Project Glasswing: AI-assisted vulnerability detection finds over 10,000 critical software flaws
By
louiereederson
Fresh out the oven, still warm. Top of the tray.
Summary
Project Glasswing is a collaborative effort launched to secure critical software against potential threats from increasingly capable AI models. With approximately 50 partners, the project has used Claude Mythos Preview to identify over ten thousand high- or critical-severity vulnerabilities across the world's most systemically important software. The key insight is that the bottleneck in software security has shifted from finding vulnerabilities to verifying, disclosing, and patching them at scale.
Key quotes
· 2 pulledWe and our approximately 50 partners have used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities across the most systemically important software in the world.
Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found.
You might also wanna read

Anthropic Launches Project Glasswing Cybersecurity Initiative with Major Tech Partners
Anthropic has launched Project Glasswing, a cybersecurity initiative partnering with major tech companies including Nvidia, Apple, Google, A
AI-Powered Bug Discovery Finds 271 Hidden Vulnerabilities in Firefox, Signaling New Era for Software Security
Security Now episode 1080 analyzed how frontier AI models (specifically Claude) discovered 271 hidden bugs in Firefox's codebase, as documen
AI discovers 271 Firefox vulnerabilities, signaling security debt repayment
Mozilla discovered 271 previously unknown Firefox vulnerabilities in just days using AI-powered testing, bugs that millions of automated tes
IBM and Red Hat launch Project Lightwell: $5 billion AI initiative to fix open-source security crisis
IBM and Red Hat are launching Project Lightwell, a $5 billion initiative deploying 20,000 engineers to address the growing security crisis i
zdnet.com·15h ago
AI bug-finding systems uncover real vulnerabilities at DARPA cybersecurity challenge
The article discusses the DARPA AI Cyber Challenge (AIxCC) held in Las Vegas, where top cybersecurity teams demonstrated AI-powered bug-find

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
