Anthropic CVEs Accumulate, Intruders Uninterested – GadgetLad

Anthropic CVEs: More Whimper Than Bite

Even with the hysteria surrounding AI models detecting vulnerabilities like a Jack Russell on a hunt, the truth is, most attackers aren’t interested in them. As per VulnCheck’s security expert, Patrick Garrity, fewer than 0.5 percent of the vulnerabilities associated with Anthropic or Project Glasswing are being exploited in practice. It sounds a bit like much ado about nothing to me.

Glasswing: Reality or Risk?

Garrity has been monitoring the CVEs related to Project Glasswing, Anthropic’s initiative for distributing its enigmatic Claude Mythos Preview model. This particular model was considered too perilous to release to the public because it’s said to be adept at locating and leveraging weaknesses, second only to the most astute human intellects. Thus, Anthropic secures it tightly, permitting only selected Glasswing personnel to utilize it for identifying and remedying flaws in their own software and open-source components.

The Statistics

Garrity’s Anthropic CVE tracker enumerates vulnerabilities attributed to Anthropic and Project Glasswing. He monitors these CVEs against the company’s known exploited vulnerabilities index. As of Monday, he has noted 225 CVEs, yet only one, a troublesome SQL injection vulnerability in Ghost (CVE-2026-26980), has been exploited in the wild. “Discovering a vulnerability is one aspect, but attracting the attention of threat actors is an entirely different challenge,” Garrity conveyed to GadgetLad.

AI: Exceptional Bug Seeker

Garrity isn’t diminishing AI’s ability to uncover bugs. Recent security updates from major companies like Microsoft and Apple, along with various open-source efforts, indicate that AI models are revealing more security issues than before. However, Garrity points out that this ability isn’t “exclusive to a single model or framework.”

Exploiting Bugs: Not So Easy

The majority of vulnerabilities fail to attract a hacker’s attention. Traditionally, just below one percent to two percent of vulnerabilities become weaponized. While AI excels at identifying vulnerabilities, it still falls short at patching them. A study conducted by 1Password’s team, involving 6,080 patches, showed that AI-generated solutions only succeeded 26 percent of the time. Concurrently, another study from Veracode reported an average security pass rate of merely 56 percent for AI-generated code.

Humans Remain Key Players

The intricate process of developing and deploying security fixes still requires human involvement. “AI simplifies the search for vulnerabilities, but the significant work still occurs downstream: coordinating, triaging, remediating, and implementing patches,” Garrity clarified. Anthropic might not have recognized this when they initiated the project.

Conclusion: Much Noise About Nothing?

So, that’s your lot. Anthropic’s AI powerhouses are uncovering vulnerabilities everywhere, yet only a tiny fraction pique a hacker’s interest. Ultimately, it’s we, the human operators, who must step up and get the task completed. Who would have thought? Just another day, another dollar in the tech realm, right?