AI Finds 10,000 Critical Software Flaws in Just One Month
Artificial intelligence has identified more than 10,000 critical software vulnerabilities within just a month across some of the world’s most important digital systems, according to US-based AI startup Anthropic. The company disclosed the findings after early testing of its newly developed advanced AI model, Claude Mythos.
To strengthen cybersecurity protection, Anthropic launched a special initiative called “Project Glasswing” last month. Under the program, nearly 50 partner organizations—including tech giants Amazon, Apple, Google, and Microsoft, alongside several security research firms—were granted access to the Mythos model.
The primary objective of the initiative was to use AI to detect and fix software weaknesses before cybercriminals could exploit them.
Anthropic said that during the first month of testing, the AI model discovered more than 10,000 high- and medium-severity vulnerabilities across over 1,000 open-source projects and partner systems that support global internet and digital infrastructure.
In a statement, Anthropic said, “Most partners discovered hundreds of critical flaws in their software. Several organizations reported that the new technology increased vulnerability detection speed by nearly ten times compared to traditional human-led methods.”
Among the notable findings, Mozilla reported identifying and fixing 271 security flaws while testing the codebase of Firefox version 150.
Meanwhile, Cloudflare said the AI system detected nearly 2,000 bugs within its infrastructure, including around 400 categorized as highly critical. According to Cloudflare’s security team, the AI model demonstrated a significantly higher accuracy rate in detecting flaws compared to conventional human-designed testing methods.
AI Faster Than Humans, But Raising New Challenges
Although the technology is being hailed as a breakthrough in cybersecurity defense, experts warn that it also introduces a new challenge.
Cybersecurity specialists say that while AI can identify thousands of vulnerabilities almost instantly, human engineers are unable to patch and resolve those flaws at the same pace. As a result, the window between vulnerability discovery and software patching could become an increasingly dangerous period for potential cyberattacks.
Open-source software developers have reportedly requested Anthropic to slow down the submission of vulnerability reports because engineering teams are struggling to handle the overwhelming volume of detected issues.
Not Being Released to the Public
Anthropic has made it clear that Claude Mythos and similar high-end AI cybersecurity systems will not be made publicly available at this stage.
The company warned that the same AI capable of detecting vulnerabilities could also be weaponized to create sophisticated malware and highly advanced cyberattacks if it falls into the wrong hands.
For that reason, the technology remains under strict supervision so that only cybersecurity defenders—not hackers—can benefit from its advanced capabilities.
DBTech/BMT/OR



