Anthropic’s cutting-edge artificial intelligence recently unearthed tens of thousands of potential vulnerabilities lurking within open-source codebases. However, the paramount bottleneck constraining this endeavor proved not to be computational horsepower, but rather human capacity. By May 22, the Claude Mythos Preview model had proactively generated a staggering 23,019 vulnerability candidates. Unfortunately, external human specialists possessed the bandwidth to manually verify a mere 1,900 of these reports. Astonishingly, they validated 1,726, a formidable 90.8% as genuine security flaws.
Project Glasswing: AI vs. Human Capacity
Anthropic initiated this monumental vulnerability sweep in February 2026. The sophisticated model systematically audited myriad open-source projects, subsequently forwarding its discoveries to six independent information security firms for rigorous manual verification. This methodology forms the bedrock of Project Glasswing, an initiative wherein AI strives to identify hazardous defects with unprecedented velocity, ideally preempting malicious actors from forging functional exploits.
At the precise moment the operational snapshot was published, Anthropic had actively disclosed 1,596 distinct vulnerabilities spanning 281 disparate projects to their respective developers. While project maintainers formally responded to 1,451 disclosures, they successfully remediated only 97 issues. Furthermore, a mere 88 vulnerabilities received formal CVE designations or GitHub Security Advisories. This stark disparity illuminates a profound, emerging crisis within the industry: automated vulnerability discovery is currently scaling exponentially faster than the human capacity for verification, remediation, and the subsequent deployment of critical patches.
High-Profile Discoveries and the Verification Lag
The compendium of published examples encompasses severe vulnerabilities residing within ubiquitous projects such as nginx, wolfSSL, Temporal, Nomad, ImageMagick, and FreeRDP. For instance, CVE-2026-27654, discovered within nginx, involves a critical buffer overflow manifesting during WebDAV operations. To maintain transparency, Anthropic curates a public registry of its findings, immutably securing confirmed records utilizing SHA-3-512 hashes pending the conclusion of the coordinated disclosure window.
Fortunately, this massive automated search has not yet precipitated a commensurate tsunami of active exploits. Although the volume of publicly acknowledged CVEs directly attributed to the project later swelled into the hundreds, documented instances of real-world exploitation remained exceptionally rare. Ultimately, artificial intelligence has already accelerated the discovery of profound vulnerabilities far beyond the velocity at which the cybersecurity industry can effectively process these findings and comprehensively seal the breaches.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.