docs: add confirmed patch status and new sources
Track CVE assignments, patch dates, and security advisories for the flagship Glasswing-discovered vulnerabilities. 13 new sources added. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -36,6 +36,29 @@
|
||||
| S13 | Security Magazine: Expert reactions | securitymagazine.com/articles/102226-what-are-security-experts-saying-about-claude-mythos-and-project-glasswing |
|
||||
| S14 | The Conversation: Why an AI superhacker has the tech world on alert | theconversation.com/claude-mythos-and-project-glasswing-why-an-ai-superhacker-has-the-tech-world-on-alert-280374 |
|
||||
|
||||
## Security Advisories & Patch Sources
|
||||
|
||||
| ID | Source | URL |
|
||||
|----|--------|-----|
|
||||
| S15 | FreeBSD-SA-26:08.rpcsec_gss (CVE-2026-4747) | freebsd.org/security/advisories/FreeBSD-SA-26:08.rpcsec_gss.asc |
|
||||
| S16 | NVD: CVE-2026-4747 | nvd.nist.gov/vuln/detail/CVE-2026-4747 |
|
||||
| S17 | OpenBSD 7.7/7.8 Errata (025_sack, 2026-03-21) | openbsd.org/errata77.html |
|
||||
| S18 | Calif.io MAD Bugs write-up (CVE-2026-4747 prompts) | github.com/califio/publications/blob/main/MADBugs/CVE-2026-4747/write-up.md |
|
||||
| S19 | Firefox 149 Security Advisory (6 Anthropic-credited CVEs) | cybersecuritynews.com/firefox-149-released/ |
|
||||
| S20 | SentinelOne: CVE-2026-4692 (Firefox) | sentinelone.com/vulnerability-database/cve-2026-4692/ |
|
||||
| S21 | FFmpeg thanks Anthropic (PiunikaWeb) | piunikaweb.com/2026/04/08/ffmpeg-thanks-claude-mythos-16-year-bug-fix/ |
|
||||
| S22 | The Hacker News: Claude Mythos Finds Thousands of Zero-Day Flaws | thehackernews.com/2026/04/anthropics-claude-mythos-finds.html |
|
||||
| S23 | Red Hat RHSA-2026:7837 (Firefox downstream) | access.redhat.com/errata/RHSA-2026:7837 |
|
||||
|
||||
## Post-Announcement Analysis
|
||||
|
||||
| ID | Source | URL |
|
||||
|----|--------|-----|
|
||||
| S24 | Forrester: AI Will Break the Vuln Management Playbook | forrester.com/blogs/project-glasswing-shows-that-ai-will-break-the-vulnerability-management-playbook/ |
|
||||
| S25 | Humai: Less Than 1% Are Patched | humai.blog/anthropic-found-thousands-of-zero-days-in-windows-macos-chrome-and-firefox-less-than-1-are-patched/ |
|
||||
| S26 | Picus Security: The Glasswing Paradox | picussecurity.com/resource/blog/anthropics-project-glasswing-paradox |
|
||||
| S27 | VentureBeat: Mythos detection ceiling | venturebeat.com/security/mythos-detection-ceiling-security-teams-new-playbook/ |
|
||||
|
||||
## Unverified / To Investigate
|
||||
|
||||
- Security firm **Aisle** reportedly replicated some Glasswing discoveries with cheaper models (mentioned by Schneier, S4)
|
||||
|
||||
Reference in New Issue
Block a user