Glasswing: 10,000 Vulnerabilities in One Month, Verizon Joins as First Telecom
One month in, Project Glasswing is finding vulnerabilities faster than the software industry can patch them.
Anthropic’s collaborative cybersecurity effort — launched last month with approximately 50 partners using Claude Mythos Preview — has found more than 10,000 high- or critical-severity vulnerabilities across some of the most systemically important software on the internet. The bottleneck has shifted. It is no longer how quickly AI can find new vulnerabilities. It is how quickly humans can verify, disclose, and deploy patches.
What partners are reporting
The numbers from individual partners are concrete:
- Cloudflare found 2,000 bugs across its critical-path systems, 400 of which are high- or critical-severity. Its security team says the false positive rate is better than human testers, and the discovery rate is more than 10x its prior baseline.
- Mozilla found 271 vulnerabilities in Firefox 150 while testing Mythos Preview — over ten times more than found in Firefox 148 using Claude Opus 4.6. Most are already patched.
- Palo Alto Networks released a firmware update containing five times more patches than its typical release cycle.
Most Glasswing partners report finding hundreds of critical- or high-severity bugs each, a rate several say is more than tenfold their previous pace.
Independent evaluations
Third-party assessments outside the Glasswing programme are consistent with partner reports:
- The UK’s AI Security Institute has confirmed Mythos Preview is the first model to solve both of its cyber ranges end-to-end — simulations of multistep corporate cyberattacks.
- XBOW, an independent offensive security platform, calls Mythos Preview “a significant step up over all existing models” on its web exploit benchmark, with “absolutely unprecedented precision” on a token-for-token basis.
- ExploitBench and ExploitGym, two recently published academic benchmarks for exploit development capability, both list Mythos Preview as the strongest performer.
Confidentiality rules loosened
In its initial form, Glasswing required partners to sign confidentiality agreements restricting what they could share about Mythos findings with organisations outside the programme. Anthropic is now revising that position: partners can share threat intelligence from Mythos findings with other organisations that may be exposed to the same vulnerabilities.
The practical effect is that downstream users of open-source software libraries can receive early warning when a Glasswing partner finds a critical flaw — without needing their own Mythos access.
Verizon joins as first telecom
Verizon is now a Glasswing participant, the first telecommunications carrier to join. Telecom infrastructure sits at the intersection of AI capabilities and national security risk — Verizon’s network carries a significant share of US internet traffic. Its inclusion extends Glasswing’s reach into a sector that has been largely absent from AI security partnerships so far.
The disclosure lag problem
Anthropic is explicit about the constraint it faces: the software industry’s standard is 90-day coordinated disclosure after discovery, or 45 days after a patch ships. That convention exists to prevent attackers from exploiting vulnerabilities before users can update.
AI has compressed discovery from months to days. But disclosure and patching timelines are still measured in weeks. Anthropic says it will publish far more granular detail about Glasswing findings — specific vulnerabilities, attack chains, model capability evidence — once patches for Mythos-discovered flaws are widely deployed.
The current public data is therefore a lagging indicator of what Mythos Preview can already do.
Key numbers
| Partner | Bugs Found | Severity | Rate |
|---|---|---|---|
| Cloudflare | 2,000 total | 400 high/critical | 10x prior rate |
| Mozilla | 271 | Firefox 150 vs 148 | 10x vs Opus 4.6 |
| All partners | 10,000+ | High or critical | — |
- UK AISI: first model to solve both cyber ranges end-to-end
- XBOW: “absolutely unprecedented precision” on exploit benchmark
- Disclosure timeline: 45-90 days per standard coordinated disclosure — currently the binding constraint