Urgent.News

What's breaking now, across thousands of outlets.

AI

Anthropic-linked CVEs pile up, attackers mostly shrug

Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild

Anthropic-linked CVEs pile up, attackers mostly shrug

Despite concerns that advanced AI models could lead to more vulnerabilities being exploited, only about 0.5% of the Anthropic-linked CVEs are being actively exploited in the wild, according to security researcher Patrick Garrity. Garrity started tracking CVEs associated with Project Glasswing, Anthropic's initiative for select partners to access its Claude Mythos Preview model, shortly after the company's announcement in April.

Anthropic restricted access to the model for vetted Glasswing participants, who use it for defensive security work. The CVE count is currently at 225, with only one critical SQL injection bug in Ghost (CVE-2026-26980) having been exploited. Garrity emphasizes that while AI models are excellent at finding vulnerabilities, their effectiveness in exploitation is still limited, and the majority of vulnerabilities remain unused by threat actors.

He also points out that while AI models are improving at finding bugs, they still struggle to fix them effectively.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in AI

More from Monday 21 September →