Bonum Certa Men Certa

Akira Urushibata on Misleading Numbers From Anthropic's Project Glasswing (False Marketing by FUD Tactics)

posted by Roy Schestowitz on May 29, 2026

Posted yesterday and approved a short while ago by the libreplanet-discuss moderator:

Anthropic / Project Glasswing published a report on May 22.  (I was
not aware of this when I sent out my last message to this list, dated
May 26.)

https://www.anthropic.com/research/glasswing-initial-update https://red.anthropic.com/2026/cvd/
I find the numbers in this report hard to digest. There are some loose ends. Notably, in the middle it gives a chart with several boxes summarizing the process, which is unfortunately inconsistent with the text.
Here is my interpretation:
Over the last several months over 1000 "open source" packages were scanned and Mythos reported 23019 problems. Mythos marked 6202 of them as high or critical severity (which implies that 16817 were medium or low severity.)
Security firms and Anthropic staff examined 1752 of the 6202 packages (which implies that 4450 were not examined by them.) Of the 1752 examined 1092 were confirmed to be positive. 1092 / 1752 = 0.623 or 62.3% By applying this ratio to 6202 packages we arrive at an estimate of 3866 problems of high or critical severity.
For 530 of the 1092 vetted vulnerabilities, notices were sent to maintainers (which implies that for 562 confirmed vulnerabilities disclosure is pending.) Of the 530 problems 75 have been patched by developers.
The numbers 1900, 1726 and 467 which appear in the summary chart do not appear in the text.
On April 7th Anthropic announced that "Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." What is the relation between the "thousands" and the figures given above? The figures in the recent report include vulnerabilities found after April 7th and do not include problems in proprietary software.
Maintainers were informed of 530 vulnerabilities and 75 were patched. That means 455 have not been patched. What is the breakdown here? Often it takes time for maintainers to respond. But there may be cases in which the maintainers believe that the problem has been wrongly attributed. In other cases maintainers may claim that the problem has already been solved. The report gives us no information on feedback from developers.
The cURL developer was notified of 5 issues. Are these 5 a subset of the 530 confirmed vulnerabilities?
Mythos finds a curl vulnerability by Daniel Stenberg https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
Note that this article is about cURL's encounter with the Linux Foundation while the recent report is from Anthropic.
---
The following is a message from Linus Torvalds recently posted to the Linux kernel development list:
May 17 2026 https://lwn.net/Articles/1073192/
...
Some of the documentation updates might be worth highlighting: the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools. People spend all their time just forwarding things to the right people or saying "that was already fixed a week/month ago" and pointing to the public discussion. Which is all entirely pointless churn, and we're making it clear that AI detected bugs are pretty much by definition not secret, and treating them on some private list is a waste of time for everybody involved - and only makes that duplication worse because the reporters can't even see each other's reports. AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make-believe work. Feel free to use them, but use them in a way that is productive and makes for a better experience. The documentation may be a bit less blunt than I am, but that's the core gist of it. So just to make it really clear: if you found a bug using AI tools, the chances are somebody else found it too. If you actually want to add value, read the documentation, create a patch too, and add some real value on *top* of what the AI did. Don't be the drive-by "send a random report with no real understanding" kind of person. Ok?
Linus
The Anthropic / Glasswing report does not tell us how many of the 530 problems disclosed were already known to the the developers.
---
The following blog page also discusses numbers in the Anthropic / Glasswing report. I do not agree with the interpretation of the figure 1752 found in this analysis.
Mythos Grading Mythos: Got Patches Yet? https://www.flyingpenguin.com/mythos-grading-mythos-got-patches-yet/

How much of the media merely parroted whatever Anthropic claimed about its secret data? More importantly, how much of this media got paid by Anthropic? This giant Ponzi scheme is based upon or built around plagiarism and abundance of mostly useless data. It has budge allocated to PR and devoted/reserved for "marketing" (buying positive press coverage). Always remember that!

You cannot trust their "products" (LLM slop) and their executives any more than people who tried to sell NFTs.

Other Recent Techrights' Posts

Society Will Only Improve Owing to People Who Push Boundaries
Push boundaries with ideas and facts, not with forbidden language
Digital Sovereignty Discussed in the United Kingdom (UK)
Digital Sovereignty would be nice, but let's remember what contributes to it
IBM Adds Only More IBM Staff to the Fedora Council, They Like LLM Slop for Posting 'Articles'
It's like Canonical with Ubuntu, only worse
 
Links 19/06/2026: Salesforce Data Thefts and GAFAM's Conspiracy Theories That Data Center Opposition is a Foreign Plot
Links for the day
Links 19/06/2026: The Retweeting Class and Data Centres as National Security Risk
Links for the day
Don't Attack the Wives (or Spouses) of Pundits/Activists/Journalists
We will be writing several series about this in the future
Internet Relay Chat (Shorthand IRC) is Still Growing
Contrariwise, social control media is waning
The Register MS Published a New Page With "AI" 21 Times in It. It Was Paid SPAM.
The former editor of the The Register MS admitted to me (directly) that he knew all this "AI" stuff was stupid hype
Murdoch's Wall Street Journal (WSJ) Associates Dependence on a Ponzi Scheme With "the Future"
Those ludicrous ads (disguised as rankings) from WSJ deserve scorn and ridicule
The XBox Story is Still Fast-Developing, the Layoffs Are Confirmed to be Happening Already (Mid-June), Just Not "Officially"
Workers have Microsoft have long braced for what is happening this summer and will accelerate further in two weeks' time
Fake News From Rupert Murdoch's WSJ Could Not Keep IBM From Sinking
"2026 Best Companies for the Future"?
To GNU, AV2 Adoption May be a Year If Not Years Away
The leap between versions means that there is fertile ground for incompatibilities
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 18, 2026
IRC logs for Thursday, June 18, 2026
Gemini Links 19/06/2026: "Born and Raised by the Internet", Fifteen Years in Gopher
Links for the day
Links 18/06/2026: Clown Computing Has Harmful Sound, Facebook "Must Face the Music (Infringement Litigation)"
Links for the day
IBM Common Stock Down to About $250, It Was at $330 Just 17 Days Ago
Happy birthday IBM!
Microsoft's CEO Openly Admits XBox is Not Sustainable and Microsoft is Beginning to Admit Slop Isn't Working and Is Not Not Sustainable Either
Expect Microsoft cancellations next month (or later this month) to impact far more than XBox and some studios
EPO and Disabilities: Payments Allegedly Disabled
But people who do cocaine can claim paid "sick leave" (over 100,000 euros for no work at all) if the President sleeps with them
SLAPP Censorship - Part 110 Out of 200: Anti-SLAPP Reform Formally Advanced in the United Kingdom (UK) the Same Week the Serial Strangler From Microsoft (US) Does Forum-Shopping in the UK
The only language they understand is money. They don't understand privacy.
Links 18/06/2026: UK Social Media Ban for Minors, Finland Lifts a Nuclear Weapons Ban
Links for the day
'Article' With "AI" 27 Times in the Page, It's "Partner Content" (Paid Spam) as Usual at The Register MS
We deem this a timely reminder that a lot of the hype around slop is paid-for lies
Microsoft Layoffs Have Reportedly Already Started at ZeniMax
The overall scale is unknown
Cyber Show: "Our independence remains intact and we're set to continue relentlessly probing the world of digital technology with hard questions"
As one should
European Patent Office (EPO) Series: Leveraging the Lusitanian Connection
Mendonça no longer functions as an independent agent but rather as a fig-leaf for a mafia-like entity that prizes obedience over integrity and self-preservation over truth
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, June 17, 2026
IRC logs for Wednesday, June 17, 2026
The "Official" Numbers That Say "Microsoft Layoffs" Will be Misleading
The scale of the layoffs in gaming will be unprecedented
SLAPP Censorship - Part 109 Out of 200: When You Drag Family Members Into a Case Unrelated to Them Because Their Relative Published Something
This did not exactly surprise us given what we had already encountered
SUEPO Munich Informs/Contacts the German Government About the Situation at the European Patent Office (EPO)
Salary Erosion Procedure: Two letters to Germany
Gemini Links 17/06/2026: Feeling "Useful"; PISA Pen-and-Paper Cipher
Links for the day
Trajectory of O'Reilly: From Publisher of Books to Microsoft Advertiser
The state of the media is not good and when prolific book publishers start running ads as 'articles' or videos (never mind the disclosure) it is rather tasteless
Links 17/06/2026: Slop's “Crack Cocaine” Approach to Pricing, Microsoft's Rapid Shrinking of Gaming Business
Links for the day
Links 17/06/2026: "How Developers React to Slop-Scented Blog Posts", Police Caught Fabricating Evidence Using Slop
Links for the day
More Than 90% in European Patent Office (EPO) Ballot Vote for Continuation of Industrial Actions/Strikes, About Half Wish to Further Intensify These
Ballot results on intensification of actions
If Not Now, Then When?
If you are not part of the solution/s, then you're merely a vessel or passive participant
Microsoft Offers People 'Retirements' (Again) to Fake (Artificially Lower) Number of Layoffs, Those People Are Nowhere Near Retirement Age
Microsoft implicitly affirms huge cuts are coming
Gemini Links 17/06/2026: 10 Years in Canada, Wild Flower Explorations, and Microslop
Links for the day
European Patent Office (EPO) Series: The Portuguese Prodigy
In this part we will present some additional background information about Mendonça's activities before he joined the EPO
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 16, 2026
IRC logs for Tuesday, June 16, 2026