AI-assisted vulnerability research is contributing to a sharp rise in disclosed high- and critical-severity software flaws, with monthly totals reportedly climbing from fewer than 100 to more than 600. Anthropic's Project Glasswing reportedly identified over 10,000 high- or critical-severity issues, while exploitation of disclosed vulnerabilities is increasingly occurring on the day of disclosure or earlier, making patch cycles measured in weeks inadequate.
Okta used pre-release OpenAI and Anthropic frontier models through the Daybreak Cyber Partner Program and Project Glasswing to scan high-priority customer-installed software across hundreds of repositories. Its testing found that autonomous agents frequently generated false positives or overstated severity, while expert-led investigation, manual reproduction, and triage substantially improved results. VMware similarly prioritized fixes found after adopting Claude Mythos and Project Glasswing, releasing VCF 9.1.1 as a security-focused update and delaying planned VCF 9.2 features.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Reported high- and critical-severity vulnerability disclosures reached roughly 2,500 in July, nearly five times the pre-Mythos baseline and 60% above the June total.
By June, 21 named technology organizations, including Microsoft, Google, Apple, Adobe, Oracle, Cisco, and IBM, had disclosed approximately 1,500 high- and critical-severity CVEs. The reported total was more than 3.5 times the previous monthly record.
Epoch AI data indicated that public disclosures of high- and critical-severity vulnerabilities by major technology companies began increasing sharply in spring 2026, rising from a baseline of a few hundred per month toward more than 600.
VMware unveiled the major Cloud Foundation 9.0 release.
Okta used OpenAI's GPT 5.5 Cyber Preview and Anthropic's Mythos Preview through the Daybreak Cyber Partner Program and Project Glasswing to scan hundreds of repositories and millions of lines of code. Human Product Security engineers triaged, reproduced, and reported potential vulnerabilities, finding that expert-guided investigations improved results over autonomous scanning.
Anthropic's AI-powered Project Glasswing vulnerability-discovery effort reportedly surfaced more than 10,000 high- or critical-severity vulnerabilities, many of which had not yet been individually disclosed.
VMware made Cloud Foundation 9.1.1 generally available, consolidating security patches associated with vulnerabilities identified through Anthropic Claude Mythos and Project Glasswing. Broadcom deferred planned VCF 9.2 feature work to prioritize remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
sec.okta.com
Open sourcecybersecuritynews.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.