The real bottleneck is no longer finding bugs. It is validating them fast enough to keep up, and Anthropic’s Project Glasswing shows AI-assisted discovery is already producing more candidate issues than maintainers can process cleanly.
Anthropic says Claude Mythos surfaced more than 10,000 vulnerability candidates across widely used software, with 6,202 tagged high or critical across 1,000+ open-source projects. After analysis, only 1,726 were true positives, and one named example was WolfSSL CVE-2026-5194, a critical flaw that could let an attacker forge certificates and masquerade as a legitimate service.
For operators that embed WolfSSL, the risk is not just a CVE count. It is downstream trust failure in TLS and mTLS, plus the lag between discovery, validation, and patch propagation across products that bundle the library.
Anthropic: Mythos finds more than 10,000 software flaws in first month
Anthropic’s Mythos model uncovers over 10,000 critical software flaws in its first month, shifting the cyber challenge from finding bugs to patching them.
Project Glasswing has uncovered 10,000 vulnerabilities: Anthropic
This means organizations that still treat patching as a quarterly exercise are operating with materially more risk than they were even a short time ago, says an analyst.