tech

Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.

Anthropic’s Glasswing project found 10,000+ critical flaws across 1,000 open-source projects in a month. Only 97 have been patched.

Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.

TL;DR

  • Anthropic's Glasswing project discovered over 10,000 critical vulnerability candidates in 1,000+ open-source projects in one month.
  • Only 97 of the confirmed critical flaws have been patched, highlighting a significant gap between discovery and remediation.
  • Claude Mythos Preview, an AI model used by Glasswing, can identify vulnerabilities at a pace the open-source ecosystem cannot absorb.
  • A critical flaw in WolfSSL, a widely used embedded TLS library, was a notable finding, with potential for attackers to forge certificates.
  • Access to Claude Mythos Preview is restricted to approximately 50 organizations described as "systemically important cyber defenders."
  • The AI model has also been used for defensive purposes, such as detecting and preventing a $1.5 million fraudulent wire transfer.
  • Anthropic and OpenAI are developing specialized AI models for cybersecurity, restricting public access due to concerns about misuse.
  • The rapid AI advancements necessitate a call for developers to shorten patch cycles and for organizations to harden security measures.