AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them
Anthropic's Project Glasswing gives vetted partners access to its Claude Mythos Preview model, an AI system the company says is skilled enough at finding and exploiting software flaws that it restricted public release. Partners use the model defensively, hunting for bugs in their own products and open source dependencies rather than attacking others.
Security researcher Patrick Garrity at VulnCheck has been tracking CVEs credited to Anthropic or Glasswing since the program launched in April. As of this week, the tally sits at 225 vulnerabilities, but only one, a critical SQL injection flaw in Ghost (CVE-2026-26980), has been confirmed as exploited in the wild. That puts the real-world exploitation rate at under half a percent.
Garrity says this doesn't mean AI can't find genuine security flaws; recent large patch releases from major vendors suggest AI-assisted research is surfacing more issues than ever. But finding a vulnerability and having it become a tool attackers actually use are two different things. So far, Glasswing-linked bugs appear no more dangerous in practice than a random sample of other disclosed vulnerabilities.