Gen. partnerAlgotech

AI Found 10,000 Critical Vulnerabilities. People Can't Keep Up Fixing Them | CCTV NEWS Ep.331

Artificial intelligence may be starting to change cybersecurity faster than we expected. Anthropic claims its AI model Mythos Preview discovered more than 10,000 critical vulnerabilities within a few weeks. In the new episode of CCTV NEWS we discussed this project, as well as a possible leak of internal GitHub repositories, Discord's new end-to-end encryption, and an operation against VPN infrastructure used by ransomware groups.

|
May 27, 2026

Artificial intelligence may be starting to change cybersecurity faster than we expected. Anthropic claims its AI model Mythos Preview discovered more than 10,000 critical vulnerabilities within a few weeks. In the new episode of CCTV NEWS we discussed this project, as well as a possible leak of internal GitHub repositories, Discord's new end-to-end encryption, and an operation against VPN infrastructure used by ransomware groups.

AI found 10,000 critical vulnerabilities

Anthropic published the first details of Project Glasswing, an initiative focused on searching for security bugs using AI models. The company says the Claude Mythos Preview model helped identify more than 10,000 critical or high-severity vulnerabilities during the first month.

Anthropic also warns that the current limit may no longer be finding bugs themselves, but humans' ability to verify and fix the discovered vulnerabilities. According to the company, maintainers of open source projects are unable to keep up with the volume of new reports generated using AI.

GitHub investigates possible leak of internal repositories

GitHub confirmed a security incident related to the compromise of an employee's device through a malicious extension for Visual Studio Code. According to the company, unauthorized access to thousands of internal repositories may have occurred.

GitHub also stated that it has no evidence so far of impact on customers' private repositories or their data. The incident is linked to the group TeamPCP, which has recently been associated with several supply chain attacks against the open source ecosystem.

Discord now encrypts all calls

Discord announced the completion of a multi-year project to implement end-to-end encryption for all voice and video calls on the platform. The only exception remains Stage Channels intended for public broadcasts.

The company also said it currently does not plan to introduce end-to-end encryption for text messages, because a large part of the platform's features were designed without this type of protection.

Police dismantled VPN infrastructure used by ransomware groups

European and North American security agencies, as part of Operation Saffron, targeted the First VPN service, which investigators say was used by at least 25 ransomware groups.

During the operation, 33 servers were seized and investigators also warned service users that their identities are now known to security agencies.

Cisco patches critical vulnerability with CVSS 10.0

Cisco released fixes for the critical vulnerability CVE-2026-20223 in the Secure Workload platform. The flaw, with a maximum CVSS score of 10 out of 10, could have allowed attackers remote access to sensitive data without authentication.

According to the company, there is no evidence so far of active exploitation of the flaw, but Cisco recommends installing security updates as soon as possible.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.