Anthropic expands Project Glasswing to 150+ organizations, discovering over 10,000 high-severity vulnerabilities

Anthropic has expanded Project Glasswing from 50 to 150+ organizations (15+ countries), covering critical infrastructure areas such as power/water/health/communications, etc., and partners have discovered more than 10,000 high-risk/critical vulnerabilities.

Anthropic has announced a significant expansion of its Project Glasswing cybersecurity partnership—from approximately 50 initial partners to more than 150 organizations spanning more than 15 countries, including new critical infrastructure sectors such as power, water, healthcare, communications, and hardware. Partners have discovered more than 10,000 high-severity or critical security vulnerabilities in the code base using Claude Mythos Preview, and Anthropic is launching its Claude Security product simultaneously.

Project Glasswing extended promotional image

Expand scale

Working closely with existing partners, the security industry, open source software maintainers, and the U.S. government, each new organization will need to meet Anthropic's security requirements to gain access. Newly added industries – power, water, healthcare, communications and hardware – were underrepresented among the first partners. Many of the new partners are vendors, companies or nonprofits that maintain code bases relied upon by numerous organizations around the world, including governments.

Strategic Judgment

Anthropic gave a clear timeline: The era of cheap, fast AI models with strong network capabilities is coming. It is expected that within the next 6 to 12 months, many other AI companies will also have Mythos-level models, and may be released without safety guardrails. Project Glasswing's mission is thus divided into two levels: first, to help the software industry adapt by safely providing better models, tools, and public infrastructure; second, to gradually shift the focus of support from "discovering vulnerabilities" to "disclosing, fixing, and deploying patches."

Tools and Products

Anthropic's recently released Claude Security uses the latest public cutting-edge models such as Claude Opus 4.8 to scan the code base and recommend patches. At the same time, Anthropic provides internal tools to trusted security teams on demand to help partners discover vulnerabilities more quickly. Officials pointed out that the bottleneck of network security has shifted from "discovering vulnerabilities" to "verifying, disclosing and patching the huge number of vulnerabilities discovered by the Mythos-level model" - many partners have begun to use the model to write patches and conduct pre-release inspections to prevent vulnerabilities from appearing at the source.

10,000+ high-severity vulnerabilities were discovered in a matter of weeks. This number itself shows that the network attack and defense capabilities of the Mythos-level model far exceed that of human security teams. The 6-12 month window forecast given by Anthropic is even more eye-catching - if other companies do release Mythos-level models without guardrails during this period, AI network security will officially enter the "arms race" stage.

Project Glasswing covers 15+ countries, works closely with the U.S. government, and targets critical infrastructure such as power and water services. It has been upgraded from a corporate security project to a strategic project with national security significance. For the domestic AI security field, similar AI vulnerability detection systems are still in their early stages - whether the cooperation between domestic network security companies and AI companies can refer to Project Glasswing's "Directed Openness + Security Requirements" framework is a direction worth exploring.

Worth following up on:

  1. 6-12 Month Window Accuracy: Actual Timeline for Other Companies to Release Mythos-Class Models
  2. Claude Security’s commercialization progress: Can AI vulnerability scanning tools become an independent product line?
  3. Scale repair of open source software vulnerabilities: Progress and specific plans for cooperation with third parties
  4. Vulnerability Fix Rate: How many of the 10,000+ discovered vulnerabilities were actually fixed?
Copyright: Content sourced from Anthropic official announcement . This platform has compiled and organized this content for informational purposes and learning exchange only. If there are any copyright concerns, please contact us for resolution.

Reviews

  • Loading reviews...