Signal Scout
Signal Scout | Research | October 2, 2026

When finding vulnerabilities gets cheap

A problem statement, with early data and the questions I'd want answered.

1
Problem statement

What happens when AI can find vulnerabilities faster than anyone can fix them?

What we're seeing

In May 2026, Anthropic reported the first month of Project Glasswing. Its Mythos Preview model found 23,019 potential vulnerabilities across more than 1,000 open-source projects, about 6,202 of them rated high or critical. Independent firms checked 1,752 of the high and critical findings and confirmed 90.6% as real. At the time of the update, 530 had been reported to maintainers and 75 were patched. Some maintainers asked Anthropic to slow its disclosures because they needed more time to write patches. Anthropic's summary: progress "used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch." [1]

Glasswing is the controlled version of this: a gated model, vetted partners and coordinated disclosure. The same capability is also moving into open-weight models, which nobody gates. SignalScout counts 21,232 open-weight models on Hugging Face with their safety guardrails removed or reduced, downloaded over 50 million times in 30 days. [2] Removing guardrails doesn't make a model better at finding bugs, but it removes the refusal mechanism for malicious actors.

Working hypothesis

The constraint in software security is moving from finding vulnerabilities to fixing them, and the time available to fix them is shrinking. Coordinated programs disclose on a schedule maintainers can manage. Someone running an unguardrailed model may not disclose at all.

I could be wrong about this, so these are the questions I'd want answered first.

Questions worth evaluating

  • Can the projects absorb it? SignalScout's map of the AI development stack alone tracks 138 technologies in 17 categories, across 330,153 public repositories. [6] Each has its own dependency tree, and all of it sits on top of the wider open-source supply chain. I haven't seen anyone measure how many of these projects have the maintainers to handle a surge of valid reports.
  • How far behind the frontier are open-weight models at finding vulnerabilities? That gap sets how long the controlled window lasts, and I haven't seen it measured consistently.
  • Do low-severity bugs matter more when AI can chain them? Anthropic showed Mythos Preview chaining two to four Linux kernel vulnerabilities into root access. [3] Traditional severity scores rate bugs one at a time.
  • Is money the constraint? In March 2026, AI labs and large tech companies committed $12.5 million through OpenSSF and Alpha-Omega to help maintainers handle AI-generated security reports. [4] If the real constraint is maintainer time, money only helps where it buys people.
  • Would a national program help? Hack the Pentagon found 138 valid vulnerabilities for $150,000 in 2016, but it covered five websites the DoD owned and could fix. [5] Nobody can assign work to an open-source maintainer.
  • Should the companies that depend most on a project share the work of maintaining it?

Mitigating considerations

  • Mature teams may absorb the volume. Palo Alto Networks' latest release had more than five times its usual number of patches. [1] If that capacity exists beyond the largest vendors, the problem is smaller than it looks.
  • Findings below high severity may turn out to be mostly duplicates or immaterial. Glasswing's independent validation covered high and critical findings, so we don't know yet.
  • Open-weight models may lag far enough behind that the controlled window stays wide.

Why the answers matter

Each question points to a different fix. If maintainer capacity is the constraint, money and people help. If chaining changes what matters, prioritization has to change. If open weights close the gap quickly, the window for any of it is short.

2
References

References

  1. Anthropic, "Project Glasswing: initial update," May 22, 2026. https://www.anthropic.com/research/glasswing-initial-update
  2. SignalScout, "Models with the safety removed or reduced," harvested 2026-09-07. https://signalscout.dev/uncensored
  3. Anthropic, "Claude Mythos Preview's Cybersecurity Capabilities," April 7, 2026. https://www.anthropic.com/research/mythos-preview
  4. OpenSSF, "Leading Tech Coalition Invests $12.5 Million Through OpenSSF and Alpha-Omega to Strengthen Open Source Security," March 17, 2026. https://openssf.org/?p=9804
  5. Belfer Center, "The Pentagon's First Bug Bounty Exceeded All Expectations." https://www.belfercenter.org/publication/pentagons-first-bug-bounty-exceeded-all-expectations
  6. SignalScout, "The AI development stack, mapped," indicator set 0.9.2. https://signalscout.dev/taxonomy