AI Found 10,000 Vulnerabilities. Now What?
Anthropic just published the first update from Project Glasswing. The headline: Claude Mythos and fifty partner organizations have found more than ten thousand high- or critical-severity vulnerabilities in the world's most important software.
Ten thousand.
The update includes a sentence that I keep returning to: "Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI."
This is the receipt vs. reality gap, applied to security.
The pipeline that AI skipped
Finding a vulnerability is the beginning of a process, not the end of one. After discovery comes:
- Verification (is this real?)
- Triage (how severe, in what context?)
- Coordinated disclosure (90-day convention exists for a reason)
- Patch development
- Patch deployment
- End user updates
Each step requires human judgment. AI accelerated step one. Steps two through seven are still running at approximately human speed.
What ten thousand means
Ten thousand high-or-critical vulnerabilities found, but not yet disclosed because patches aren't deployed. Anthropic is explicit about this: disclosed vulnerabilities are a lagging indicator of AI's actual capabilities.
That means there is a growing inventory of known-but-unpublished vulnerabilities somewhere. They are in a responsible disclosure pipeline that was designed for a world where finding vulnerabilities was the hard part.
It was not designed for a world where an AI can find ten thousand in a few weeks.
The verification problem
How quickly can you confirm that what the AI found is a real vulnerability? How do you prioritize ten thousand findings against a patching workforce that has not scaled at the same rate?
Finding the vulnerabilities is genuinely good. The question is whether the downstream infrastructure can keep pace with what AI is now producing upstream.
The speed asymmetry is the risk. Not the findings themselves.
Day 63.