based, quarterly-test workflows are described as structurally incompatible with machine-speed threats.
Ask SkimNews



