#glasswing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #glasswing, aggregated by home.social.
-
"Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.
If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.
So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.
The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.
Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."
https://www.vulncheck.com/blog/anthropic-glasswing-receipts
#AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI
-
❝ I'm assuming the other 23k findings were pure dog shit and they want you to forget that it has a 90+% false positive rate ❞
https://masto.nyc/@gbargoud/117237178321400249but… WHO DECIDED THAT?
the #MythosAI #Glasswing report isn’t just obfuscating #accountability, it is pretty much leaving us in the dark about the actual #employment of tech workers’ and the amount of work/hours evaluating the LLMs code review.
someone at #Anthropic is lying about the actual human/hours #labor involved in managing Mythos.
-
RE: https://mastodon.social/@bagder/117236076403978219
maybe am missing something, but:
so #Glasswing uses #MythosAI to review all the partners’ code bases. they get 26,153 “findings” but only 2,736 are actually reported to project maintainers.
so someone ―either at #Anthropic and/or the +200 companies in Glasswing― decided that 23,417 flags should remain “off ledger”.
WHO MADE THAT DECISION? who reviewed the code review?
is this why management types loves #AI: it completely obfuscates accountability?
-
Anthropic's Bug Hunters Are Outrunning Microsoft's Fixers, and the Backlog Is Growing
Stay curious — follow @1ban_news.
-
@ThePrimeTime on YT!
#Glasswing #Mythos #Fable5 #InfiniteRed #AI #ClosedWeights #OpenWeights
He’s always wrong... - @ThePrimeTime
https://www.youtube.com/watch?v=OTa_vK9919g
7/1/2026
-
🧠 La mossa di #OpenAI con #Daybreak può essere letta come un chiaro posizionamento competitivo nello stesso nuovo spazio strategico aperto da #Anthropic con Project #Glasswing.
👉 I dettagli: https://www.linkedin.com/posts/alessiopomaro_openai-daybreak-anthropic-ugcPost-7475417595542859776-lWLi/
___
✉️ 𝗦𝗲 𝘃𝘂𝗼𝗶 𝗿𝗶𝗺𝗮𝗻𝗲𝗿𝗲 𝗮𝗴𝗴𝗶𝗼𝗿𝗻𝗮𝘁𝗼/𝗮 𝘀𝘂 𝗾𝘂𝗲𝘀𝘁𝗲 𝘁𝗲𝗺𝗮𝘁𝗶𝗰𝗵𝗲, 𝗶𝘀𝗰𝗿𝗶𝘃𝗶𝘁𝗶 𝗮𝗹𝗹𝗮 𝗺𝗶𝗮 𝗻𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿: https://bit.ly/newsletter-alessiopomaro -
Un'AI ha trovato 10.000 vulnerabilità critiche in 6 settimane — inclusa una in OpenBSD rimasta nascosta per 27 anni.
Si chiama Project Glasswing. Amazon, Apple, Microsoft e Google siedono allo stesso tavolo per difendersi insieme.
Ho scritto cosa prevede, come prepararsi e cosa proporre ai clienti già oggi.
-
Anthropics KI-Modell #Mythos: Zugriff soll deutlich ausgeweitet werden | heise online https://www.heise.de/news/Absicherung-von-Software-Anthropic-oeffnet-Project-Glasswing-fuer-Europa-11316440.html #AnthropicMythos #Anthropic #ArtificialIntelligence #AI #ProjectGlasswing #Glasswing
-
🧠 #Anthropic ha annunciato l'espansione di Project #Glasswing, l'iniziativa che utilizza l'#AI per individuare vulnerabilità nei software che supportano infrastrutture e servizi critici.
👉 I dettagli: https://www.linkedin.com/posts/alessiopomaro_anthropic-glasswing-ai-share-7468619015335333889-rgMy/
___
✉️ 𝗦𝗲 𝘃𝘂𝗼𝗶 𝗿𝗶𝗺𝗮𝗻𝗲𝗿𝗲 𝗮𝗴𝗴𝗶𝗼𝗿𝗻𝗮𝘁𝗼/𝗮 𝘀𝘂 𝗾𝘂𝗲𝘀𝘁𝗲 𝘁𝗲𝗺𝗮𝘁𝗶𝗰𝗵𝗲, 𝗶𝘀𝗰𝗿𝗶𝘃𝗶𝘁𝗶 𝗮𝗹𝗹𝗮 𝗺𝗶𝗮 𝗻𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿: https://bit.ly/newsletter-alessiopomaro -
In which Catriona Robinson, Deputy Director General of Cyber Security, at the National Cyber Security Centre, which is part of New Zealand's Government Communications Security Bureau intelligence agency, talks to Radio New Zealand's Guyon Espiner about her organisation buying pre-release access to Anthropic's Mythos through Project Glasswing.
-
Anthropic prépare son IA la plus puissante : Apple, Samsung et l’OTAN déjà dans les rangs
https://mac4ever.com/196480
#Mac4Ever #Anthropic #Glasswing -
🧠 #Anthropic ha pubblicato il primo aggiornamento su Project #Glasswing: in un mese ha individuato oltre 10.000 vulnerabilità.
👉 I dettagli: https://www.linkedin.com/posts/alessiopomaro_anthropic-glasswing-ai-share-7466798291725471745-ijuM/___
✉️ 𝗦𝗲 𝘃𝘂𝗼𝗶 𝗿𝗶𝗺𝗮𝗻𝗲𝗿𝗲 𝗮𝗴𝗴𝗶𝗼𝗿𝗻𝗮𝘁𝗼/𝗮 𝘀𝘂 𝗾𝘂𝗲𝘀𝘁𝗲 𝘁𝗲𝗺𝗮𝘁𝗶𝗰𝗵𝗲, 𝗶𝘀𝗰𝗿𝗶𝘃𝗶𝘁𝗶 𝗮𝗹𝗹𝗮 𝗺𝗶𝗮 𝗻𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿: https://bit.ly/newsletter-alessiopomaro -
Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!
Contact us today to see how our research-driven approach shapes the future of #appsec!
https://www.anthropic.com/research/glasswing-initial-update
#doyensec #security #ai #claude #claudecode #claudemythos #anthropic
-
For folks who are thinking about locally patching open-source software to fix what they think is a bug (_especially_ if they think it's a security vulnerability), I think that's a path to https://www.xkcd.com/424/
-
#Anthropic lockert Regeln für #Mythos-KI - inside-it[.]ch
Das Unternehmen erlaubt Partnern seines Cybersecurity-Modells Mythos künftig, Erkenntnisse zu Sicherheitslücken breiter weiterzugeben.
https://www.inside-it.ch/anthropic-lockert-regeln-fuer-mythos-ki-20260519 #ArtificialIntelligence #AI #AnthropicMythos #Glasswing -
Okay, here goes another AI Great Hot Take!1
AI will:
- increase the number of discovered vulnerabilities2
- decrease the quality of vulnerability reports3
- increase the number of vulnerabilities4
Welcome to the #vulnslopalypse, and please take note AI added nothing of value.
4 https://www.ioactive.com/the-security-gap-in-ai-generated-code/
-
Daniel Stenberg, lead developer curlu, popisuje výsledek skenu Anthropicova modelu Mythos, toho, kolem kterého Anthropic v dubnu vyvolal rozruch tvrzením, že je „nebezpečně dobrý“ v hledání bezpečnostních chyb. Přístup curl dostal přes program Glasswing a Linux Foundation / Alpha Omega.
Výsledek: sken nad 178 000 řádky kódu ohlásil 5 „potvrzených zranitelností“. Po […]
https://zdrojak.cz/zpravicky/mythos-nasel-v-curl-zranitelnost/ -
.@AnthropicAI announced a breakthrough: #AI so capable of breaking software that they decided not to publish it. They gave it to #Apple, #Microsoft, #Google, #Amazon & others via a initiative dubbed Project #Glasswing. Find the bugs before anyone else does.https://cybersec.picussecurity.com/s/the-glasswing-paradox-the-thing-that-can-break-everything-is-also-the-thing-that-fixes-everything-26922
-
New Firefox update patches a whopping 271 bugs with help from Claude Mythos
https://www.zdnet.com/home-and-office/networking/firefox-new-features-271-security-bug-fixes/ #cybersecurity #Claude #Mythos #Glasswing #Firefox #271Vulnerabilities -
RE: https://infosec.exchange/@patrickcmiller/116420098230430030
Healthy scepticism.
TL;DR by the authors:
"Anthropic presents Mythos and Project Glasswing as evidence that advanced AI vulnerability research should be restricted. But our replication suggests a different conclusion: the capabilities Anthropic points to are already available in public models, so defenders should prepare for that reality instead."
-
The EU built the most comprehensive AI regulatory framework on the planet.
The UK gets the cyberweapon first.
Glasswing access to Mythos is being extended to British banks while the European Commission is still asking for "some information" from a spokesman in Brussels.
Regulatory sophistication as competitive disadvantage.
#Mythos #Anthropic #Glasswing #Cybersecurity #DataSovereignty
-
🐛 Faster Bugs, Same Backlog — #Mythos Preview found thousands of zero-days across every major OS and browser in a matter of weeks. Anthropic was nervous enough about it to not release it publicly. That's notable. What's also notable is that "thousands of critical vulnerabilities" describes a perfectly ordinary patch Tuesday for most security teams — the backlog isn't new, the speed is.
The uncomfortable truth Project #Glasswing surfaces isn't that attackers are about to get a superpower (they are), it's that defenders have been relying on a fundamentally broken triage model for years. CVSS 10 gets the fire drill. The exploitable CVSS 6 sitting on an internet-facing legacy box gets the backlog. That gap is the actual attack surface. AI-accelerated discovery doesn't fix it — it just makes it more expensive to ignore.
→ Week #16/2026 also covers: AI vishing platforms hit the cybercrime market, NIST quietly caps CVE coverage, and Russia goes after a Swedish power grid.
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-16-2026-faster-bugs-same-backlog
If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI