Anthropic Expanding Project Glasswing
Anthropic has expanded Project Glasswing, a collaborative initiative to secure critical software, by adding approximately 150 new organizations to the partnership. This expansion aims to provide critical infrastructure providers and open-source maintainers with access to Claude Mythos Preview to identify and remediate security vulnerabilities before powerful, unguarded cyber-capable AI models become widely available.
Expansion of Project Glasswing Partners
Anthropic is extending access to Claude Mythos Preview to 150 new organizations across more than 15 countries. These partners include vendors, nonprofits, and providers of critical infrastructure in sectors such as power, water, healthcare, communications, and hardware.
Anthropic identifies these partners based on the potential catastrophic impact of a successful attack on their codebases, estimating that a major attack on most of these partners could affect more than 100 million people and significantly impact global and national security.
The Role of Claude Mythos Preview in Cybersecurity
Claude Mythos Preview is being used by Project Glasswing partners to scan codebases for vulnerabilities. Initial partners (roughly 50 organizations) have already identified more than 10,000 high- or critical-severity security flaws.
Anthropic warns that "Mythos-class models" will likely be available from other AI companies within 6 to 12 months, potentially without safeguards to prevent misuse. Project Glasswing is designed to help cyberdefenders adapt to this reality by establishing new operating norms and providing access to advanced tools.
Defensive Capabilities and Tools
Beyond vulnerability discovery, Claude Mythos Preview and similar models are being utilized for:
- Patch Generation: Writing patches to fix identified vulnerabilities.
- Pre-release Checks: Preventing vulnerabilities from entering codebases during development.
- Penetration Testing: Simulating cyberattacks to identify exploit paths.
- Threat Detection: Automating the detection and response to threats.
- Legacy Code Migration: Rebuilding legacy codebases in memory-safe languages.
To further support the industry, Anthropic has released Claude Security, a product utilizing frontier models like Claude Opus 4.8 to scan codebases and suggest patches. They are also providing specific tools developed for Project Glasswing partners to trusted security teams upon request.
Addressing the Patching Bottleneck
Anthropic notes that the primary bottleneck in cybersecurity is no longer finding vulnerabilities, but verifying, disclosing, and patching them. To address this, the company is collaborating with third parties to scale the reviewing and patching of open-source software and developing best practices for disclosing vulnerabilities to maintainers to streamline triage and action.
Future Roadmap and Safeguards
Anthropic intends to eventually release Mythos-level capabilities to the general public. However, this requires the development of robust safeguards to prevent misuse—safeguards that Anthropic states have not yet been developed by any AI developer.
Until these safeguards are exist, Anthropic will continue to expand Project Glasswing, prioritizing:
- Essential infrastructure providers.
- Maintainers of critical open-source software.
- Safety testers.
Additionally, the company plans to scale its Cyber Verification Program, which grants Mythos-class capabilities to organizations for specific cyberdefense tasks.
Sources
- OriginalExpanding Project Glasswing
Related
- Dispatch
- Dispatch
- Dispatch
- Dispatch
- Dispatch