{"id":17712,"date":"2026-06-11T09:16:35","date_gmt":"2026-06-11T09:16:35","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17712"},"modified":"2026-07-09T16:23:59","modified_gmt":"2026-07-09T16:23:59","slug":"the-vulnerability-that-only-ai-has-found","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/11\/the-vulnerability-that-only-ai-has-found\/","title":{"rendered":"The vulnerability that only AI has found"},"content":{"rendered":"<p style=\"color:#6190a9;font-size:0.9em;margin:0 0 16px;padding:0;\">5 min read<\/p>\n<p><strong>In a consortium called Project Glasswing, an AI model uncovered vulnerabilities this spring that human auditors had missed. The same model that patches these gaps could also be used to exploit them. This dual-use dilemma forces Anthropic to implement tiered access-and SOC teams to adopt a new threat model.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The capability is real.<\/strong> Anthropic\u2019s Mythos models lead in security tasks, uncovering vulnerabilities in programs like Project Glasswing that humans overlook.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Defense and offense rely on the same strength.<\/strong> Whoever can reliably find vulnerabilities can also exploit them. That\u2019s why Anthropic restricts access and reroutes high-risk requests to a weaker model.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The threat model is evolving.<\/strong> SOC teams must now account for attackers who search for weaknesses at the same AI-driven speed as defenders.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#0a7385;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/04\/patch-prioritization-cvss-overwhelming-soc\/\" style=\"color:#333;text-decoration:underline;\">Patch prioritization: Why CVSS alone slows down your SOC<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/security-awareness-the-click-rate-measures-the-wrong-thing\/\" style=\"color:#333;text-decoration:underline;\">Security awareness: Click rates measure the wrong thing<\/a><\/p>\n<div style=\"border-left:3px solid #69d8ed;background:#f4fafb;padding:16px 20px;margin:24px 0;color:#1a2a2e;\">\n<strong>What is dual-use in AI models?<\/strong> Dual-use refers to a capability that can be used for both defensive and offensive purposes. An AI model that finds vulnerabilities to patch them can also leverage the same ability to exploit them. The outcome depends on the user\u2019s intent.\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What happened in Project Glasswing<\/h2>\n<p>When Anthropic unveiled its Mythos models in April, the first step wasn\u2019t a product for the masses. The company held back its most powerful version and deployed it within a consortium: Project Glasswing. There, select firms used the model to identify and fix software vulnerabilities before attackers could discover them.<\/p>\n<p>The results justified the caution. A system that detects security flaws faster and more thoroughly than an experienced team is a formidable defensive tool. Such a tool demands controlled distribution.<\/p>\n<div style=\"background:#003340;border-radius:10px;margin:32px 0;padding:26px 30px;color:rgba(255,255,255,0.92);\">\n<div style=\"font-size:0.72em;text-transform:uppercase;letter-spacing:0.14em;color:#69d8ed;font-weight:700;margin-bottom:12px;\">The core of the problem<\/div>\n<p style=\"margin:0;font-size:1.12em;line-height:1.55;color:rgba(255,255,255,0.92);\">A model that finds vulnerabilities is equally suited for defense and attack. The search process is identical-the only difference is the objective.<\/p>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why the same capability works in both directions<\/h2>\n<p>Penetration testing and attacks have always relied on the same techniques, just with different intentions. In a model designed to find vulnerabilities at scale, this long-standing tension becomes a concrete governance challenge.<\/p>\n<p>Anthropic\u2019s answer is tiering. The widely available variant automatically routes higher-risk queries from cybersecurity, biology, and chemistry to a less powerful model instead of answering them itself. The strongest variant remains reserved for a small circle of defenders and infrastructure providers, sometimes in partnership with government agencies.<\/p>\n<div style=\"border-left:3px solid #69d8ed;padding:6px 0 6px 22px;margin:28px 0;\">\n<div style=\"margin-bottom:14px;\"><span style=\"color:#0a7385;font-weight:700;\">April 2026<\/span><br \/>Mythos becomes publicly known, but its release to the general public is withheld. Launch of Project Glasswing.<\/div>\n<div style=\"margin-bottom:14px;\"><span style=\"color:#0a7385;font-weight:700;\">Spring 2026<\/span><br \/>The model identifies vulnerabilities within the consortium that had eluded human auditors.<\/div>\n<div><span style=\"color:#0a7385;font-weight:700;\">June 2026<\/span><br \/>The strongest variant is deployed to a tight circle of cyber-defenders; the broad variant routes risky queries onward.<\/div>\n<\/div>\n<div style=\"background:#003340;border-radius:10px;padding:26px 30px;margin:32px 0;color:#dff3f7;\">\n<div style=\"font-size:0.72em;text-transform:uppercase;letter-spacing:0.14em;color:#69d8ed;font-weight:700;margin-bottom:18px;\">The situation in numbers<\/div>\n<div style=\"display:flex;flex-wrap:wrap;gap:24px;color:#dff3f7;\">\n<div style=\"flex:1;min-width:130px;color:#dff3f7;\">\n<div style=\"font-size:2em;font-weight:800;color:#ffffff;line-height:1;\">15+<\/div>\n<div style=\"font-size:0.86em;margin-top:6px;color:#a9cdd6;\">countries where Mythos models are being tested on critical infrastructure<\/div>\n<\/div>\n<div style=\"flex:1;min-width:130px;color:#dff3f7;\">\n<div style=\"font-size:2em;font-weight:800;color:#ffffff;line-height:1;\">80 %<\/div>\n<div style=\"font-size:0.86em;margin-top:6px;color:#a9cdd6;\">of the code merged by Anthropic, according to their own figures, originates from Claude<\/div>\n<\/div>\n<div style=\"flex:1;min-width:130px;color:#dff3f7;\">\n<div style=\"font-size:2em;font-weight:800;color:#ffffff;line-height:1;\">2<\/div>\n<div style=\"font-size:0.86em;margin-top:6px;color:#a9cdd6;\">access tiers separate broad use from full security capability<\/div>\n<\/div><\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What this means for SOC teams<\/h2>\n<p>The practical takeaway isn\u2019t cause for alarm, but it is cause for preparation. When defenders locate gaps at AI speed, security teams must assume attackers will seek the same leverage. The window between vulnerability discovery and exploitation tends to shrink.<\/p>\n<p>For your threat model, that means faster patch cycles, tighter monitoring of exposed interfaces, and the expectation that automated search will become the norm on both sides. Governance frameworks such as NIS2 already demand demonstrable responsiveness; AI-driven discovery turns that requirement into a genuine race against time.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What is dual-use in AI models?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Dual-use refers to a capability that can be deployed both defensively and offensively. A model that finds vulnerabilities to patch them can just as easily use that same capability to exploit them. The difference lies solely in the user\u2019s intent.<\/p>\n<\/details>\n<details>\n<summary><strong>What is Project Glasswing?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A consortium in which selected companies leverage Anthropic\u2019s Mythos model to discover and remediate software vulnerabilities. It was the deliberately controlled path to deploying strong security capability without making it widely available.<\/p>\n<\/details>\n<details>\n<summary><strong>Why does the broad model reroute risky queries?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The publicly available variant automatically passes higher-risk topics from cybersecurity, biology, and chemistry to a less powerful model. This lets full performance be offered where it\u2019s non-critical, while throttling where abuse is a risk.<\/p>\n<\/details>\n<details>\n<summary><strong>Does this mean more attacks on my company?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Not necessarily more attacks, but potentially faster ones. When automated search becomes the norm, the gap between discovery and exploitation narrows. Patch cadence and visibility of your own interfaces move to the top of the priority list.<\/p>\n<\/details>\n<details>\n<summary><strong>What should an SOC team do right now?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Inventory exposed interfaces, base patch prioritization on real exploitability rather than scores alone, and expand your threat model to include AI-capable attackers. What matters most is how quickly your team responds.<\/p>\n<\/details>\n<div style=\"margin:40px 0 24px 0;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/06\/03\/artificial-intelligence-is-no-longer-a-playground-for-the-it-channel\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-gtia-state-of-the-channel-2026-ki-reifeg-15372770.png\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Artificial Intelligence Is No Longer a Playground for the IT Channel<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/when-the-update-itself-becomes-an-entry-point\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-lieferkettenangriff-software-mittelstand-72660027-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">When the update itself becomes an entry point<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/apple-builds-ai-as-its-moat-the-golden-gate-strategy\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-golden-gate-apple-macht-ki-zum-burggrabe-32684178-250x139.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Apple Builds AI as Its Moat: The Golden Gate Strategy<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Rethinking cybersecurity: AI models find vulnerabilities that humans couldn&#8217;t see. The same strength that defends and attacks &#8211; the dual-use dilemma.","protected":false},"author":50,"featured_media":17604,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Dual-use | This term is already in English, and it refers to goods, software, or technology that can be used for both civilian and military purposes.","_yoast_wpseo_title":"The vulnerability that only AI has found","_yoast_wpseo_metadesc":"Revolutionizing cybersecurity: AI models detecting vulnerabilities overlooked by humans. Explore the dual-use dilemma of defense and attack.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,2,255],"tags":[],"class_list":["post-17712","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-innovation","category-praxis-umsetzung-en"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":17603,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17712"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17712\/revisions"}],"predecessor-version":[{"id":21139,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17712\/revisions\/21139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17604"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}