Finding Fault Is Easy
I opened my Wazuh dashboard to see what needed attention. I found high-severity vulnerabilities on two machines.
When I investigated, I found two browsers had already downloaded their own updates and were waiting for a relaunch that had not happened. The “Relaunch to Update” prompt, the one that lives in the corner of the screen and is easy to dismiss without thinking, had been doing its job. The fix was available.
How long has your browser been nagging you to restart it? Be honest.
This is not the first time the SOC surfaced something I did not expect to find. A few months ago it was two critical Firefox CVEs (Common Vulnerabilities and Exposures, the public records that track known software flaws) rated 9.8 out of 10 on the severity scale. Firefox itself said nothing. Wazuh had the information sitting in its vulnerability inventory. I found it because I went looking. At the time I thought, “the thing I built is working.” I did not know then how routine that would become.
In the last Field Notes post, I wrote about coordinated vulnerability disclosure and a case where it broke down publicly. The takeaway was about who pays the price when cooperation in cybersecurity fails. What has changed in 2026 is that even cooperation may not be enough.
In early April, Anthropic launched Project Glasswing, a controlled program giving a limited number of technology and infrastructure partners access to their most capable AI model for the specific purpose of scanning codebases for vulnerabilities. The reasoning behind careful access controls is not hard to follow: a tool this capable at finding vulnerabilities serves defenders and threat actors alike. What appropriate access looks like is now being decided in real time, and not only by the companies building these tools. By June the program had expanded to roughly 200 organizations across critical infrastructure sectors including power, water, healthcare, and communications.
The list of organizations that joined is worth pausing on. Cisco, Microsoft, AWS, Google, CrowdStrike, Palo Alto Networks, JPMorganChase, and the Linux Foundation are all Project Glasswing partners. Some of those organizations compete directly with each other. That reality is pulling them to the same table they would rarely share otherwise. That is genuinely notable, even if it is also a measure of how serious the problem is.
Anthropic’s June update on the program put numbers to it, and they cut both ways. In the first weeks alone, Glasswing partners identified more than 10,000 high or critical severity vulnerabilities. Mozilla found and fixed 271 vulnerabilities in Firefox 150 during testing, more than ten times the number found in a previous version using an earlier model. These numbers are not anomalies. They are what happens when you apply a sufficiently capable tool to the problem of finding bugs at scale.
Anthropic has already named what this shift means: “The bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.”
You cannot fault an X-ray machine for finding a broken bone.
That shift has consequences that are already showing up in the numbers.
Of roughly 1,600 vulnerabilities Anthropic disclosed to open-source software maintainers through Glasswing, approximately 97 had been patched as of May 2026. That is about six percent. The other 94 percent are somewhere in a pipeline: waiting for triage, waiting for disclosure, waiting for a maintainer to find time to understand and fix something that may be deeply embedded in code they did not write.
The infrastructure meant to help organizations make sense of all this is under pressure of its own. The National Institute of Standards and Technology (NIST) announced in April that the National Vulnerability Database (NVD), the system that assigns severity scores and affected product data to known vulnerabilities and that most security tools depend on to tell you what to prioritize, can no longer fully enrich every incoming submission. Full analysis will now go to roughly the top fifteen to twenty percent of CVEs. The rest will exist as records without the context that makes them actionable.
In June 2026, Microsoft’s monthly patch release set a record at 206 vulnerabilities. Researchers at Tenable are predicting that 100-plus CVEs per month is the new baseline for Patch Tuesday alone, with AI-assisted discovery tools accelerating the rate further as more vendors deploy them.
The vulnerabilities on those two machines I mentioned earlier were found because I went looking. The browsers had already done their part. The updates were downloaded, the prompts were waiting. There is no alert rule in my SOC that fires automatically on high or critical severity findings. There should be. That is on my list.
The browser prompt may still be in the corner of your screen. It does not require a SOC to act on. It just requires not ignoring it again.
The accelerating stream of vulnerabilities and their accompanying updates can be overwhelming for corporate IT departments and individual users alike: the realtor, the nurse, the doctor, the person writing this. That’s patch fatigue. It is not a reason to give up.
Elia Zaitsev, CTO of CrowdStrike and a Project Glasswing partner, put it this way: “That is not a reason to slow down; it’s a reason to move together, faster.” I understand that. I am not sure we can even pause long enough to question it. But what if moving faster is itself part of the problem? Disclosure strain is real. Review fatigue is real. Patch fatigue is real. The work still has to continue. The best way to do that seems to be together. Responsibly. With real humans involved, using the best tools available.
The question I keep coming back to is whether pointing AI at our most critical codebases and infrastructure is worth it. I do not think we have a clean answer yet.
What I have is a to-do list item I have been putting off: build the alert rule that should have told me about those vulnerabilities before I went looking for them.
Excuse me while I go do that.
ADHawk Technical Solutions — Protecting Access. Empowering People.
If this made you wonder what might be sitting unpatched on your devices or in your organization, that’s the right question to be asking. I am glad to talk.