home.social

#projectglasswing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #projectglasswing, aggregated by home.social.

  1. "Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.

    If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.

    So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.

    The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.

    Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."

    vulncheck.com/blog/anthropic-g

    #AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI

  2. "Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.

    If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.

    So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.

    The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.

    Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."

    vulncheck.com/blog/anthropic-g

    #AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI

  3. "Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.

    If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.

    So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.

    The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.

    Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."

    vulncheck.com/blog/anthropic-g

    #AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI

  4. "Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.

    If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.

    So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.

    The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.

    Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."

    vulncheck.com/blog/anthropic-g

    #AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI

  5. "Anthropic’s own dashboard states 421 findings patched upstream, resulting in 462 advisories (GHSA/CVEs assigned); however, the ledger itself shows only 202 fixed findings.

    If we look at the GHSA ledger, CVE ledger, and main ledger (yes, there are three), the numbers also don’t add up. The CVE ledger lists 70 CVEs while the main ledger has 82 CVEs. The GHSA ledger lists 49 GHSAs, while the main ledger lists 77 GHSAs. None of which add up to the claim of 421 findings fixed upstream.

    So this makes me wonder whether the ledger is AI-assisted and under-reviewed. Likely a combination of the two.

    The Ledger has received only two bulk updates, so results are not published in real time. It’s worth highlighting that while the ledger has a public reveal date, that date doesn’t reflect the actual day the finding was revealed in the ledger as we saw with the recent update.

    Don’t discount the reality that AI tools like Claude are incredibly valuable and useful tools for discovering vulnerabilities. AI can help accelerate the discovery of bugs and vulnerabilities in software, as the evidence I've discussed across software suppliers and the CVE program shows. This blog aims to better understand the claims that Anthropic and other frontier model providers have made about Project Glasswing, and to see if the evidence aligns with those claims. It appears there are many discrepancies in the data they've published, which is still a small fraction of the findings after five months. The receipts are starting to trickle in, they just don’t reconcile."

    vulncheck.com/blog/anthropic-g

    #AI #Anthropic #CyberSecurity #ProjectGlasswing #Mythos #Glasswing #LLMs #GenerativeAI

  6. Oh lord. Can we get a moment's peace? Anthropic's most powerful — and dangerous — AI tool has been compromised. A group on a private Discord gained unauthorized access to Claude Mythos, a cybersecurity model so capable it can exploit vulnerabilities faster than elite human hackers. They cracked it on launch day by guessing its URL. Access came via a third-party contractor. Anthropic says no core systems were breached, but the irony is hard to ignore: an AI built to defend against cyberattacks... got hacked. The group claims curiosity, not malice — but the risk is real. techcrunch.com/2026/04/21/unau
    #Anthropic #ClaudeMythos #CyberSecurity #AIRisk #DataBreach #ProjectGlasswing #ArtificialIntelligence #TechNews #Hacked #AISecuriy