AI Has Moved the Bottleneck From Finding Vulnerabilities to Fixing Them

AI Has Moved the Bottleneck From Finding Vulnerabilities to Fixing Them

Images
Authored by
Josh Leclerc
Date Released
18 August, 2026
Comments
No Comments

Anthropic’s Project Glasswing is an early signal of a bigger shift: AI is making vulnerability discovery faster than the security ecosystem can comfortably absorb.

Anthropic’s May 2026 Project Glasswing update is worth paying attention to because it does not read like another vague prediction about artificial intelligence changing cybersecurity. It describes a concrete operational problem: AI can now find serious vulnerabilities faster than people, vendors, maintainers, and customers can verify, disclose, patch, and deploy the fixes.

That is the part that matters for defenders. The industry has spent years trying to improve vulnerability discovery. Better scanners. Better code analysis. Better bug bounty programs. Better offensive testing. Project Glasswing suggests that discovery may no longer be the slowest part of the system. In some cases, it may be the easiest part.

What Anthropic reported

Anthropic says that Project Glasswing and approximately 50 partners used Claude Mythos Preview to identify more than 10,000 high or critical-severity vulnerabilities across systemically important software. In its open-source scanning work, Anthropic says Mythos Preview estimated 6,202 high or critical-severity vulnerabilities across more than 1,000 projects.

The more important detail is not the headline number. It is the workflow behind it. Anthropic describes a steep drop-off between finding, triaging, disclosing, and patching vulnerabilities. Several maintainers reportedly asked Anthropic to slow down disclosures because they needed more time to design patches. That is the security ecosystem’s capacity problem made visible.

The old model assumed scarcity at discovery

Most vulnerability management programs were built around an older assumption: finding issues was difficult, so the organization would scan, receive a manageable queue of findings, prioritize by severity, and work through remediation. That model already struggled in real environments. It struggles even more when AI dramatically increases the volume and quality of vulnerability discovery.

This does not mean every AI-generated finding is reliable. It does not mean every organization is suddenly facing thousands of new critical bugs in its own code. It does mean the economics have changed. The marginal cost of finding likely vulnerabilities is dropping. The human cost of proving them, fixing them, testing them, communicating them, and deploying patches has not dropped at the same pace.

That gap creates a dangerous middle period. Vulnerabilities are being found faster. Patches still take time. Customers still defer updates. Change control still has windows. Clinical, municipal, manufacturing, and public-sector environments still carry systems that cannot be touched quickly without operational risk. Attackers benefit from that lag.

This is not only a vendor problem

It would be easy for buyers to read the Anthropic update as a software manufacturer issue. Vendors need better secure development. Open-source maintainers need support. Large technology companies need better internal scanning. All of that is true. It is also incomplete.

Every organization that depends on software sits downstream of this shift. If an AI-assisted model finds a flaw in a library, firewall, identity product, remote access system, clinical application, or SaaS platform, the customer still has to understand exposure, validate whether the affected version is present, decide whether compensating controls are needed, and deploy the fix when it arrives.

The Government of Canada’s patch management guidance describes patching as a process for assessing, acquiring, testing, prioritizing, deploying, and validating fixes. The word “prioritizing” becomes more important in this new phase. A team that cannot distinguish internet-facing, identity-adjacent, business-critical exposure from ordinary backlog noise will drown in findings before it reduces meaningful risk.

Open source is where the pressure shows first

Open-source software sits underneath almost everything. It is in commercial products, cloud services, internal applications, security tools, embedded systems, and developer pipelines. Project Glasswing’s open-source numbers matter because they show the pressure landing where the maintenance model is often the thinnest.

Many maintainers are volunteers or small teams supporting code that critical organizations rely on heavily but fund lightly. When AI increases vulnerability discovery, the open-source ecosystem does not automatically gain more people to reproduce issues, assess severity, design patches, review pull requests, issue advisories, and support downstream users. The finding arrives quickly. The fix still depends on humans with limited time.

For Canadian organizations, this should change the way software dependency risk is discussed. The useful question is not whether open source is safe or unsafe. That framing is too shallow. The better question is whether the organization knows where high-impact dependencies exist, whether those dependencies are still maintained, how quickly updates can be consumed, and what compensating controls exist when upstream patching cannot move fast enough.

The governance question this raises

If AI makes vulnerability discovery abundant, then governance has to decide what gets fixed first. That decision cannot be left to CVSS score alone. It needs exposure context, asset ownership, exploitability, business criticality, dependency depth, data sensitivity, and whether the affected system provides access to identity, remote access, administration, or public-facing services.

The organizations that adapt well will not be the ones with the longest vulnerability reports. They will be the ones that can turn new information into action quickly without creating operational chaos.

What lean teams should do now

For lean IT and security teams, the response should not be building a complex AI vulnerability program. The first step is knowing the systems that would matter most if a serious vulnerability appeared tomorrow. Public-facing services. Remote access. Identity infrastructure. Backup systems. Security tooling. Business-critical SaaS integrations. Internet-exposed applications. Those assets need named owners and faster decision paths than the ordinary maintenance backlog.

Teams should also reduce ambiguity in their dependency picture. Ask what software is externally exposed, what products are running unsupported versions, where open-source components are used in custom applications, and which vendors have clear security advisory and patch notification processes. That inventory will not be perfect. It does need to be usable when a high-impact advisory appears.

What larger organizations should review

For larger environments, Project Glasswing should trigger a review of vulnerability intake capacity. Can the organization absorb a sudden increase in high-confidence vulnerability reporting from vendors, researchers, internal AI scanning, and external advisories? Does the remediation process have an accelerated path for exposed systems? Are exception approvals time-bound? Are compensating controls tracked until proper remediation is complete?

Security teams should also review how software supply chain risk, patch management, and incident response connect. A critical upstream vulnerability is not only a ticket. It may require legal review, vendor communication, business continuity decisions, customer messaging, and monitoring for exploitation attempts. Treating it as a routine patching task is how organizations lose time.

The broader lesson

Project Glasswing does not mean defenders have lost. There is an optimistic version of this story where AI helps vendors, maintainers, and enterprises find and fix serious software flaws before attackers can use them. That outcome is possible. It is also not automatic.

The uncomfortable lesson is that discovery speed is now outpacing remediation capacity. Security programs that measure success by how many findings they identify will look busy while risk accumulates. The more useful measure is whether the organization can make fast, defensible decisions about the small number of findings that truly matter.

AI has not made patching obsolete. It has made slow patching harder to defend.

Sources and further reading

How Arancia Can Help

AI is increasing discovery speed. Organizations need remediation discipline that can keep up.

Arancia helps organizations turn vulnerability information into practical action, with prioritization models that reflect real exposure, business impact, and operational constraints.

  • Vulnerability management program review aligned with exposure, ownership, and remediation authority
  • Internet-facing asset and critical dependency assessment
  • Patch prioritization framework design for lean IT and security teams
  • Software supply chain and open-source dependency governance review
  • Compensating control strategy for systems where immediate patching is not achievable

Arancia helps organizations reduce the gap between finding risk and fixing it. Get in touch.

Subscribe to our monthly security bulletin

By submitting this form, you acknowledge that your personal data will be processed in accordance with Arancia Privacy Policy and Terms of Use.