Let's not bury that image content.
23,019 potential vulnerability candidates -> 1,900 Reviewed by external security firms -> 1726 confirmed positive -> 467 reported to maintainers
Why only review 1900? How were these chosen? Were the 1259 that were not reported to maintainers just duplicates or were they even valid?
23,019 potential vulnerability candidates -> 1,129 reported direct to maintainers by Anthropic, at their request (May contain false positives)
They just spammed the maintainers with these without reviewing them?
1129 + 467 = 1596 total reported to maintainers -> 1451 acknowledged by maintainers
Does acknowledged mean they said they received the report or does it mean they validated the report? Because it looks a lot like "received", when accounting for that prior 1259 gap and the fact the bulk of them weren't reviewed prior to sending.
Subsequent analysis of these vulnerability candidates has identified that 1,726 are valid true positives. As many as 1,094 flaws are assessed to be either high- or critical-severity.
But that 1726 was reduced to 467 come reporting time. Which makes that 17% hit rate possibly... 4.7%?
MYTHOS IS TOO POWERFUL TO RELEASE /s
I assume this article is slop. It contradicts 10k high sev by paragraph 3, not even Anthropic claims it in their media release, which contains even sadder numbers.