Thursday, 8 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed
Technology

Anthropic-linked CVEs pile up, attackers mostly shrug

The Register ·
Anthropic-linked CVEs pile up, attackers mostly shrug

Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity.

Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April.

At the time, Anthropic said the new model was too risky to release publicly because its bug-finding and exploitation skills surpass all but the most skilled humans.

As such, Anthropic restricted access to Mythos Preview to vetted Glasswing participants, who use the model for defensive security work, including finding and fixing flaws in their own software products and open source dependencies.

Garrity’s Anthropic CVE tracker maintains a list of vulnerabilities credited to the Anthropic team and/or Project Glasswing and also checks these CVEs against the company's known exploited vulnerabilities index "to get a better read on the real Glasswing ‘danger factor.’" As of Monday, the CVE count is 225, and just one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild.

“There's a big difference between finding vulnerabilities and whether they're actually useful to and will be used by threat actors,” Garrity told The Register.

“The main thing this data highlights is that what Anthropic is discovering and disclosing is fairly limited in impact, and from what we can tell, isn't resulting in different outcomes from a threat perspective than a random selection of other vulnerabilities would.” Anthropic didn’t immediately respond to our questions, but we will update this story if we hear back.

Garrity says he doesn’t dispute AI’s ability to find bugs.

Indeed, anyone following security disclosures over the past few months would have a hard time arguing that AI models aren’t bringing to light significantly more security flaws than ever before.

Case in point: recent massive patch drops from Microsoft, Apple, Palo Alto Networks, and don’t even get us started on open source projects.

Also, as Garrity pointed out, these vulnerability-finding skills aren’t “a capability unique to one model or harness.” “A lot of the hysteria we're seeing assumes that every vulnerability or bug is likely to be used by threat actors,” he told The Register.

“But the reality is that only a small fraction ever get used in exploitation campaigns.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›