{"id":48929,"date":"2026-04-23T07:46:34","date_gmt":"2026-04-23T07:46:34","guid":{"rendered":"http:\/\/localhost\/?p=48929"},"modified":"2026-04-23T07:46:34","modified_gmt":"2026-04-23T07:46:34","slug":"project-glasswing-proved-ai-can-find-the-bugs-whos-going-to-fix-them","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=48929","title":{"rendered":"Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-23T11:43:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhkzSPo6TkrJjcTvsuM1O71fiiZ7gnKw4PqqtKu_TeAaZNr5qAEfsfVvoZv64F7EFULRIv8SKePHZehY_0g9AqyqlnMdTPF-OLf1S9RwmB-edOgYKEg1Llw-6m87CQBglHxbK3oS0Brnwc9_x_oi56XGuxe1V9vN0KfoY9cUmU4mplEHeqQxO-5byx79YY\/s1600\/picus-main.jpg)\\n\\nLast week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to **find and patch bugs before adversaries can**.\\n\\nMythos Preview, the model that led to Project Glasswing, **found vulnerabilities across every major operating system and browser.** Some of these bugs had survived decades of human audits, aggressive fuzzing, and open-source scrutiny. One had been **sitting for 27 years** in OpenBSD, generally considered to be one of the world\u2019s most secure operating systems.\\n\\nIt&#8217;s tempting to file this under \\&#8221;**AI lab says their AI is too dangerous,** \\&#8221; the same playbook OpenAI ran with GPT-2. \\n\\nNot so fast; there&#8217;s a material difference this time. \\n\\nMythos didn&#8217;t just find individual CVEs. \\n\\n  * It **chained four independent bugs into an exploit sequence** that bypassed both the browser renderer and the OS sandboxing\\n  * It performed local privilege escalation in Linux through race conditions\\n  * It built a 20-gadget ROP chain targeting FreeBSD&#8217;s NFS server, distributed across packets.\\n\\n\\n\\nClaude Opus 4.6, Anthropic&#8217;s previous frontier model, failed at autonomous exploit development almost entirely.**Mythos hit a 72.4% success rate in the Firefox JS shell**.\\n\\nThis isn&#8217;t theoretical, nor some new three-to-five-year prediction. This is about to be a real-world engineering reality.\\n\\n## **Why Project Glasswing Exposes the Real Cybersecurity Gap**\\n\\nHere&#8217;s the number that should keep security leaders awake at night: **fewer than 1% of the vulnerabilities found by Mythos were patched**.\\n\\nLet that sink in for a moment. \\n\\nThe most powerful vulnerability discovery engine ever built ran against the world&#8217;s most critical software, and the ecosystem couldn&#8217;t absorb the output. \\n\\nGlasswing solved the finding problem. \\n\\nNobody solved the problem of fixing.\\n\\n### **Why Defenders Can&#8217;t Keep Up: Calendar Speed vs. Machine Speed**\\n\\nThis is the structural issue the cybersecurity industry has been circling for years. AI just made it impossible to ignore. \\n\\nDefenders operate on **calendar speed**. They: \\n\\n  * Gather intelligence \\n  * Build a campaign\\n  * Simulate the threats \\n  * Mitigate \\n  * Repeat\\n\\n\\n\\nThat cycle takes about **four days on a good day**. Attackers, especially those now leveraging LLMs at every stage of their operation, are **moving at machine speed**. \\n\\nFor an up-to-the-minute take, David B. Cross, CISO at Atlassian, will be speaking at the Autonomous Validation Summit on May 12 about what this looks like from the inside, why periodic testing can&#8217;t keep pace with adversaries that operate autonomously, and what defenders should be doing instead.\\n\\n### **AI-Powered Attacks Are Already Autonomous**\\n\\nEarlier this year, a threat actor deployed **a custom MCP server hosting an LLM as part of their attack chain** against FortiGate appliances. \\n\\nThe AI handled everything: \\n\\n  * Automated backdoor creation\\n  * Internal infrastructure mapping fed directly to the model\\n  * Autonomous vulnerability assessment, and \\n  * AI-prioritized execution of offensive tools for domain admin access. \\n\\n\\n\\nThe result? **2,516 organizations across 106 countries were compromised** in parallel. The entire chain, from initial access through credential dumping to data exfiltration, was autonomous. The only human involvement was reviewing the results afterward.\\n\\n### **AI-based Vulnerability Discovery Is Outpacing Remediation**\\n\\nThe gap between attacker speed and defender speed isn&#8217;t new. \\n\\n**What&#8217;s new is that a small but worrisome gap just became a canyon.**\\n\\n  * Autonomous systems like AISLE discovered 13 out of 14 OpenSSL CVEs in recent coordinated releases, bugs that had survived years of human review. \\n  * XBOW became the top-ranked hacker on HackerOne in 2025, surpassing all human participants.\\n  * The median time from disclosure to weaponized exploit dropped from 771 days in 2018 to single-digit hours by 2024.\\n  * By 2025, the majority of exploits will be weaponized  _before_ being publicly disclosed.\\n\\n\\n\\n**Now add Mythos-class discovery to this picture.**\\n\\nYou don&#8217;t get a safer world automatically. You get a **tsunami of legitimate findings that still require human verification** , organizational process, business continuity considerations, and patch cycles that haven&#8217;t fundamentally changed in a decade.\\n\\n## **How to Build a Mythos-Ready Security Program**\\n\\nThe instinct after Glasswing is to ask: \\&#8221;How do we find more bugs?\\&#8221; \\n\\nThat&#8217;s actually the wrong question.\\n\\nThe right one is: \\&#8221;When thousands of exploitable vulnerabilities land on your desk tomorrow morning, **can your program actually process them?** \\&#8221;\\n\\nFor most organizations, the honest answer is no. And the reason isn&#8217;t a lack of tools or talent; it&#8217;s a structural **dependency on periodic** , **human-initiated processes** that were designed for a world where vulnerabilities trickled in, not one where they arrived in a tsunami.\\n\\nWe can&#8217;t fix every vulnerability. We can&#8217;t apply every hardening option. \\n\\n****\\n\\n\\u003e **That&#8217;s not defeatism** , that\u2019s the pragmatic starting point for any security program that actually works. The question that matters isn&#8217;t \\&#8221;is this CVE critical?\\&#8221; but \\&#8221;**is this vulnerability exploitable in my environment, right now, given what I have deployed?** \\&#8221;\\n\\nA Mythos-ready security program needs three fundamental pieces.\\n\\n### **First: Signal-Driven Validation Over Scheduled Testing**\\n\\nWhen a new threat emerges, when an asset changes, or when a configuration drifts, defenses need to be **tested against that specific change in that moment.** Not during the next quarterly pentest. Not when someone can find an open calendar slot. \\n\\nThe entire concept of \\&#8221;scheduled validation\\&#8221; assumes a stable threat landscape, and today, that **assumption is dead on arrival**.\\n\\n### **Second: Environment-Specific Context Over Generic CVSS Scores**\\n\\nGlasswing will produce an avalanche of CVEs. \\n\\nYet most vulnerability management programs are still prioritized by CVSS scores. This context-free metric tells you how bad a bug _could be in theory_ , not whether _it&#8217;s exploitable in your specific infrastructure_ , given your controls and business risk.\\n\\nWhen the volume of findings suddenly goes from **hundreds to thousands** , context-free prioritization won&#8217;t just slow you down; **it\u2019ll break your process entirely**.\\n\\n### **Third: Closed-Loop Remediation Without a Manual Handoff**\\n\\nThe current model can\u2019t survive in a world where adversaries exploit CVEs within hours of disclosure. You know the drill:\\n\\n  * Scanner finds a bug\\n  * Analyst triages it\\n  * The ticket goes to a different team\\n  * Someone patches it weeks later\\n  * Nobody re-validates\\n\\n\\n\\nThat chain of manual handoffs is exactly where the system disintegrates. If the cycle from finding to fix to re-validation can&#8217;t run without humans shuttling tickets between queues, it clearly isn\u2019t running anywhere near machine speed.\\n\\nThis isn&#8217;t about buying more tools. It&#8217;s about defenders leveraging their **one asymmetric advantage** : you know your organization\u2019s topology, **attackers don&#8217;t**. \\n\\nThat&#8217;s a significant advantage, **but only if you can act on it at machine speed.**\\n\\n## **How Autonomous Exposure Validation Closes the Gap \u2014 and Where Picus Comes in**\\n\\nThis is the part where I\u2019m going to be really transparent about who&#8217;s writing this. \\n\\nAt Picus Security, we build a platform for **Autonomous Exposure Validation**. So, full disclosure, I have a perspective here that comes with an inherent bias. Take it accordingly.\\n\\nWhat Glasswing crystallized for us, and for a lot of the CISOs we&#8217;ve been speaking with, is that the**validation step** within any **exposure management program** just became the most critical bottleneck. \\n\\n  * Finding vulnerabilities is about to get radically easier and more efficient \\n  * Patching them is going to remain painfully slow.\\n\\n\\n\\nThe only lever you can pull in between is **knowing which ones actually matter** to your environment. That&#8217;s validation.\\n\\n### **From Four Days to Three Minutes: How Agentic Workflows Change the Cycle**\\n\\nWe built Picus Swarm, the AI team powering autonomous, real-time validation, to compress the traditional four-day cycle into minutes. \\n\\nIt&#8217;s a set of AI agents that work together to do what used to require handoffs between four separate teams: \\n\\n  * A **researcher agent** ingests and vets threat intelligence. \\n  * A **red teamer agent** maps it against your environment to generate a safety-checked attacker playbook. \\n  * A **simulator agent** executes across your actual endpoints and cloud, gathering telemetry and proof data. \\n  * A**coordinator agent** bridges findings to remediation, opening tickets, triggering SOAR playbooks, pushing indicators of attack to your EDR, and re-validating after fixes land.\\n\\n\\n\\nEvery action is traceable and auditable, andevery agent operates within guardrails you define.\\n\\nThe whole chain, from a new CISA alert to validated, remediation-ready findings, runs in about three minutes. \\n\\n\\u003e When a **Mythos-class model drops thousands of findings** on your organization, you need something that can immediately tell you **which of these are exploitable in your environment.** Which controls would hold, which would fail, and what&#8217;s the vendor-specific fix? \\n\\n## **The Uncomfortable Truth**\\n\\nProject Glasswing is going to be measured by one metric: how many vulnerabilities get patched before they get exploited. Not how many are found, not how impressive the exploit chains are, but whether the ecosystem can digest what AI is about to produce.\\n\\nVisibility alone has never been enough, 83% of cybersecurity programs still show no measurable results. What\u2019s changing the equation is **closing the gap between seeing and proving:** knowing whether a potential vulnerability **would actually compromise your environment.**\\n\\nThat&#8217;s validation.\\n\\nAnd in a post-Glasswing world, it&#8217;s the only thing standing between a flood of discoveries and a flood of breaches.\\n\\n![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKHpFZNH-Ek72Ur-O89n5p6p5a4WoMoh9Wphnkqdf79P0PfQs6Q_Qsx_0qFcC9qubPoTe3wprZKk23AxTPsLQaG0f16dO07t1P1idOv8-fZtmTdHZbpwnn2uPDG1mKxAi-0Fhj-fT-IQsQ2posCTu0frZS7kjGpTDERNO6rZ1xz7nXb36I6r0PHsP_zTE\/s1600\/picus-webinar.jpg)\\n\\n_We&#8217;re hosting the Autonomous Validation Summit on May 12 \\u0026 14 with Frost \\u0026 Sullivan, featuring practitioners from Kraft Heinz and Glow Financial Services, along with our CTO, Volkan Erturk. Together, we\u2019ll be taking a deeper dive into this specific problem. _\\n\\n_\\u003e \\u003e Register here._\\n\\n_Note: This article was written byS\u0131la \u00d6zeren Hac\u0131o\u011flu, Security Research Engineer at Picus Security._\\n\\nFound this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.\\n&#8221;,&#8221;published&#8221;:&#8221;2026-04-23T11:30:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-23T11:30:00&#8243;,&#8221;type&#8221;:&#8221;thn&#8221;,&#8221;title&#8221;:&#8221;Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;THN:CD2A05D756D4965113B73FC71DADB28E&#8221;,&#8221;bulletinFamily&#8221;:&#8221;info&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/thehackernews.com\/2026\/04\/project-glasswing-proved-ai-can-find.html&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-23T11:43:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhkzSPo6TkrJjcTvsuM1O71fiiZ7gnKw4PqqtKu_TeAaZNr5qAEfsfVvoZv64F7EFULRIv8SKePHZehY_0g9AqyqlnMdTPF-OLf1S9RwmB-edOgYKEg1Llw-6m87CQBglHxbK3oS0Brnwc9_x_oi56XGuxe1V9vN0KfoY9cUmU4mplEHeqQxO-5byx79YY\/s1600\/picus-main.jpg)\\n\\nLast week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,7,11,43,5],"class_list":["post-48929","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-security","tag-tapic","tag-thn","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Project Glasswing Proved AI Can Find the Bugs. Who&#039;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=48929\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Project Glasswing Proved AI Can Find the Bugs. Who&#039;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-23T11:43:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhkzSPo6TkrJjcTvsuM1O71fiiZ7gnKw4PqqtKu_TeAaZNr5qAEfsfVvoZv64F7EFULRIv8SKePHZehY_0g9AqyqlnMdTPF-OLf1S9RwmB-edOgYKEg1Llw-6m87CQBglHxbK3oS0Brnwc9_x_oi56XGuxe1V9vN0KfoY9cUmU4mplEHeqQxO-5byx79YY\/s1600\/picus-main.jpg)nnLast week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=48929\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-23T07:46:34+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E\",\"datePublished\":\"2026-04-23T07:46:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929\"},\"wordCount\":1951,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"Security\",\"tapic\",\"thn\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=48929#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929\",\"name\":\"Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-23T07:46:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=48929\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48929#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=48929","og_locale":"en_US","og_type":"article","og_title":"Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-23T11:43:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhkzSPo6TkrJjcTvsuM1O71fiiZ7gnKw4PqqtKu_TeAaZNr5qAEfsfVvoZv64F7EFULRIv8SKePHZehY_0g9AqyqlnMdTPF-OLf1S9RwmB-edOgYKEg1Llw-6m87CQBglHxbK3oS0Brnwc9_x_oi56XGuxe1V9vN0KfoY9cUmU4mplEHeqQxO-5byx79YY\/s1600\/picus-main.jpg)nnLast week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public...","og_url":"https:\/\/zero.redgem.net\/?p=48929","og_site_name":"zero redgem","article_published_time":"2026-04-23T07:46:34+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=48929#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=48929"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E","datePublished":"2026-04-23T07:46:34+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=48929"},"wordCount":1951,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","Security","tapic","thn","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=48929#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=48929","url":"https:\/\/zero.redgem.net\/?p=48929","name":"Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-23T07:46:34+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=48929#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=48929"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=48929#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Project Glasswing Proved AI Can Find the Bugs. Who&#8217;s Going to Fix Them?_THN:CD2A05D756D4965113B73FC71DADB28E"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/48929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=48929"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/48929\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=48929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=48929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=48929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}