Thursday, Oct 8 | --:--
Back to home

Glasswing’s First Numbers: 2,100+ Vulns Patched — Vendor Metrics, Real Partner Velocity

Anthropic’s first Project Glasswing update: Claude Opus 4.7 helped patch >2,100 vulnerabilities in three weeks; Claude Security public beta for Enterprise; disclosure dashboard at 1,596 findings / 97 remediated. Palo Alto claims 5× more patches — partner self-reports, not independent audits.

Times of AI Desk 6 min read San Francisco, CA View as Markdown
Cover illustration for Glasswing’s First Numbers: 2,100+ Vulns Patched — Vendor Metrics, Real Partner Velocity

Frontier cyber capability is dual-use by design. Glasswing’s wager is that restricted defender access can produce measurable patch velocity before the same class of models is generally available — and this is the first public scorecard.

Anthropic (May 22) published an initial update on Project Glasswing, its collaborative effort to secure critical software using restricted access to advanced Claude models (Opus 4.7, Mythos). In the three weeks since launch, Claude Opus 4.7 has been used to patch over 2,100 vulnerabilities. The update includes the public beta of Claude Security for Enterprise customers, a coordinated vulnerability disclosure dashboard with 1,596 disclosed findings as of May 22, and partner reports of accelerated patching (Palo Alto Networks 5× more patches; Microsoft and Oracle cite faster response).

What the update reports

Surface Figure (Anthropic / partners)
Vulns patched with Claude >2,100 in ~3 weeks
Claude Security Public beta for Enterprise — scan, identify, propose fixes
Disclosure dashboard 1,596 disclosed; 1,451 acknowledged; 97 remediated (Mythos Preview OSS scans)
Partner velocity Palo Alto 5× patches; Microsoft, Oracle faster remediation

Access remains restricted to vetted defenders, critical infrastructure providers, and maintainers.

Claims vs checks

Patch counts and dashboard stats are Anthropic primary. Palo Alto’s 5× and Microsoft/Oracle acceleration are partner self-reports — not independent SOC audits. Treat “2,100+ patched” as company-attributed outcomes across the Glasswing cohort, not a global CVE-rate claim.

Limits

  • Three-week window — early, not steady-state.
  • Partner velocity multipliers are self-reported.
  • Upstream remediation (97 of 1,596) lags disclosure — expected, but the gap is the real operational story.

Sources

  • Anthropic: “Project Glasswing: An initial update” (May 22, 2026).
  • Anthropic coordinated disclosure dashboard (red.anthropic.com, as of May 22, 2026).
  • Related coverage confirming update timing and key figures.

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading