irc://blog.northstartproductionstudio.com/#shipped ← back to log

No telemetry. No tracking. No cookies. No accounts.

* ~ghost has joined #shipped

1,596 AI-found vulnerabilities, 1.3% ever exploited — what that number actually says

· ~ghost

Anthropic announced Project Glasswing on April 7, 2026: a 12-company consortium using an unreleased model (internally called Claude Mythos Preview) to hunt vulnerabilities across critical open-source infrastructure at a scale no human team could match. By mid-2026 the program had disclosed 1,596 vulnerabilities across 281 open-source projects, 75 already patched. One report from the program's first month put the raw find-count over 10,000 before triage. This is real, it's dated, and it's the kind of number that's easy to read as "AI just made every open-source project a sitting duck."

An independent follow-up (VulnCheck's 1H 2026 report, July 2026) put a second, quieter number next to it: of roughly 1,061 AI-assisted vulnerability findings they tracked, only 1.3% ever hit CISA's Known Exploited Vulnerabilities list — and of Glasswing's own 23,000 findings specifically, 126 became CVEs and exactly 1 was ever confirmed exploited. Their own framing: that 1.3% rate matches the baseline exploitation rate for vulnerabilities found the old-fashioned way, by humans.

the headline number and the load-bearing number aren't the same one

"AI can find 10,000 bugs in a month" and "AI-found bugs get weaponized at roughly the same rate as human-found ones" are both true, dated, sourced claims from the same body of 2026 research — and they point in opposite emotional directions. The first one is the number that gets a headline. The second one is the number that should actually change what a security team does about it, and it mostly says: don't panic-triage an AI-sourced finding differently than you'd triage a human-sourced one just because of where it came from. The finding itself still needs the same real assessment — is it reachable, is it patched, is it actually exploitable in your specific deployment — that any vulnerability report has always needed.

What the 1.3% number doesn't say, and we're not going to pretend it does: that autonomous exploitation capability is standing still. Anthropic's own Exploit Evals report (May 22, 2026) introduced ExploitBench specifically to measure whether a model can go the extra step from finding a vulnerability to writing a working exploit for it — 41 challenge instances built around real or realistic vulnerabilities in Chrome's V8 engine. That's a different, harder capability than bug- finding, and it's the one worth actually watching move over time, not the raw discovery count.

why this is the honest story, not the scary one

The instinct in security content is almost always toward the more alarming framing — it's more shareable, and "AI found 10,000 vulnerabilities" is a better hook than "AI found 10,000 vulnerabilities and almost none of them mattered in practice yet." We'd rather be the second kind of post. Both halves are real, both are dated, both are sourced — leaving either one out would be the actual distortion, in either direction.

what we're not claiming

This isn't about anything we ship — Glasswing hunts vulnerabilities in target software (browsers, OS components, open-source infrastructure); Leviathan Platform is built for a different problem entirely, an organization's own deployed agents getting socially engineered or misused. We're not stretching this into a product pitch because it isn't one. It's a real, current data point about how AI-assisted vulnerability research is actually landing so far, worth having straight rather than filtered through whichever framing makes a better headline.


Sources: Anthropic's Project Glasswing announcement and Exploit Evals/ ExploitBench report (both 2026), independently corroborated by VulnCheck's 1H 2026 exploitation-rate analysis. Verify any of these independently before repeating them further — same standard we hold every number on this site to.

#security #ai-agents #research #vulnerabilities

* ~ghost has left #shipped