Anthropic lends its "bug-hunting" AI to hospitals: good news?
Sixteen years. That's how old a bug was that had been sleeping in FFmpeg, the free video engine found in VLC and in a whole bunch of apps that play your videos. Test robots had run malicious videos through this piece of code five million times without seeing anything. It was an AI from Anthropic, Claude Mythos, that found it this spring. And since October 6, that AI is no longer reserved for Apple, Google and Microsoft: Anthropic is opening it up to small hospitals, municipal water utilities and volunteers who maintain free software. And frankly, it's one of the best pieces of news I've read this week!
The hospital technician has just received a colleague. It doesn't take a coffee break
A sixteen-year-old bug, and another one twenty-seven years old
A quick trip back in time. In April, Anthropic presents Mythos, a model so good at finding vulnerabilities that it refuses to put it up for sale. A vulnerability is an error in software that lets someone get in where they shouldn't. Instead of selling Mythos, Anthropic lends it to around forty large organizations, in a club called Project Glasswing, so they can plug the holes before hackers find them.
And Mythos immediately came up with some heavy hitters. The FFmpeg bug, slipped into the code in 2003 according to an analysis picked up by the specialist press. And a twenty-seven-year-old bug in OpenBSD, a system reputed to be one of the safest in the world, often installed on firewalls, those boxes that filter everything entering a company's network. All it took was opening a connection to the machine to crash it remotely. Twenty-seven years that experts had been rereading this code! When I read that, I said to myself: "but what were they doing all that time?" Well, they were looking, like humans do, and a human gets tired, skips a line, goes for coffee.
Happy birthday, little bug. This was the last one
129,000 vulnerabilities in four months
The figure Anthropic publishes with the announcement makes your head spin: between April and July, the club's members found at least 129,000 verified vulnerabilities. More than 33,000 are classified as serious or critical, meaning a hacker could use them to take control of a machine or steal data. Anthropic found 5,500 more on its side, combing through free software, software whose code is public and that everyone uses without knowing it.
These are corporate figures, it has to be said. They come from reports by only 33 partners, and Anthropic says the real total is at least five times higher. I want to believe it, but I have no way to verify it. What is certain is that tens of thousands of holes are being plugged in software running on your devices. Now that's concrete!
Who gets what
The Glasswing club is disappearing, folded into a broader three-tier program, and the first tier, the most open one, the one Anthropic calls Defense Access, is aimed at the security teams of companies, associations, universities and government agencies, but above all, and it is written in black and white in the announcement, “critical infrastructure operators of any size, such as regional hospitals or municipal utilities”, small security companies, volunteers who maintain free software, and researchers who have already reported vulnerabilities. You read that right: volunteers! These are precisely the people who have never had the means to pay for a team of ten experts.
The second tier is reserved for companies that are paid to attack a network with its owner's permission, just to see whether it holds up. The third, the most unrestricted one, is reserved for a handful of organizations that test systems whose failure would cause enormous damage: airplanes, power grids, transfers between banks. Those are screened together with the American government.
Why everyone doesn't get access
Because the tool that finds the vulnerability to patch it also knows how to find it to get in. Anthropic published a test that shows it very well: fifty simulated attack missions. With a normal account, Claude refuses everything, from the very first question. With “defense” access, it still refuses 46 out of 50. With “authorized attack” access, it no longer refuses any, and Claude Opus 5.5 succeeds in 34 missions out of 50. Exactly as many as without any protection.
The master key is behind the counter. And you show your card
It is the same logic as Google with Gemini 4 Argon, also reserved for defenders last week. And on the same day as Anthropic, Mistral was doing exactly the opposite: its new model, Mistral Large 4, is posting record security scores on a test where Claude and GPT score almost zero because they refuse, and it will be downloadable by anyone at the end of October. Two philosophies on the same Tuesday. For me, on this one, Anthropic is right: a tool like that, you lend it out upon presentation of a card.
What it changes for you
The utility that manages your town's water, the hospital where you take your children to the emergency room, the little piece of free software that your internet box uses without telling you: these are exactly the hackers' favorite targets, because they are important and poorly defended. From now on, they can have their systems reviewed by an AI that found a twenty-seven-year-old bug where experts had seen nothing. It does not make anything invulnerable. But it shifts the advantage toward those who defend, and you do not see that often!
And you have one role, just one, and it is simple: install the updates. All those patched vulnerabilities reach you in the form of a notification that you put off until tomorrow. The hackers, for their part, now exploit a vulnerability in less than 24 hours, Microsoft measured it. An update that waits three weeks is a door that someone repaired and that you leave open.
On the left, three weeks of “I'll do it tonight.” On the right, ten seconds
My opinion
I'm pretty much in favor, and without forcing myself. For years, computer security was a rich person's sport: the bank had its experts, the regional hospital had an overwhelmed IT guy and a printer that jams. Now, the overwhelmed IT guy gets the same tool as the bank.
Two reservations, though. To get into the program, you have to accept that Anthropic keeps the conversations, to check that nobody misuses the tool. For a hospital having its own systems analyzed, that's not a detail. And it's Anthropic, a private company, that decides who's a good guy. For now its choices seem good to me, but a bouncer is still a bouncer.
And to the IT guy at my regional hospital, if you're reading this: sign up, it's on the program page. The hackers, meanwhile, haven't waited for us to open the door!
Sources
- Anthropic, October 6, 2026: expansion of the Cyber Verification Program
- SiliconANGLE, October 6, 2026: Glasswing folded into a three-tier program
- Anthropic, April 2026: Mythos's security capabilities (OpenBSD and FFmpeg bugs)
- Mistral AI, October 6, 2026: Mistral Large 4 and its security scores
Article written with the help of Claude Code, reread and corrected by me.




Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.