Bonum Certa Men Certa

Akira Urushibata on Misleading Numbers From Anthropic's Project Glasswing (False Marketing by FUD Tactics)

posted by Roy Schestowitz on May 29, 2026

Posted yesterday and approved a short while ago by the libreplanet-discuss moderator:

Anthropic / Project Glasswing published a report on May 22.  (I was
not aware of this when I sent out my last message to this list, dated
May 26.)

https://www.anthropic.com/research/glasswing-initial-update https://red.anthropic.com/2026/cvd/
I find the numbers in this report hard to digest. There are some loose ends. Notably, in the middle it gives a chart with several boxes summarizing the process, which is unfortunately inconsistent with the text.
Here is my interpretation:
Over the last several months over 1000 "open source" packages were scanned and Mythos reported 23019 problems. Mythos marked 6202 of them as high or critical severity (which implies that 16817 were medium or low severity.)
Security firms and Anthropic staff examined 1752 of the 6202 packages (which implies that 4450 were not examined by them.) Of the 1752 examined 1092 were confirmed to be positive. 1092 / 1752 = 0.623 or 62.3% By applying this ratio to 6202 packages we arrive at an estimate of 3866 problems of high or critical severity.
For 530 of the 1092 vetted vulnerabilities, notices were sent to maintainers (which implies that for 562 confirmed vulnerabilities disclosure is pending.) Of the 530 problems 75 have been patched by developers.
The numbers 1900, 1726 and 467 which appear in the summary chart do not appear in the text.
On April 7th Anthropic announced that "Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." What is the relation between the "thousands" and the figures given above? The figures in the recent report include vulnerabilities found after April 7th and do not include problems in proprietary software.
Maintainers were informed of 530 vulnerabilities and 75 were patched. That means 455 have not been patched. What is the breakdown here? Often it takes time for maintainers to respond. But there may be cases in which the maintainers believe that the problem has been wrongly attributed. In other cases maintainers may claim that the problem has already been solved. The report gives us no information on feedback from developers.
The cURL developer was notified of 5 issues. Are these 5 a subset of the 530 confirmed vulnerabilities?
Mythos finds a curl vulnerability by Daniel Stenberg https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
Note that this article is about cURL's encounter with the Linux Foundation while the recent report is from Anthropic.
---
The following is a message from Linus Torvalds recently posted to the Linux kernel development list:
May 17 2026 https://lwn.net/Articles/1073192/
...
Some of the documentation updates might be worth highlighting: the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools. People spend all their time just forwarding things to the right people or saying "that was already fixed a week/month ago" and pointing to the public discussion. Which is all entirely pointless churn, and we're making it clear that AI detected bugs are pretty much by definition not secret, and treating them on some private list is a waste of time for everybody involved - and only makes that duplication worse because the reporters can't even see each other's reports. AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make-believe work. Feel free to use them, but use them in a way that is productive and makes for a better experience. The documentation may be a bit less blunt than I am, but that's the core gist of it. So just to make it really clear: if you found a bug using AI tools, the chances are somebody else found it too. If you actually want to add value, read the documentation, create a patch too, and add some real value on *top* of what the AI did. Don't be the drive-by "send a random report with no real understanding" kind of person. Ok?
Linus
The Anthropic / Glasswing report does not tell us how many of the 530 problems disclosed were already known to the the developers.
---
The following blog page also discusses numbers in the Anthropic / Glasswing report. I do not agree with the interpretation of the figure 1752 found in this analysis.
Mythos Grading Mythos: Got Patches Yet? https://www.flyingpenguin.com/mythos-grading-mythos-got-patches-yet/

How much of the media merely parroted whatever Anthropic claimed about its secret data? More importantly, how much of this media got paid by Anthropic? This giant Ponzi scheme is based upon or built around plagiarism and abundance of mostly useless data. It has budge allocated to PR and devoted/reserved for "marketing" (buying positive press coverage). Always remember that!

You cannot trust their "products" (LLM slop) and their executives any more than people who tried to sell NFTs.

Other Recent Techrights' Posts

Censorship of Information Unflattering to IBM (or GAFAM)
Years ago we gave a platform to a censored Microsoft whistleblower
Silent Layoffs at Microsoft in 2026
Time will tell is there are investigative journalists out there who will quit parroting Microsoft (e.g. false layoff figures) and relying on LLMs controlled by Microsoft to spew out false "facts" for them
SLAPP Censorship - Part 91 Out of 200: Legal Aid in Support of Freedom of the Press and British Women (Attacked by Americans)
bolstered by prominent counsels
Codecs and Software Patents - Part XII - GNU's Web Site Will Soon Have Many Recent Talks by Chief GNUisance Richard Stallman (RMS)
GNU videos being transcoded or converted into AV1
The Fall of Slop (Even Microsoft Admits There's a Problem)
If Microsoft admits that slop is too expensive and is for "entertainment purposes" because it cannot be relied upon, why would anyone other than the pushers and profiteers still insist that slop bears potential?
 
Links 29/05/2026: "Spyware Economy" and Cuba's Energy Crisis
Links for the day
Gemini Links 29/05/2026: Rap Rant and LLMs Criticised
Links for the day
Akira Urushibata on Misleading Numbers From Anthropic's Project Glasswing (False Marketing by FUD Tactics)
Posted yesterday and approved a short while ago
[Video] Richard Stallman's Rapperswil (Switzerland) Talk Online
accessible without proprietary software
Trusting Trust is an Old Issue, Predating Rust and LLM Slop by Over Half a Century
Microsoft Lunduke wants to make a case against Rust and slop (LLMs), but the issues he addresses aren't exactly new or unique
California Should Have Abandoned So-called 'Age‑Verification Laws', Not Make Exemptions (for Now)
This has nothing to do with 1) children 2) safety 3) safety of children
Links 29/05/2026: Cory Doctorow on Why the Internet Feels So Broken, American Pope on Defederation
Links for the day
Techrights Does Not Censor Information About IBM, It Platforms and Retains Suppressed Voices From Inside IBM
They don't like it when people criticise the management [...] panic attacks mentioned
Bob (Robert) Cringely Devoted Three Years of His Life Trying to Profit From LLM Slop and Now He Sounds Off, It's Just Not Working and It Can Crash the Economy Soon
"The labs raising money at valuations with too many zeros are happy"
Techrights After About 60,000 Articles in 20 Years
Sites fail if they don't offer anything new or if they wrongly believe that adopting slop to parrot other sites will give them exposure
Organised Plunder or Robbery: GAFAM and Hardware Companies Rely on Media Bribery to Perpetuate False Narratives and to "Drive Sales" (and Drive Prices Upwards)
The price-fixing seems plausible and, if so, we need to demand action
Linux Foundation Destroys the Identity and History of Linux
Groklaw's PJ was thorn on the side of LF sponsors
The Problem of Microsoft Crimes
Opposing crime isn't "hatred"
Red Hat Will Die Inside a Dying IBM
IBM isn't where Red Hat came to thrive but where it came to die
Very Large Strike at the European Patent Office Today, "Production" Sank a Huge Deal
At this pace, we might be looking at tens of thousands fewer European Patents being granted this year
Gemini Links 29/05/2026: Leadership and Religion, the Board Game (Second Edition)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 28, 2026
IRC logs for Thursday, May 28, 2026
Links 28/05/2026: Pakistan and Afghanistan Are Still Fighting, Iranians Back Online
Links for the day
"LLMs Are Not Much More Than Plagiarism Engines"
the impact of LLMs on communities and software projects
Is Slop Profitable Yet? No.
Everything is a giant minus
Bob (Robert) Cringely Has Just Explained That After 3 Years of Hard Work It Became Apparent LLM Slop is Unfit for Purpose in Courts
Added moments ago to Daily Links
Links 28/05/2026: LibreSSL 4.3.2, "Jeff Bezos Is Afraid Of What Comes Next", Measles Making a Comeback
Links for the day
PCs That Are Made to 'Expire' and 'Secure' Boot Contributing to Planned Obsolescence
People who are responsible for this ought to be held accountable
Evil, Faceless Corporation: Google Steals Money From You If You Don't Purchase an Android Device for MFA
At this point, under the guise of "hey hi" (slop) Google is firing tens of thousands of workers
People Go Back to Basics, Abandon Microsoft's GitHub to Avoid Slop
The media didn't pay any attention to GitHub's de facto chief quitting Microsoft only a few months ago
SLAPP Censorship - Part 90 Out of 200: When Efforts to Silence His Spouse and Also the Wife of a Blogger in Another Continent Only Give More Exposure to Embarrassing Information
The Garrett trial ended in October 2025
IBM - Much Like the European Patent Office (EPO) - Gives the President (Head of Board and CEO) All the Money While Staff Drowns in High Inflation Rates
They're discussing the same sort of thing we often see mentioned in the EPO
"THE REGISTER EXPLAINER" as "Paid-for SPAM" at The Register MS With "AI" 40 Times in the Short Page
What will be left of The Register MS in a few years?
2025: EPO President Campinos Breaks the Cookie Jar, Steals Another Million Euros While His "Brother-in-Law" Does Cocaine at the Office and Staff Prepares Rolling, Indefinite Strikes
any additional month of Campinos in charge of the EPO is a liability not just to the EPO but the EU as well
Gemini Links 28/05/2026: Dumping Microsoft GitHub, Gopher Rabbit Hole
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 27, 2026
IRC logs for Wednesday, May 27, 2026
Links 27/05/2026: TSMC Workers Next to Consider Strikes, Ceasefire Cracking
Links for the day
SLAPP Censorship - Part 89 Out of 200: SRA Admits Malfunction, That's Why Transparency is Paramount
There have been more efforts than we can to count or can enumerate (probably over 100 such efforts) to gag us and to prevent us writing about what has happened
Our Free Software Activist in Connecticut (USA)
We'll soon revisit the latest round of legislation on "age" (surveillance, ID)
Links 27/05/2026: Living Without 'Smartphoones' and "Russia’s Biggest Attack on Ukraine in 18 Months"
Links for the day
Gemini Links 27/05/2026: The USA as an "Experiment" and Some Ubuntu Manuals
Links for the day
[Video] Full Video of Richard Stallman's Talk in Rome
It seems inevitable that the official GNU site will have it
Slop is a Passing Fad, It's About Faking Productivity (Plagiarism, Misinformation, and False Positives)
Slop is a bubble. Some people accept it later than others.
Anderon - Like Kyndryl - Could be Far Deeper in Debt Than Its Alleged Worth (Vapourware)
Time will tell, but it seems like a Federal-enabled (by the Federal Government) accounting scam, nothing more, nothing less
The Media That Keeps Covering "AI" Because the Pushers of It Pay for Spam
23 times in the page they mention "AI"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 26, 2026
IRC logs for Tuesday, May 26, 2026
Codecs and Software Patents - Part XI - The Stance of RMS (Dr. Stallman) Reassured GNU Regarding AV1
cautioned against software patents since the early 90s if not earlier