Skip to content

Executive Summary

AI-driven vulnerability discovery capabilities, exemplified by Project Glasswing, have shifted the cybersecurity bottleneck from finding flaws to fixing them. The process of identifying critical vulnerabilities is now significantly faster than the pace at which security teams can patch them. This has created a new operational reality where the time between vulnerability discovery and remediation is the critical exposure window for attackers. Anthropic's findings indicate that AI can discover thousands of high- and critical-severity vulnerabilities rapidly, and this capability is expected to spread across the industry within six to twelve months.
The emergence of Agentic Runtime Security addresses this gap by focusing on behavioral detection, attack reconstruction, and containment across cloud, SaaS, identity, and AI environments, rather than relying solely on patching. The analysis suggests that traditional posture management tools are insufficient because they focus on static configurations while exploitation is occurring in dynamic runtime environments. Therefore, a new strategy must prioritize real-time behavioral monitoring and response to manage the risk created by unpatchable exposures.

Facts Only

* Anthropic reported finding over ten thousand high- or critical-severity vulnerabilities in one month via Project Glasswing.
* The bottleneck in security has shifted from finding flaws to fixing them.
* Exploitation often begins before a patch is released, with exploitation starting about one week before a patch release in 2026.
* Average time to patch a confirmed critical vulnerability was approximately two weeks.
* In some cases, vulnerabilities were exploited months before emergency patches were available, such as the Oracle E-Business Suite incident.
* The Glasswing capability is expected to become industry-wide within six to twelve months.
* There is an observed gap where 60% of breaches involved a patch that was available but not deployed in time at the time of compromise.
* Agents are proposed for runtime security functions like behavioral detection, attack reconstruction, and containment across cloud, SaaS, identity, and AI.

Full Take

The narrative presented suggests a fundamental shift from a static, posture-based security model to a dynamic, operational defense strategy in the face of accelerated adversarial capability. The core tension lies between the speed of discovery (AI) and the limitations of remediation processes. This creates a structural vulnerability where the window between exposure and fix is now the primary attack surface.
The implication for human agency is that relying on slow, sequential patching cycles is no longer sufficient defense when threats operate at machine speed. The argument shifts from "closing gaps" to "managing active risk during the gap." Defenders must transition from reactive posture management—which scores known misconfigurations—to proactive runtime awareness that monitors behavioral anomalies across interconnected systems. This requires a paradigm shift where detection and response capabilities must be integrated into the execution layer, moving beyond siloed identity or configuration checks.
The pattern observed is the necessity of compensating controls when remediation timelines are structurally impossible. The system breaks down under volume; therefore, resilience demands visibility deeper than patch status. If attackers move faster than the patching pipeline, the defense must operate concurrently within that differential—using AI not just to find flaws, but to reconstruct and contain attacks in real time across the full spectrum of cloud, SaaS, and AI interactions. The question for cognitive sovereignty is whether existing organizational structures can support this necessary shift from remediation focus to runtime operational mastery.

From the original · Mitiga Research

What Glasswing’s latest updates mean for Agentic Runtime Security Anthropic told the world it can find ten thousand critical vulnerabilities in a month, and no one can patch them fast enough. Anthropic is framing that asymmetry as a finding.
Read the full story at mitiga.io

Sentinel — Human

Confidence

This analysis presents a coherent and highly structured argument synthesizing specific technical findings regarding AI vulnerability discovery, the failure of traditional patching cycles, and the necessity of runtime security controls.

Signals Detected
low severity: Moderate sentence length variance and clear argumentative structure; strong use of rhetorical phrasing.
low severity: Strong internal logic, clear progression from problem (discovery vs. patching) to solution (runtime security), with consistent emphasis.
low severity: Incorporates specific data points and source references within the argument structure; sophisticated linking of disparate concepts.
low severity: The text presents a complex, nuanced argument synthesizing industry trends (Glasswing updates, patching delays) with proposed solutions, which suggests deep domain knowledge rather than simple aggregation.
Human Indicators
The incorporation of specific, dense metrics (e.g., 10,000 vulnerabilities found, 60% of breaches had a patch available) followed by nuanced strategic framing suggests human synthesis rather than pure LLM generation.
The use of speculative yet grounded forecasting ('within 6 to 12 months') tied directly to named industry projects provides an analyst-like voice.
Agentic Runtime Security: When Patching Can’t Keep Up. | Huntaegis