Analysis

AI safety is shifting from “finding vulnerabilities” to “digesting vulnerabilities”: what does this set of Anthropic data show?

AI Is Bringing Software Security into an “Infrastructure Phase”

The most noteworthy aspect of the latest progress announced by Anthropic’s Project Glasswing is not “how many vulnerabilities were found,” but that the security production function is being rewritten. In its first month after launch, Claude Mythos Preview found more than 10,000 high-severity or critical vulnerabilities across partner organizations and more than 1,000 open-source projects; at the open-source-project level alone, it flagged 23,019 potential vulnerabilities, of which 6,202 were estimated to be high-severity or critical.

These numbers mean that vulnerability discovery itself is shifting from work that relies heavily on human experience, penetration-testing cycles, and fragmented bounty programs into a capability that can be scaled, scanned continuously, and embedded into development workflows. For today’s digital infrastructure, this is not merely an “upgrade to security tools,” but a change in how critical systems are governed.

The Real Bottleneck Has Already Shifted from “Finding” to “Fixing”

Anthropic’s judgment in its update is straightforward: software security progress used to be constrained by the speed of finding vulnerabilities, but now it is constrained by the speed of validation, disclosure, and remediation. This conclusion is familiar in engineering and infrastructure sectors.

Whether it is port automation systems, power-grid dispatch platforms, rail transit control software, or the foundational management layers of data centers, what truly determines the exposure window of risk has never been just the ability to discover defects, but whether the patch pipeline can be absorbed quickly:

  • whether triage can be completed without disrupting production continuity;
  • whether responsibility boundaries can be clearly defined and disclosure completed;
  • whether there are enough people to design patches for different versions and dependency relationships;
  • whether releases, testing, and rollbacks can be synchronized across a complex supply chain.

Anthropic noted that, on average, a high-severity or critical vulnerability takes two weeks from discovery to patching. That timescale may seem reasonable for traditional software, but for code stacks already embedded in critical infrastructure, it means the risk window is still too long. AI has improved discovery efficiency, but it has also concentrated pressure on maintainers, open-source communities, and enterprise security teams.

This Is Not the Achievement of a Single Product, but a Stress Test of the Global Software Supply Chain

From the perspective of engineering capital, this event looks more like a stress test of the global software supply chain. Anthropic disclosed that, among 1,752 high-severity or critical findings reviewed by six independent security research organizations, more than 90% were confirmed as true positives, and more than 62% of those were confirmed to be truly high-severity or critical. This shows that frontier models already have quite high effectiveness in large-scale scanning.Some of the results disclosed by partners also show an order-of-magnitude jump in vulnerability discovery rates: Cloudflare identified about 2,000 vulnerabilities in critical-path systems, of which 400 were rated high or critical; Mozilla, during testing, fixed 271 vulnerabilities in Firefox 150, significantly more than the number found in earlier versions with assistance from early models.

What these cases have in common is this: AI is not just helping “find bugs,” but reshaping the cadence of software maintenance for enterprises. For large digital platforms, cloud service providers, browser vendors, and critical infrastructure operators, this capability is equivalent to upgrading security audits from sample checks to continuous inspections.

For the infrastructure industry, code security is becoming an “implicit public works” project

Over the past decade, the digitalization of infrastructure first showed up in the networking of control systems, ticketing systems, energy management systems, logistics platforms, and urban central systems. Today, the significance of software security has expanded from an internal IT matter to a kind of implicit public works capability.

The reason is that the operation of more and more “physical infrastructure” depends on software:

  • Port container scheduling relies on operating systems, databases, and communication protocols;
  • Railway signaling, train control, and asset management systems rely on complex software stacks;
  • Power grids and energy storage facilities rely on remote monitoring and edge control;
  • Data centers rely on virtualization, identity authentication, and patch management systems;
  • Urban public service systems rely on third-party open-source components.

When AI can discover defects in these systems at greater speed, what the industry sees is not an abstract “cybersecurity advance,” but a simultaneous rise in the fiscal, organizational, and operational pressure of digital infrastructure governance. In other words, the long-term resilience of infrastructure increasingly depends on the weakest link in the software supply chain.

Patch speed is becoming a new competitive variable

Anthropic disclosed that some partners requested that vulnerability disclosure be slowed down because they needed more time to design patches. The company then even began, in some cases, disclosing vulnerabilities without prior verification in order to accommodate maintainers’ requests.

The industry implication here is very clear: when vulnerabilities are discovered faster than the community and enterprises can patch them, security governance shifts from “scarcity of discovery” to “scarcity of digestion.” This is very similar to the logic commonly seen in infrastructure investment—projects are not stalled because there is no demand, but because approval, financing, construction, and grid-connection capacity cannot keep up.

In the software world, the new constraints are no longer scanning capability, but:

1. whether maintainers can absorb the information flow; 2. whether enterprises can quickly prioritize; 3. whether vendors can continuously release fixed versions; 4. whether institutions have end-to-end asset visibility.This is also why Anthropic has moved Claude Security into public beta and launched the Cyber Verification Program: what enterprise markets truly need is no longer just more powerful models, but accompanying governance tools, permission boundaries, and verification mechanisms.

Security issues in critical software are, in essence, systemic problems of global interconnectedness

One detail in Anthropic’s case is also worth noting: its model helped identify and stop a $1.5 million fraudulent wire transfer involving the compromised email account of a customer at an unnamed bank. This example shows that the consequences of vulnerabilities and attacks are no longer limited to the software product itself; they quickly spill over into financial transactions, account authentication, and business continuity.

This is exactly the most important link between critical software security and infrastructure security. A vulnerability in an overlooked open-source library may ultimately affect banks, airports, ports, energy companies, and even government service platforms. The deeper global interconnectedness becomes, the greater the externalities of any single-point defect.

In this sense, the maturation of AI security capabilities will drive two parallel changes:

  • On one hand, enterprises and governments will place greater emphasis on dependency governance, patch cadence, and asset inventories;
  • On the other hand, institutions with stronger security capabilities will receive a lower systemic risk premium.

This is very similar to the logic of project finance: the earlier risks are identified, the more controllable the cost of capital; the more transparent the governance, the more stable the long-term operations.

Implications for future engineering capital

If we place Anthropic’s progress within the broader infrastructure landscape, it corresponds to global engineering capital entering a “digital foundation first” phase. Today’s new projects, whether ports, railways, data centers, or urban utility systems, are increasingly inseparable from software stacks, cloud platforms, and remote control systems.

This means that future infrastructure investment due diligence will no longer focus only on geology, construction, grid connection, and contract terms; it will also increasingly pay attention to:

  • whether the software dependency chain is traceable;
  • whether suppliers have sustained patching capabilities;
  • whether there are long-unpatched exposures in open-source components;
  • whether control systems have least-privilege and rapid isolation capabilities;
  • whether the project company has established security governance processes suited to the AI era.

At this level, what Anthropic demonstrates is not an isolated AI security technology, but a broader trend: infrastructure competition is extending into the code layer, protocol layer, and update layer. Whoever can discover problems faster, verify them faster, and fix them faster will be closer to true system resilience.

ConclusionMythos Preview discovered more than 10,000 high-risk or critical vulnerabilities, which certainly represents a leap in AI security capabilities. But more importantly, it reveals an industry reality: in critical software and digital infrastructure, the scarcest resource is no longer the ability to “see risk,” but the organizational capacity to “handle risk.”

For engineering firms, infrastructure operators, government digitalization departments, and investment institutions, this shift will directly affect project delivery, asset operations, and long-term capital costs. In the years ahead, infrastructure competition will not only be a competition of steel, concrete, railways, and power grids, but also one of patching speed, supply chain visibility, and system resilience.

SEO Description

Anthropic announced that Claude Mythos Preview found more than 10,000 high-risk or critical vulnerabilities in one month, showing that AI is advancing software security from “finding vulnerabilities” to “digesting vulnerabilities.” From the perspective of global infrastructure, digital supply chains, and project governance, this article analyzes the long-term impact of this change on ports, power grids, data centers, rail transit, and engineering capital.

Source URL

https://opentools.ai/news/anthropic-mythos-finds-10000-flaws

Reference trail · globalinfrareview

globalinfrareview frames this note through Projects / Investment / Energy & Utilities. Projects / Investment / Energy & Utilities explains the local editorial angle; Source links should be opened before the summary is reused (dates, names and status changes still need checking).

Source links

  1. https://opentools.ai/news/anthropic-mythos-finds-10000-flawsPrimary

Related articles

Back to channel