Vulnerability discovery is starting to outrun the human capacity to fix, and Zscaler says that gap should change how Zero Trust programs prioritize risk.
In an August 13, 2026 blog post, Zscaler’s Anand Singh recapped a Black Hat panel featuring leaders from the Cloud Security Alliance, Qualys, and Rubrik. The starting point was Project Glasswing, Anthropic’s controlled-access consortium of roughly 50 vetted organizations. Using restricted access to the “Claude Mythos” model, participants had collectively surfaced more than 10,000 high- and critical-severity vulnerabilities by May 22, 2026.
Singh’s argument: when AI finds flaws faster than teams can remediate, chasing every CVE by severity stops working. Rubrik told the panel it rebuilt its code-review pipeline after Mythos generated more findings than human reviewers could process.
For security leaders, the practical shift is from raw CVSS queues to exploitability and reachability. What a flaw can actually touch, given your segmentation, becomes the ranking input. That maps directly onto Zero Trust work: microsegmentation boundaries, asset prioritization, and continuous-monitoring dashboards built for auditors rather than backlog counts.



Leave a Reply