Security News

AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them

The Register · 22 Sept 2026
Key Takeaway Don't panic over headline vulnerability counts; prioritise patching based on confirmed exploitation and relevance to your own systems, not just how a flaw was discovered.

Anthropic's Project Glasswing gives vetted partners access to its Claude Mythos Preview model, an AI system the company says is skilled enough at finding and exploiting software flaws that it restricted public release. Partners use the model defensively, hunting for bugs in their own products and open source dependencies rather than attacking others.

Security researcher Patrick Garrity at VulnCheck has been tracking CVEs credited to Anthropic or Glasswing since the program launched in April. As of this week, the tally sits at 225 vulnerabilities, but only one, a critical SQL injection flaw in Ghost (CVE-2026-26980), has been confirmed as exploited in the wild. That puts the real-world exploitation rate at under half a percent.

Garrity says this doesn't mean AI can't find genuine security flaws; recent large patch releases from major vendors suggest AI-assisted research is surfacing more issues than ever. But finding a vulnerability and having it become a tool attackers actually use are two different things. So far, Glasswing-linked bugs appear no more dangerous in practice than a random sample of other disclosed vulnerabilities.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.