GLM 5.3 finds 2436 unpatched open source vulnerabilities likely missed by Mythos (Project Glasswing)
Summary
GLM 5.3 identified 2436 unpatched open-source vulnerabilities, 1097 rated critical or high, many over 26 years old, in what appears to be Z.ai's counterpart to Project Glasswing.
Similar Articles
@AnthropicAI: Patching these vulnerabilities will make us safer. But the software industry will need to adapt to the volume of vulner…
Anthropic's Project Glasswing has used Claude Mythos Preview to find over 10,000 high or critical severity vulnerabilities in critical software, with partners like Cloudflare reporting a tenfold increase in bug finding rates, highlighting the shift from discovery to patching as the bottleneck.
May 22, 2026AnnouncementsProject Glasswing: An initial update
Anthropic's Project Glasswing, using Claude Mythos Preview, has found over ten thousand high- or critical-severity vulnerabilities in critical software, with partners like Cloudflare reporting a tenfold increase in bug-finding rate.
@logangraham: A lot of people have been wondering about Mythos, Glasswing, and the vulns we / our partners are fixing. Today, I’m exc…
Anthropic's Claude Mythos Preview model has been evaluated by XBOW and UK AISI, showing unprecedented autonomous cybersecurity capabilities, including solving end-to-end cyber ranges and finding thousands of vulnerabilities. The announcement emphasizes the need to prepare for rapidly advancing AI capabilities in cybersecurity.
Project Glasswing: what Mythos showed us
Cloudflare tested Anthropic's Mythos Preview LLM, designed for security vulnerability research, and found it capable of chaining multiple bugs into exploits and generating working proofs, representing a significant advancement over general-purpose frontier models.
Expanding Project Glasswing
Anthropic is expanding Project Glasswing, its collaborative cybersecurity effort, to approximately 150 new organizations across multiple countries and industries, providing them access to Claude Mythos Preview to find vulnerabilities in critical software.