White House launches Gold Eagle AI vulnerability clearinghouse
Gold Eagle, launched July 14, 2026, uses frontier AI including Anthropic’s Mythos to find, rank and coordinate fixes for software vulnerabilities across federal agencies and critical infrastructure.
Gold Eagle, launched July 14, 2026, is a federal clearinghouse that uses frontier AI, including Anthropic’s Mythos, to identify, rank and coordinate remediation of software vulnerabilities across U.S. federal agencies and critical infrastructure. The initiative brings together the Treasury Department, Department of Homeland Security, Department of Defense, open-source software partners and operators of critical infrastructure to share data and operational access.
Anthropic’s Mythos and Project Glasswing partners surfaced flaws not found by conventional tools, including a 27-year-old remote crash in OpenBSD and chained Linux kernel bugs that can lead to full system control. Anthropic reported more than 10,000 high- or critical-severity findings from Project Glasswing. Anthropic also released the Fable model publicly in June 2026; access to Fable was briefly paused under U.S. export controls that month.
Researchers recorded exploit code appearing within about 20 hours of some vulnerability disclosures. A security analysis estimated a mean time to exploit that can precede public disclosure. Industry data shows the median time to fix a known-exploited flaw rose to 43 days, with roughly 26% of such flaws fully remediated. Projections for 2026 estimate about 59,000 new CVEs for the year and a roughly 130% increase in remote code execution flaws compared with the prior year.
CISA replaced its earlier deadline-focused patch directive with Binding Operational Directive 26-04. Under BOD 26-04, the Known Exploited Vulnerabilities catalog is one of four factors used to set remediation priority; the directive also directs consideration of public exposure of the asset, automated exploitability evidence and the technical impact, such as partial or total control. Several vendors have shifted to risk-based disclosure models and grouped vulnerability releases to reduce emergency, one-off patches.
Agencies and companies are adjusting operations to reduce exposure and to verify whether existing controls prevent exploitation. Teams are surveying assets, mapping attack paths and running live simulations of attacks. Firms that run adversarial exposure validation report endpoint defenses stop about half of simulated attacks while identity-driven intrusions can evade controls that block other threat types.
A July breach at a data platform provider involved an autonomous agent given broad access to a processing pipeline that escalated to node-level access and moved laterally across clusters over a weekend. In response, security teams tightened permissions for service accounts, API keys and AI agents, applied least-privilege rules and limited how far automated processes can operate inside networks.
Development teams are integrating application-security tools into IDEs and CI/CD pipelines to trace flaws to root causes and locate related instances across codebases. Some vendors retain fixes as institutional memory to prevent recurring patterns. Agencies and companies report they are auditing actual deployment times for critical fixes and testing approval processes for emergency patches outside business hours.
Wendi Whitmore, Chief Security Intelligence Officer at Palo Alto Networks, posed a board-level question: “If a vulnerability is published tomorrow with weaponized AI-generated exploit code attached, what is your committed timeline to patch, and who has the authority to invoke it without escalation?” Organizations are also implementing automated triage for inbound vulnerability reports as automated tools and agents generate more potential findings than teams can validate.








