AI Finds More Flaws Than Teams Can Triage

The real bottleneck is no longer finding bugs. It is validating them fast enough to keep up, and Anthropic’s Project Glasswing shows AI-assisted discovery is already producing more candidate issues than maintainers can process cleanly. Anthropic says Claude Mythos surfaced more than 10,000 vulnerability candidates across widely used software, with 6,202 tagged high or critical across 1,000+ open-source projects. After analysis, only 1,726 were true positives, and one named example was WolfSSL CVE-2026-5194, a critical flaw that could let an attacker forge certificates and masquerade as a legitimate service. For operators that embed WolfSSL, the risk is not just a CVE count. It is downstream trust failure in TLS and mTLS, plus the lag between discovery, validation, and patch propagation across products that bundle the library.

Part of the PlainSec briefing for 2026-05-25

Sources