Desk live·
ForensicPost
AI/Vulnerabilities/File 26-0404

Autonomous Vulnerability Research Reported 10,000 Critical Findings in Open Source

A twelve-organisation coalition using autonomous vulnerability research reported more than ten thousand high- and critical-severity findings across systemically important open-source software in a single month.

Constructed geometry · not a chart of case data
TargetOpen-source software estate
ActorResearch consortium
D. Kennedy14 min readConfidence: high3 sources reviewed

Project Glasswing is a coalition of twelve technology organisations — reported partners include AWS, Apple, Microsoft, Google, Cisco, CrowdStrike, NVIDIA, Palo Alto Networks, Broadcom, the Linux Foundation and JPMorgan Chase — applying an Anthropic model to autonomous vulnerability research. In its first month it reported discovering more than ten thousand high- and critical-severity vulnerabilities across systemically important open-source software.

Reported findings include remote code execution flaws and privilege escalation chains across major operating systems, browsers, and foundational libraries including FFmpeg and the Linux kernel.

This Is A Change In Rate, Not In Kind

Automated vulnerability discovery is not new. Fuzzing has been finding memory-safety defects at scale for two decades, and large projects have run continuous fuzzing infrastructure for years.

What is reported here is different in throughput and in reach. Fuzzing finds crashes and requires human analysis to determine whether a crash is exploitable. Findings at this volume, characterised as complete exploitation chains, compress the step that used to be the constraint.

The Disclosure Problem Is The Story

Ten thousand findings against open-source software is not straightforwardly good news, and the coalition’s own reporting makes that clear. Of approximately 1,596 vulnerabilities disclosed to maintainers as of May 2026, around 97 had been patched — a remediation rate near six per cent, filed separately at 26-0410.

A vulnerability that has been found and disclosed but not fixed is in a worse state than one nobody knew about, because the knowledge exists and the defence does not.

What The Funding Indicates

Reported alongside the project are up to $100 million in compute credits and $4 million in grants directed at open-source security groups. The ratio is worth noticing: the discovery side is resourced at roughly twenty-five times the remediation side.

That is not a criticism of the grants, which are real money into an under-funded area. It is an observation that the capability being scaled and the capacity needed to absorb its output are being funded on very different orders of magnitude.

How we reported this

Compiled from the coalition’s published material and independent analysis, listed below. Finding counts originate with the project and its partners; we have not independently verified them, and note that the organisation publishing them has a commercial interest in the capability. We have not reviewed any vulnerability data. Corrections: corrections@forensicpost.com.

Sources
  1. Project Glasswing: an initial updateAnthropic
  2. Project Glasswing: AI discovery outpaces open source patching capacityCloud Security Alliance
  3. Project Glasswing proved AI can find the bugs. Who’s going to fix them?The Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary