Anthropic’s Project Glasswing Update

Refract AI Intelligence Digest

BLUF

AI-driven vulnerability scanning is producing findings faster than organizations can patch them.

NEWS

Anthropic released a status report for Project Glasswing showing their model found numerous dangerous vulnerabilities in client software since April 2026. Despite media claims that their Mythos model is superior at finding flaws, Schneier notes that nearly zero vulnerabilities have been patched. The initiative was initially driven by PR goals that created an uncritical perception of the tool's effectiveness.

Why I Care

Relying on AI for vulnerability discovery without matching remediation capacity leaves organizations exposed to known risks. This impacts enterprises using these tools and skews industry perception of AI security capabilities.

Next Steps

Security leaders should prioritize patching existing findings before deploying new AI scanners by end of Q3 2026. Teams must measure success by remediation rates rather than discovery volume when evaluating vendor claims.

In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic’s claims that it’s now common wisdom that Mythos is better at finding software vulnerabilities than other models. Which is just not true. In any case, Anthropic has published a Project Glasswing status report. It’s finding a lot of vulnerabilities in software—yay! Some of them are even dangerous. But almost none of them has been patched. It’s ...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.