Anthropic-linked CVEs pile up, attackers mostly shrug

← Back to the feed

Anthropic-linked CVEs pile up, attackers mostly shrug

The Register · 4 hours ago

Anthropic's Project Glasswing, which provides vetted partners with access to the Claude Mythos Preview model for defensive security work, has been credited with discovering 225 vulnerabilities since launching in April. However, only one of these flaws has been exploited in the wild, according to VulnCheck security researcher Patrick Garrity, suggesting that the model's impressive bug-hunting capability has not translated into a surge of real-world attacks. This finding challenges widespread concerns that advanced AI models would lead to dramatically increased exploitation rates.

The data reveals that fewer than 0.5 per cent of Glasswing-attributed CVEs are being actively weaponised—consistent with historical patterns where only one to two per cent of all disclosed vulnerabilities are exploited in practice. Garrity emphasised that discovering vulnerabilities and having threat actors actually use them are fundamentally different outcomes. Additionally, recent research shows that whilst AI models excel at identifying flaws, they struggle with remediation; studies found AI-generated security fixes were successful only 26 per cent of the time, with over half either failing to resolve issues or introducing new vulnerabilities. The practical work of coordination, triage, remediation and patch deployment remains predominantly human-intensive labour.

  • Only 1 of 225 Glasswing-attributed CVEs has confirmed real-world exploitation
  • AI finds bugs well but fixes them successfully just 26% of the time
  • Vulnerability discovery rate doesn't predict actual attacker adoption

AI Technology

Read the full article at the source →