It's not unknown if it's effective...
someone from Mozilla put their name on a blog post saying they fixes 22 vulnerabilities and an upcoming patch fixes 200+
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
This isn't anthropic, they have no incentive to lie about how good the product is. They're committing limited development resources to these fixes so would want them to be real problems.
It's also definitely more than 0, the original mythos post disclosed a OpenBSD vulnerability that was patched and they disclosed more as hashes for unpatched vulnerabilities, basically signatures of either descriptions or exploit implementations, so when they fix and disclose the plain text ones we know the original post was telling the truth. The signatures are difficult to forge.
We also have a ton of 3rd party researchers looking at this stuff if they did forge those signatures and I haven't seen any whistleblowers with access to the model saying it garbage. If you have any sources let me know, I would be interested in reading that.
My point is not to white knight for anthropic. They're flaunting IP rights and driving up energy prices for personal profit, but that when you take a position and say something it should be for actual reasons, not just "I hate this company"