CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Mythos found thousands of critical bugs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 184

As cited

Copy frozen at (site build).

research

Risky Bulletin: Mythos found thousands of critical bugs

Anthropic's Mythos AI model, part of Project Glasswing, identified over 23,000 vulnerabilities across more than 1,000 open-source projects in six weeks. Of these, approximately 6,200 have been rated as high or critical severity, with over 1,500 already confirmed as legitimate issues and nearly 100 patched. The company estimates the confirmed critical bugs could reach 3,900 as analysis continues.

Why it matters: Open-source maintainers and organizations using these projects need to prioritize identifying and patching the confirmed critical vulnerabilities in their dependencies, as Anthropic's analysis suggests widespread exposure in the ecosystem.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Risky Bulletin: Mythos found thousands of critical bugs

Anthropic's Mythos cybersecurity model identified more than 23,000 vulnerabilities across over 1,000 open-source projects six weeks after launching Project Glasswing. Of these findings, 6,202 vulnerabilities carry high or critical severity ratings, with 1,500 confirmed as legitimate issues and nearly 100 already patched; the company anticipates this confirmed count could reach 3,900 as analysis continues.

Why it matters: Open-source maintainers and organizations using these projects need to prioritize reviewing and patching confirmed vulnerabilities in their dependencies, as thousands of critical issues are being systematically identified and disclosed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary