Anthropic Glasswing at 5 months: 26,153 findings, only 0.8% fixed so far
terryyuezhuo · x · 2026-09-09
VulnCheck's Patrick Garrity audits Anthropic's Project Glasswing (launched April 7) via its Vulnerability Disclosure Ledger: Anthropic claims 26,153 findings, but only 2,736 (10.5%) reached the public ledger; just 202 (0.8%) are confirmed fixed, 245 (0.9%) withdrawn, and 2,096 (8%) reported to maintainers without confirmed fixes. Five months in, only 9.8% of findings have reached a maintainer — highlighting that validating, coordinating and fixing vulnerabilities still requires human triage, a limitation Anthropic itself acknowledges.
More from Safety
- We added a PII gate before the LLM call: SSNs get a 400 before ever reaching the model — Scholeristical · 2026-09-09
- Muse agent is deliberately decoupled from credentials and network permissions for safety — rohanpaul_ai · 2026-09-09
- Singapore launches world's first governance framework for agentic AI with four accountability pillars — Comfortable_Gene5180 · 2026-09-09
- Meta puts Muse agents under public bug bounty, up to $300K per critical flaw — ThomasScialom · 2026-09-09
- OpenAI and Anthropic rewrite enterprise data policies with zero data retention offers — DeepLearningAI · 2026-09-09
- Alignment researcher reaffirms 2023 essay: AI alignment is fundamentally tractable — QuintinPope5 · 2026-09-09