Finding Vulnerabilities Is Becoming the Easy Part

By David Mundy, VP of Marketing, Tuskira
Anthropic launched its Cyber Mission on October 8, 2026. The part that matters most for security teams is OSS Scanner, which gives participating open-source projects recurring scans from Anthropic’s strongest models. Reports can include an explanation of the vulnerability, a proof of concept, and a suggested fix.
This is good news. Open-source maintainers are badly outnumbered, and broader access to frontier-model security capabilities should surface weaknesses that would otherwise stay buried.
It will also create a lot more findings.
Anthropic is candid about the tradeoff. The reports are model-generated and sent without human review, so some will contain inaccuracies, including wrong severity ratings. And Anthropic says its earlier Project Glasswing work uncovered many vulnerabilities without producing “a sufficient reduction in cyber risk,” with months often passing between a vulnerability being found and being fixed.
Its clearest conclusion is the one security teams should sit with.
Tuskira Research measured the same gap earlier this year.
The gap
A proof of concept isn’t proof of exposure
A proof of concept can show that a bug is exploitable under particular conditions. It can’t establish whether those conditions exist in your environment, what an attacker could reach next, or whether a deployed control would interrupt the path.
Consider the same vulnerability at two companies.
- Affected service sits behind a WAF rule that blocks the exploit pattern
- Host is covered by EDR
- No path from the system to sensitive data
- Service is internet-facing
- Its identity has standing access to production
- Nothing between the entry point and the data would stop an attacker
The vulnerability and the severity score are identical. The risk isn’t.
Telling them apart depends on evidence from the environment.
A frontier model can help reason through those questions. It still needs current information about the organization’s architecture, identities, configurations, telemetry and security controls before its answer means anything operationally.
Unpatchable systems
When patching isn’t the immediate answer
Anthropic’s focus on operational technology makes this especially clear. Industrial systems can stay in service for decades, and taking them offline to patch may be dangerous, disruptive, or impossible.
Most enterprises have less dramatic versions of the same problem, such as an application without vendor support, a database that can’t be restarted this quarter, or an appliance whose last update caused an outage.
In those situations, another patch recommendation doesn’t solve the immediate problem. The team needs to know whether a WAF rule, firewall policy, identity restriction, EDR setting or segmentation change can interrupt the path now. It also needs evidence that the change worked.
That’s the difference between having a compensating control on paper and having a defense that holds.
The loop
Discovery has to feed a defense loop
The emerging workflow looks like this.
- 01DiscoveryA frontier model finds the bug and shows it can be exploited
- 02Environment contextIdentities, assets, exposures, detections and deployed controls, as they are today
- 03Path validationDoes this finding create a viable path to something that matters?
- 04Control selectionWhich change you already own closes it fastest?
- 05Governed actionRecommend, stage or execute through the tool that owns the control
- 06RetestProve the path is closed and record the outcome
“Nobody gets credit for the longest list of findings. You get credit for the paths you closed, and for being able to show it.”
Piyush Sharrma, CEO, TuskiraFrontier models are rapidly improving the discovery step. Tuskira takes the resulting finding and places it inside a live model of the customer’s environment.
The Security Data Fabric brings together identities, assets, exposures, detections and deployed controls, keeping the digital twin current as the environment changes. Tuskira then determines whether the finding creates a viable path to something important, tests whether existing defenses interrupt it, and identifies the most effective change for closing the path.
Depending on the customer’s policy and integrations, that change can be recommended, staged, or executed through the tool that owns the control. Tuskira then retests the path and records the outcome. The customer’s existing tools remain the systems of record.
Frontier models bring powerful discovery and reasoning. Tuskira grounds that intelligence in enterprise context, control evidence, governed execution and verified closure.
AI will find more vulnerabilities than defenders have ever had to process. The advantage will belong to the teams that can tell which findings create a real path and close it through the controls they already own.
Give us one finding.
We’ll show you whether it creates a path in your environment, which control you already own closes it, and the retest that proves it.
Request a demo →Sources: Anthropic, “Introducing the Anthropic Cyber Mission,” October 8, 2026. Tuskira Research, “The Emerging Patch Gap,” June 2026.


