Project Glasswing tracker logs 225 CVEs credited to Anthropic, under 0.5% exploited in the wild
xeophon · x · 2026-09-21
The GitHub project Anthropic-Credited-CVEs tracks vulnerabilities credited to Anthropic's research team under Project Glasswing, now counting 225 CVEs, organized by vendor, CVSS score, and disclosure ledger with community-maintained updates.
Its companion stats deliver a counterintuitive finding: fewer than 0.5% of CVEs are exploited in the wild. The project also collects a series of observations evaluating whether Glasswing's disclosure record this year lives up to the hype.
More from Safety
- Agent Attack Paths Measured: Browser Content Leaks 11/12, MCP Config 8/8, Shell 0/14 — DaimoNNN · 2026-09-21
- Education as an AI safety frontier: cultivating human judgment against uncontrollable AI — bttyeo · 2026-09-21
- The "AI Sandbox Escapes" Were Sloppy Firewall Failures, Not Air-Gap Breaks — PithyCyborg · 2026-09-21
- Internal Bot Audit Reveals AI Agents Run With Far More IAM Access Than Needed — Careless_Sabfey_4906 · 2026-09-21
- New model's vuln stats look same as before: many found, few exploited in the wild — xeophon · 2026-09-21
- US and China Discuss Alerting Each Other to AI National Security Threats — Wired AI · 2026-09-21