Cisco praises AI bug hunt, won't reveal flaw tally
Cisco says AI models scanned 1.8 billion lines of code for vulnerabilities, but it won't say how many flaws they found or whether all are fixed.
Intelligence analysis by GPT-5.4 Mini

Cisco and Anthropic are framing frontier AI as a serious vulnerability-hunting tool, with Cisco saying the models reviewed vast codebases far faster than a human team could. The headline result is scale and speed, but the company is withholding the bug count.
Cisco used smart computer helpers to look for weak spots in its software much faster than people could alone. It says the helpers were useful, but it did not say how many problems they actually found, which leaves the result a bit like counting apples without showing the basket.
Analysis
Cisco's AI-assisted bug hunt
Cisco says advanced AI systems, including Anthropic's Claude Mythos Preview and OpenAI's GPT 5.5-Cyber, scanned 1.8 billion lines of code across Cisco products in eight weeks. Cisco security chief Anthony Grieco said that amount of work would have taken the company's security team about eight years if done conventionally.
The company is emphasizing scale, not just speed. According to Cisco, the code spanned more than 25 programming languages, and the work used a human-guided harness designed to keep false positives low. Grieco said the setup produced a false positive rate of under 3 percent, and that the point was to generate findings engineering teams could actually act on.
What Cisco did not say
Cisco did not disclose how many vulnerabilities the models found, and it did not say whether every issue has already been fixed. The Register notes that Cisco did not answer questions on that point. That omission matters because the practical value of AI-assisted scanning depends not just on discovery, but on remediation and disclosure.
Anthropic widens access
The article is also part of a broader Anthropic rollout. Anthropic said it expanded Project Glasswing, its controlled partner program for Claude Mythos Preview, from about 50 organizations to about 200. The new cohort spans more than 15 countries and includes additional vendors and infrastructure-related organizations. Anthropic says each partner must meet security requirements before getting access.
The article uses Palo Alto Networks as a comparison point: the company said a month of testing frontier AI models found 26 CVEs tied to 75 security issues. That gives some sense of why vendors are excited, even if Cisco itself has not shared comparable numbers.
The overall message is clear: frontier models are moving from theoretical security tools into structured, partner-only bug hunting programs. But the lack of a bug tally leaves the real impact hard to measure.
Key points
- Cisco says AI models scanned 1.8 billion lines of code across its products in eight weeks.
- The company says that job would have taken its security team about eight years to do manually.
- Cisco did not disclose how many vulnerabilities the models found or whether all of them are fixed.
- Anthropic expanded Project Glasswing to about 200 partners, up from about 50.
- Palo Alto Networks previously said similar testing found 26 CVEs tied to 75 issues.
If Cisco's approach holds up, AI-assisted scanning could help security teams inspect entire products instead of tiny slices of code. The low false-positive rate and human review layer suggest the findings may be useful enough for engineers to fix quickly.
The story leaves the most important outcome unclear because Cisco will not say how many flaws were found or whether they are all fixed. If these tools are powerful enough to find bugs at scale, they may also widen the gap between companies that can secure their code and attackers who can exploit the same class of models.



