Project Glasswing: An initial update(Project Glasswing 初步更新)
title: "Project Glasswing: An initial update(Project Glasswing 初步更新)" tags: [部落格, 英文, Anthropic, AI安全, 網路安全, 漏洞發現] source: https://www.anthropic.com/research/glasswing-initial-update date: 2026-05-22 domain: 國際視野 type: research status: active updated: 2026-08-30 ---# Project Glasswing: An initial update(Project Glasswing 初步更新)
來源: Anthropic 原文日期: 2026-05-22
中文摘要
Anthropic 於 2026 年 3 月啟動 Project Glasswing,與約 50 個合作夥伴合作,利用 Claude Mythos Preview 模型掃描全球最重要軟體專案中的安全漏洞。第一個月內,合作夥伴們在各自軟體中發現了數百個高嚴重性或關鍵級漏洞,合計超過一萬個。Cloudflare 發現 2,000 個 bug(其中 400 個為高/關鍵嚴重性),誤報率優於人類測試者。Mozilla 在 Firefox 150 中發現並修復了 271 個漏洞,數量是使用 Claude Opus 4.6 在 Firefox 148 中發現量的十倍以上。Anthropic 本身掃描了 1,000 多個開源專案,發現 6,202 個高/關鍵嚴重性漏洞。
關鍵洞察
原文關鍵句(英文保留)
> "After one month, most partners have each found hundreds of critical- or high-severity vulnerabilities in their software. Collectively, they've found more than ten thousand. Several have told us that their rate of bug-finding has increased by more than a factor of ten."
> "Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI."
> "The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity."