{"id":13469,"date":"2026-06-09T05:03:46","date_gmt":"2026-06-09T05:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/anthropics-project-glasswing-update-html\/"},"modified":"2026-06-09T05:03:46","modified_gmt":"2026-06-09T05:03:46","slug":"anthropics-project-glasswing-update-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/anthropics-project-glasswing-update-html\/","title":{"rendered":"Anthropic\u2019s Project Glasswing Update"},"content":{"rendered":"\n<div>Anthropic\u2019s Project Glasswing Update<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In April, Anthropic initated <a href=\"https:\/\/www.anthropic.com\/glasswing\">Project Glasswing<\/a>. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic\u2019s claims that it\u2019s now common wisdom that Mythos is better at finding software vulnerabilities than other models. Which is just <a href=\"https:\/\/www.theguardian.com\/commentisfree\/2026\/may\/08\/how-dangerous-is-anthropics-mythos-ai\">not<\/a> <a href=\"https:\/\/spectrum.ieee.org\/ai-cybersecurity-mythos\">true<\/a>.<\/p>\n<p>In any case, Anthropic has <a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\">published<\/a> a Project Glasswing status report. It\u2019s finding <a href=\"https:\/\/www.securityweek.com\/anthropic-mythos-detected-23000-potential-vulnerabilities-across-1000-oss-projects\/\">a lot<\/a> of vulnerabilities in software\u2014yay! Some of them are even dangerous. But almost none of them has been patched. It\u2019s <a href=\"https:\/\/www.flyingpenguin.com\/mythos-grading-mythos-got-patches-yet\/\">weird<\/a>. There\u2019s something fishy about the data that I don\u2019t understand. That Anthropic refuses to release details\u2014that it just says \u201ctrust us\u201d\u2014is a <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2026\/04\/mythos-and-cybersecurity.html\">big problem<\/a> here.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2026\/06\/anthropics-project-glasswing-update.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Anthropic\u2019s Project Glasswing Update In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic\u2019s claims that it\u2019s now common wisdom that Mythos is better at [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,57,476,1,416],"tags":[87],"class_list":["post-13469","post","type-post","status-publish","format-standard","hentry","category-ai","category-bruce-schneier","category-patching","category-uncategorized","category-vulnerabilities","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13469"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13469"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13469\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}