🔒Anthropic Discovers 225 Bugs, But Only One Exploited
AI finds bugs, but humans still needed for fixes
TL;DR
VulnCheck researcher finds 225 flaws linked to Anthropic, but only one exploited in the wild. AI excels at finding bugs, but fixing them still requires human intervention.
VulnCheck researcher Glasswing has discovered 225 flaws linked to Anthropic's Project Glasswing, but only one has been exploited in the wild. This highlights the limited impact of AI-discovered vulnerabilities. AI models excel at finding bugs, but fixing them is another story. In one study, AI-generated fixes fully resolved vulnerabilities just 26% of the time. The reality is that while AI can uncover a vast number of security flaws, the real challenge lies in the human coordination, triage, and remediation needed to address them.

Key Points
VulnCheck researcher Glasswing found 225 flaws linked to Anthropic's Project Glasswing.
Only one of the 225 vulnerabilities has been exploited in the wild, a critical SQL injection bug in Ghost (CVE-2026-26980).
AI models are excellent at discovering vulnerabilities, but fixing them is another story — only 26% of AI-generated fixes fully resolve issues.
Historically, less than 2% of vulnerabilities get weaponized and used in the wild, highlighting the gap between discovery and exploitation.
The real challenge lies in human coordination, triage, and remediation to address AI-discovered security flaws.
Why It Matters
AI models excel at finding bugs, but fixing them still requires human intervention. If you're managing security for a system, the real challenge isn't just finding vulnerabilities but also fixing them. The 225 flaws discovered by Anthropic highlight the need for robust human oversight and action in security remediation.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,484 builders reading daily.