May 22, 2026
Project Glasswing: more than 10,000 high and critical vulnerabilities in a month
Anthropic's first Glasswing update: partners using Claude Mythos Preview found over ten thousand serious bugs, and the bottleneck moved from finding vulnerabilities to fixing them.
Six weeks after launch, Anthropic said its roughly 50 Glasswing partners had used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities. Cloudflare alone reported 2,000 bugs, 400 of them high or critical; Mozilla fixed 271 vulnerabilities in Firefox 150.
In open source, Mythos Preview scanned more than 1,000 projects and estimated 6,202 high or critical vulnerabilities out of 23,019 findings. Of 1,752 assessed by independent firms, 90.6% were valid. On average a high or critical bug took two weeks to patch, and some maintainers asked Anthropic to slow down.
The conclusion: progress is now limited by how fast vulnerabilities can be verified, disclosed and patched. Anthropic also released Claude Security in beta and described a harness with codebase mapping, scanning subagents, triage and a threat model builder — the same shape later used by OSS Scanner.
Sources
Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.
Scan a repository