惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
Engineering at Meta
Engineering at Meta
量子位
A
About on SuperTechFans
阮一峰的网络日志
阮一峰的网络日志
Recent Announcements
Recent Announcements
博客园 - 司徒正美
V
Visual Studio Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
腾讯CDC
Jina AI
Jina AI
C
Check Point Blog
H
Help Net Security
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
爱范儿
爱范儿
I
InfoQ

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
Claude Mythos AI Identified 10,000+ Software Vulnerabilit...
Deeba Ahmed · 2026-05-26 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Artificial intelligence safety startup, Anthropic, recently shared the first results of a new program called Project Glasswing. Launched in April 2026, the defensive initiative tests a highly capable, unreleased AI model named Claude Mythos Preview to find security weaknesses in the software.

Huge Number of Flaws Discovered in Free Software

Initial data shows the AI is fast at finding flaws. In just one month, Anthropic and its 50 restricted partners identified more than 10,000 high- or critical-severity security gaps across major software systems.

Anthropic also used the tool to check over 1,000 open-source software projects. This refers to free, public code under the hood of billions of everyday devices. Over 23,000 total potential bugs were spotted, and to cross-verify the findings, six independent security research firms examined the data. External experts confirmed 1,726 real flaws, including around 1,000 high-risk issues. Anthropic believes the final count of severe bugs will reach 6,200 as checking continues.

One major discovery happened inside wolfSSL, an open-source security library used by five billion smart gadgets and routers to encrypt data. The AI discovered a critical certificate forgery flaw, now officially catalogued as CVE-2026-5194. It has a high severity rating of 9.3 out of 10, though the research firm Red Hat rates it a maximum 10.

The AI even built a mock attack demonstrating how cybercriminals could exploit this flaw to forge digital identities and host fake bank websites that appear perfectly real to regular users.

The dashboard of open-source vulnerabilities, showing vulnerabilities of all severities (Source: Antrhopic)

Tech Companies Face a Huge Fix-It Backlog

Finding flaws is now much quicker than fixing them, creating a backup for human teams. While the average time to patch a bug is two weeks, several tech companies are using the data to clean up their applications:

 Cloudflare found 2,000 bugs across its systems.

  • Mozilla fixed 271 flaws in its Firefox 150 web browser, a massive jump from what older AI tools found in Firefox 148.
  •  Palo Alto Networks, Microsoft, and Oracle are rolling out fixes much faster than their usual speed.
  • Apart from software testing, the AI helped a partner bank stop a fraudulent 1.5-million-dollar wire transfer after an unknown hacker took over a customer’s email and made spoof phone calls.

Because this AI model is powerful, Anthropic is keeping it private to prevent threat actors from using it offensively. However, the company plans to expand the program to the UK and US governments while humans work on patching the thousands of security gaps already found.