{
  "id": 9050216,
  "title": "Anthropic-linked CVEs pile up, attackers mostly shrug",
  "url": "https://urgent.news/2026/09/21/anthropic-linked-cves-pile-up-attackers-mostly-shrug",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T22:32:51.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/21/anthropic-linked-cves-pile-up-attackers-mostly-shrug/5298018"
  },
  "original_language": "en",
  "account": "As more vulnerabilities linked to Anthropic and Project Glasswing are discovered, a small fraction of these security flaws are being exploited in the wild, according to VulnCheck researcher Patrick Garrity. Anthropic launched Project Glasswing, a program that grants select partners access to its Claude Mythos Preview model, shortly after announcing the initiative in April. The model, Anthropic claims, is too risky for public release due to its superior bug-finding and exploitation abilities compared to human experts. Access to this program is limited to vetted Glasswing participants, who utilize the model for defensive security work, including identifying and rectifying flaws in their own software products and open-source dependencies.\n\nAs of Monday, Anthropic's CVE tracker records 225 vulnerabilities attributed to Anthropic and/or Project Glasswing. Of these, only one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild. Analysts suggest that while AI models excel at finding vulnerabilities, they are less effective at creating exploitable ones. The primary concern, according to Garrity, is that the vulnerabilities discovered by Anthropic and Project Glasswing have minimal impact and are not being weaponized at a higher rate than other, randomly selected vulnerabilities. This data indicates that Anthropic's discoveries and disclosures are limited in their threat potential.",
  "summary": "Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Anthropic-linked CVEs pile up, attackers mostly shrug",
        "url": "https://urgent.news/2026/09/21/anthropic-linked-cves-pile-up-attackers-mostly-shrug-9052820",
        "published": "2026-09-21T22:32:51.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}