discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Cisco praises AI bug hunt, won't reveal flaw tally

Cisco says AI models scanned 1.8 billion lines of code for vulnerabilities, but it won't say how many flaws they found or whether all are fixed.

By Jessica Lyons·Jun 2·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Cisco praises AI bug hunt, won't reveal flaw tally
Image: theregister.com

Cisco and Anthropic are framing frontier AI as a serious vulnerability-hunting tool, with Cisco saying the models reviewed vast codebases far faster than a human team could. The headline result is scale and speed, but the company is withholding the bug count.

Why it matters

This shows how security teams are starting to use frontier models as part of real product defense, not just demos. It also raises the usual security questions: how many issues were found, how reliable the findings were, and whether disclosure is being kept intentionally vague.

Cisco used smart computer helpers to look for weak spots in its software much faster than people could alone. It says the helpers were useful, but it did not say how many problems they actually found, which leaves the result a bit like counting apples without showing the basket.

Analysis

Cisco's AI-assisted bug hunt

Cisco says advanced AI systems, including Anthropic's Claude Mythos Preview and OpenAI's GPT 5.5-Cyber, scanned 1.8 billion lines of code across Cisco products in eight weeks. Cisco security chief Anthony Grieco said that amount of work would have taken the company's security team about eight years if done conventionally.

The company is emphasizing scale, not just speed. According to Cisco, the code spanned more than 25 programming languages, and the work used a human-guided harness designed to keep false positives low. Grieco said the setup produced a false positive rate of under 3 percent, and that the point was to generate findings engineering teams could actually act on.

What Cisco did not say

Cisco did not disclose how many vulnerabilities the models found, and it did not say whether every issue has already been fixed. The Register notes that Cisco did not answer questions on that point. That omission matters because the practical value of AI-assisted scanning depends not just on discovery, but on remediation and disclosure.

Anthropic widens access

The article is also part of a broader Anthropic rollout. Anthropic said it expanded Project Glasswing, its controlled partner program for Claude Mythos Preview, from about 50 organizations to about 200. The new cohort spans more than 15 countries and includes additional vendors and infrastructure-related organizations. Anthropic says each partner must meet security requirements before getting access.

The article uses Palo Alto Networks as a comparison point: the company said a month of testing frontier AI models found 26 CVEs tied to 75 security issues. That gives some sense of why vendors are excited, even if Cisco itself has not shared comparable numbers.

The overall message is clear: frontier models are moving from theoretical security tools into structured, partner-only bug hunting programs. But the lack of a bug tally leaves the real impact hard to measure.

Key points

  • Cisco says AI models scanned 1.8 billion lines of code across its products in eight weeks.
  • The company says that job would have taken its security team about eight years to do manually.
  • Cisco did not disclose how many vulnerabilities the models found or whether all of them are fixed.
  • Anthropic expanded Project Glasswing to about 200 partners, up from about 50.
  • Palo Alto Networks previously said similar testing found 26 CVEs tied to 75 issues.
The Upside

If Cisco's approach holds up, AI-assisted scanning could help security teams inspect entire products instead of tiny slices of code. The low false-positive rate and human review layer suggest the findings may be useful enough for engineers to fix quickly.

The Downside

The story leaves the most important outcome unclear because Cisco will not say how many flaws were found or whether they are all fixed. If these tools are powerful enough to find bugs at scale, they may also widen the gap between companies that can secure their code and attackers who can exploit the same class of models.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityllmsai-agentstech

Author

Jessica Lyons

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 2, 2026

Source

theregister.com

Share

Topics

securityllmsai-agentstech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…