shiichan

Project Glasswing scales up: AI guards the world's critical software across about 150 organizations!

Hey everyone, it's Shiichan! Today I've got a news story that makes me sit up a little straighter: it's about AI and cybersecurity.

Anthropic News anthropic.com

What was announced?

From Anthropic's News, there's a big update: they're expanding Project Glasswing. Project Glasswing is their collaborative effort to secure the world's most important software. Back in early April, roughly 50 initial partners got access to Claude Mythos Preview and started scanning their codebases for vulnerabilities. So far, those partners have found more than 10,000 high- or critical-severity security flaws. That's a lot!

Now they're extending the partnership to about 150 new organizations. It's not open to everyone, though: each one has to meet Anthropic's security requirements before they get access.

Why it matters

The new organizations span more than 15 countries, and most of them provide critical infrastructure to many more. This round brings in industries that weren't well represented in the first cohort: power, water, healthcare, communications, and hardware. A lot of the new partners are vendors, too, meaning companies and nonprofits that maintain codebases relied on by tons of other organizations and governments.

What they all share is that a successful attack on their code could be catastrophic. Anthropic estimates that for most partners, a major attack could affect more than 100 million people. That's why hardening these systems matters so much.

What changes

Anthropic frames this as a step toward a lasting advantage for defenders. The thinking behind it goes like this:

"Cheap, fast AI models with powerful cyber capabilities are around the corner."

In other words, cheap and fast AI models with strong cyber capabilities are almost here. Anthropic expects that within 6 to 12 months, many other AI companies will have Mythos-class models, and some could release them without safeguards against misuse. In that world, cyberattacks could happen far more often and in less predictable forms, so defenders need to get ready first.

Dive Deep

Anthropic sees its role in two parts:

  • One, help the software industry adapt by safely providing wide access to better models, tools, and shared infrastructure.
  • Two, gradually shift its support from finding vulnerabilities toward disclosing, fixing, and shipping patched software.

Concretely, they released Claude Security, a product that uses the latest public frontier models like Claude Opus 4.8 to scan codebases and suggest patches. They're also releasing, on request and to trusted security teams, the internal tools they built to help Project Glasswing partners find vulnerabilities faster.

The bottleneck right now is verifying, disclosing, and patching the flood of vulnerabilities these models surface. Mythos Preview helps here too: partners use it to write patches and to run pre-release checks that stop vulnerabilities before they appear. It can also handle penetration testing, automate threat detection and response, and rebuild legacy codebases in memory-safe languages, among other defensive tasks.

Looking ahead, Anthropic is honest that releasing Mythos-level capabilities in general access needs strong, precise safeguards against misuse, something no one has built yet. So for now they plan to expand Project Glasswing further and to scale up their Cyber Verification Program, which grants Mythos-class capabilities to more organizations for specific cyberdefense tasks.

Wrap-up

  • Project Glasswing grows from roughly 50 to about 150 organizations, and joining requires meeting security requirements.
  • New partners span more than 15 countries, centered on critical-infrastructure operators and vendors in power, water, healthcare, communications, and hardware.
  • More than 10,000 high- or critical-severity flaws found so far; a major attack could affect over 100 million people.
  • The focus shifts from finding to disclosing, fixing, and shipping, via Claude Security, shared internal tools, and a growing Cyber Verification Program.
  • This one's for security teams, open-source maintainers, and critical-infrastructure operators, plus anyone who wants to think about the future of AI and security.