Anthropic has expanded Project Glasswing, its AI-driven vulnerability discovery initiative, to 150 additional companies with a focus on critical infrastructure sectors including power, water, healthcare, communications, and hardware. While analysts view the expansion positively, they highlight a growing 'patch bottleneck' problem: AI can identify vulnerabilities far faster than vendors and enterprise security teams can triage, validate, and remediate them. Experts warn that accelerating vulnerability discovery without matching remediation capacity could overwhelm security teams, turning cybersecurity from a visibility problem into an execution problem. Additional concerns include the lack of transparency around Anthropic's security requirements for new participants, the need for confidence scoring on automated patches to build CISO trust, and risks that expanding access to hundreds of companies increases the attack surface for potential leaks.

6m read timeFrom csoonline.com
Post cover image
123 Impressions