GMAsia
    AI News·21 Sept 2026·via The Register

    Anthropic-linked CVEs pile up, attackers mostly shrug

    Anthropic’s Project Glasswing, an initiative using its Claude Mythos Preview model to find software flaws, has identified 225 vulnerabilities since April. Only one of these, a critical SQL injection bug in Ghost (CVE-2026-26980), has seen confirmed exploitation in the wild. This low exploitation rate challenges concerns that advanced AI models will dramatically increase the number of exploited CVEs. Security researcher Patrick Garrity of VulnCheck tracked these vulnerabilities.

    Nexa's Summary

    The low exploitation rate of Anthropic’s AI-discovered vulnerabilities pushes back against AI hype. Of 225 flaws found by Project Glasswing, only one has been exploited in the wild. This suggests that while AI excels at finding bugs, it does not automatically translate to increased real-world threats. The impact of AI on cybersecurity is more nuanced than many assume.

    This finding is important for Asia’s cybersecurity firms and large enterprises. They face pressure to adopt AI for defense, but this data shows that AI’s value is in discovery, not necessarily in preventing exploitation. Companies investing heavily in AI bug-finding tools should balance this with human-led remediation efforts. The human element in fixing and prioritizing vulnerabilities remains critical.

    The thing to watch is whether the ratio of exploited to discovered vulnerabilities changes as AI models improve at identifying more complex flaws. If that single exploited bug remains an outlier, the current human-centric remediation processes will hold. If the rate climbs toward the historical 1 to 2 percent, then the threat landscape changes for Asian firms.

    #security
    Original reporting by The RegisterWe don't republish, read the full story →

    Related reading

    6 stories