Research · 104 days ago
The shift is not that AI can find more bugs. It is that those findings are now landing on the people who maintain widely used infrastructure code, so the bottleneck becomes triage and patching instead of discovery. That can turn one tool into a backlog problem across many downstream products and sectors.
Anthropic expanded Project Glasswing from about 50 initial partners to roughly 150 more vetted organizations. The new group includes critical-infrastructure vendors and maintainers of widely used codebases, after the first wave reportedly found thousands of vulnerabilities and more than 23,000 potential issues, with over 6,000 expected to be severe.
The near-term risk is simple: if small maintainer teams cannot confirm and fix issues fast enough, the software many other organizations depend on stays exposed even after the bug hunt gets better.
2 sources covering this story
Anthropic Expanding Mythos Access to 150 New Organizations
Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.
Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators
The AI firm also said it’s exploring how to help open-source developers deal with a flood of vulnerability reports.
Part of the PlainSec briefing for 2026-06-03