{"id":600938,"date":"2026-05-24T05:12:22","date_gmt":"2026-05-24T05:12:22","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/600938\/"},"modified":"2026-05-24T05:12:22","modified_gmt":"2026-05-24T05:12:22","slug":"project-glasswing-an-initial-update-anthropic-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/600938\/","title":{"rendered":"Project Glasswing: An initial update \\ Anthropic"},"content":{"rendered":"<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Last month, we launched <a href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a>, our collaborative effort to secure the world\u2019s most critical software before increasingly capable AI models can be turned against it.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Since then, we and our approximately 50 partners have used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities across the most systemically important software in the world. Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it\u2019s limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In this post, we discuss what we\u2019ve learned about this critical challenge for cybersecurity in the first weeks of Project Glasswing. We focus on the early public evidence of Mythos Preview\u2019s performance, on the initial results of our effort to scan thousands of open-source software projects, and on what this progress means for cyberdefenders today. We also cover what to expect next from Project Glasswing, and how we\u2019re thinking about releasing Mythos-class models in the future.<\/p>\n<p>Our early resultsOur approach to discussing Mythos Preview\u2019s findings<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The software industry\u2019s longstanding convention is to disclose new vulnerabilities 90 days after they\u2019re discovered (or, if a patch is created before the 90 days is up, around 45 days after the patch becomes available). This allows time for end users to update their software before a vulnerability can be exploited by attackers. Our own <a href=\"https:\/\/www.anthropic.com\/coordinated-vulnerability-disclosure\" rel=\"nofollow noopener\" target=\"_blank\">Coordinated Vulnerability Disclosure policy<\/a> takes this approach.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">However, this means that disclosed vulnerabilities are a lagging indicator of the accelerating frontier of AI models\u2019 cyber capabilities: we\u2019re not yet at the point where we can fully detail our partners\u2019 findings with Mythos Preview without putting end users at risk. Instead, we provide illustrative examples of the model\u2019s performance, along with aggregate statistics on our progress to date. Once patches for the vulnerabilities that Mythos Preview has discovered are widely deployed, we\u2019ll provide much more detail about what we\u2019ve learned.<\/p>\n<p>Evidence from our partners and external testers<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Project Glasswing\u2019s initial partners build and maintain software that is fundamental to the functioning of the internet and other essential infrastructure. Fixing flaws in their code reduces risk for the many other organizations that rely on it, and therefore reduces risk for billions of end users.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">After one month, most partners have each found hundreds of critical- or high-severity vulnerabilities in their software. Collectively, they\u2019ve found more than ten thousand. Several have told us that their rate of bug-finding has increased by more than a factor of ten. For instance, <a href=\"https:\/\/blog.cloudflare.com\/cyber-frontier-models\/\" rel=\"nofollow noopener\" target=\"_blank\">Cloudflare<\/a> has found 2,000 bugs (400 of which are high- or critical-severity) across their critical-path systems, with a false positive rate that Cloudflare\u2019s team considers better than human testers.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This tallies with external testers\u2019 experience of Mythos Preview\u2019s performance, and with recent additional evaluations of the model:<\/p>\n<p>The UK\u2019s AI Security Institute <a href=\"https:\/\/www.aisi.gov.uk\/blog\/how-fast-is-autonomous-ai-cyber-capability-advancing\" rel=\"nofollow noopener\" target=\"_blank\">reports<\/a> that Mythos Preview is the first model to solve both of their cyber ranges (simulations of multistep cyberattacks) end to end;Mozilla <a href=\"https:\/\/blog.mozilla.org\/en\/privacy-security\/ai-security-zero-day-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">found and fixed<\/a> <a href=\"https:\/\/hacks.mozilla.org\/2026\/05\/behind-the-scenes-hardening-firefox\/\" rel=\"nofollow noopener\" target=\"_blank\">271 vulnerabilities<\/a> in Firefox 150 while testing Mythos Preview\u2014over ten times more than they found in Firefox 148 with Claude Opus 4.6;XBOW, an independent security platform, <a href=\"https:\/\/xbow.com\/blog\/mythos-offensive-security-xbow-evaluation\" rel=\"nofollow noopener\" target=\"_blank\">reports<\/a> that Mythos Preview is a \u201csignificant step up over all existing models\u201d on its web exploit benchmark, and provides \u201cabsolutely unprecedented precision\u201d on a token-for-token basis;<a href=\"http:\/\/exploitbench.ai\" rel=\"nofollow noopener\" target=\"_blank\">ExploitBench<\/a> and <a href=\"https:\/\/arxiv.org\/abs\/2605.11086\" rel=\"nofollow noopener\" target=\"_blank\">ExploitGym<\/a>, two recently released academic benchmarks for measuring models\u2019 exploit development capabilities, show Mythos Preview as the strongest performer. We discuss what these benchmarks tell us about the model in more detail on our <a href=\"https:\/\/red.anthropic.com\/2026\/exploit-evals\/\" rel=\"nofollow noopener\" target=\"_blank\">Frontier Red Team blog<\/a>.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">More generally, we\u2019re now seeing that patched software is being rolled out much more quickly. The latest Palo Alto Networks release included over <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2026\/05\/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update\/\" rel=\"nofollow noopener\" target=\"_blank\">five times<\/a> as many patches as usual. Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/05\/a-note-on-patch-tuesday\" rel=\"nofollow noopener\" target=\"_blank\">has reported<\/a> that the number of new patches they\u2019ll release will \u201ccontinue trending larger for some time.\u201d And Oracle is finding and fixing vulnerabilities across its products and cloud <a href=\"https:\/\/blogs.oracle.com\/security\/accelerating-vulnerability-detection-and-response-at-oracle\" rel=\"nofollow noopener\" target=\"_blank\">multiple times faster<\/a> than before.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Mythos Preview has also proved useful for other kinds of security work. For example, at one of our Glasswing partner banks, Mythos Preview helped to detect and prevent a fraudulent $1.5 million wire transfer after a threat actor compromised a customer\u2019s email account and made spoof phone calls.<\/p>\n<p>Open-source software<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">For the last few months, Anthropic has used Mythos Preview to scan more than 1,000 open-source projects, which collectively underpin much of the internet\u2014and much of our own infrastructure.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">So far, Mythos Preview has found what it estimates are 6,202 high- or critical-severity vulnerabilities in these projects (out of 23,019 in total, including those it estimates as medium- or low-severity).<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">1,752 of those high- or critical-rated vulnerabilities have now been carefully assessed by one of six independent security research firms, or in a small number of cases by ourselves. Of these, 90.6% (1,587) have proved to be valid true positives, and 62.4% (1,094) were confirmed as either high- or critical-severity. That means that even if Mythos Preview finds no further vulnerabilities, at our current post-triage true-positive rates, it\u2019s on track to have surfaced nearly 3,900 high- or critical-severity vulnerabilities in open-source code\u2014in addition to those it has found for Project Glasswing\u2019s partners. To be clear, we intend to continue scanning open-source code for some time, so we expect this number to rise.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">One example of an open-source vulnerability that Mythos Preview detected was in <a href=\"https:\/\/www.wolfssl.com\/\" rel=\"nofollow noopener\" target=\"_blank\">wolfSSL<\/a>, an open-source cryptography library that\u2019s known for its security and is used by billions of devices worldwide. Mythos Preview <a href=\"https:\/\/www.wolfssl.com\/how-claude-mythos-preview-helped-harden-wolfssl\/\" rel=\"nofollow noopener\" target=\"_blank\">constructed an exploit<\/a> that would let an attacker forge certificates that would (for instance) allow them to host a fake website for a bank or email provider. The website would look perfectly legitimate to an end user, despite being controlled by the attacker. We\u2019ll release our full technical analysis of this now-patched vulnerability (assigned <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-5194\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-5194<\/a>) in the coming weeks.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">As we noted above, the bottleneck in fixing bugs like these is the human capacity to triage, report, and design and deploy patches for them. Finding them in the first place has become vastly more straightforward with Mythos Preview. We\u2019ve created a <a href=\"https:\/\/red.anthropic.com\/2026\/cvd\/\" rel=\"nofollow noopener\" target=\"_blank\">dashboard of the open-source vulnerabilities<\/a> we\u2019ve scanned, below, which shows the different steps in our disclosure process and will track our progress over time. This shows vulnerabilities of all severity levels, rather than only the subset initially assessed as high- or critical-severity by Mythos Preview. Note the steep drop-off at each phase, reflecting the amount of human effort required to verify and fix each of the vulnerabilities.<\/p>\n<p><img loading=\"lazy\" width=\"1634\" height=\"1008\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\"  src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/05\/1779599542_870_image.webp\"\/>Our dashboard of open-source vulnerabilities, showing vulnerabilities of all severities (rather than only those estimated high- or critical-severity by Mythos Preview).<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Our process for triaging vulnerabilities is intensive. First, we or one of the external security firms we work with reproduce the issue that Mythos has found and re-assess its severity. Once we\u2019ve confirmed that a vulnerability is real, we check for whether there are already fixes in place, and write a detailed report to the software\u2019s maintainers. We take considerable care here: on top of the regular challenges of maintaining open-source software, maintainers have been facing a deluge of low-quality, AI-generated bug reports. Indeed, several maintainers have told us they\u2019re currently severely capacity constrained, and some have even asked us to slow down our rate of our disclosures because they need more time to design patches. (On average, a high- or critical-severity bug found by Mythos Preview takes two weeks to patch.)<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">On maintainers\u2019 request, we sometimes disclose bugs directly, without further assessment. We\u2019ve now reported 1,129 such unvetted bugs, of which Mythos Preview estimated that 175 were high- or critical-severity.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We estimate that we\u2019ve disclosed 530 high- or critical-severity bugs to maintainers so far. This is based on Claude\u2019s assessment of severity in the case of direct disclosures, and maintainers\u2019 or our security partners\u2019 assessment where available. There are a further 827 confirmed vulnerabilities (estimated as high- or critical-severity in the same manner) that we\u2019re aiming to disclose as quickly as possible.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">75 of the 530 high- or critical-severity bugs we\u2019ve reported have now been patched, and 65 of those have been given public advisories. The number of patches is still relatively low for three reasons. First, we\u2019re still early in the 90-day window that\u2019s set out in our Coordinated Vulnerability Disclosure policy: we expect many more patches to land soon. Second, we are likely to be undercounting patches because some vulnerabilities are patched without a public advisory: in those cases, we\u2019re reliant on scanning for the patches ourselves using Claude. Third, the low volume of patches reflects a genuine problem: even at our relatively slow pace of disclosures, Mythos Preview is adding to an already-overloaded security ecosystem.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity. Confronting this challenge successfully will make our software far safer than before. Below we discuss some ways that cyber defenders can adapt.<\/p>\n<p>Adapting to a new phase of cybersecurity<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Models with similar cybersecurity skills to Mythos Preview will soon be more broadly available. There is a clear need for a larger effort across the software industry to manage the volume of findings that these models will generate.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Currently, there\u2019s often a long lag between the discovery of a vulnerability, the creation of a patch for it, and the time when the patch is widely deployed by end users. This leaves open a significant window for attackers to exploit critical software. Mythos-class models significantly shrink the time and cost required to find and exploit vulnerabilities, magnifying the risk associated with these time lags. Ultimately, Mythos-class models will enable developers to build far more secure software by catching bugs before they are deployed. But this interim period\u2014while vulnerabilities are being rapidly discovered and slowly patched\u2014presents new risks.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Software developers and users should act now to reduce their exposure to these risks. The advice below is not new, and many researchers (including at Anthropic) are currently working on better and more durable solutions. In the meantime, it\u2019s important to get the basics right:<\/p>\n<p>Software developers should shorten their patch cycles and make security fixes available as quickly as possible. The thoughtful use of publicly available AI models can help here; we\u2019re building tools and sharing our research to support this (more details below). Developers should also help their users stay up-to-date with their software by making it as easy as possible to install updates; to the extent feasible, they should be more persistent with users who are still running software with known vulnerabilities.Network defenders should shorten their patch testing and deployment timelines. The critical controls laid out by organizations like the <a href=\"https:\/\/www.nist.gov\/cyberframework\" rel=\"nofollow noopener\" target=\"_blank\">National Institute of Standards and Technology<\/a> and the UK\u2019s <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/10-steps\/risk-management\" rel=\"nofollow noopener\" target=\"_blank\">National Cyber Security Centre<\/a> are now all the more important, since they improve security without depending on any single patch landing in time. These include steps like hardening networks\u2019 default configurations, enforcing multi-factor authentication, and keeping comprehensive logs for detection and response.Tools for cyberdefense with publicly available AI models<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Many generally-available models can already find large numbers of software vulnerabilities, even if they can\u2019t find the most sophisticated vulnerabilities or exploit them as effectively as Claude Mythos Preview. Project Glasswing has already spurred many other organizations to take action on their own codebases with these generally-available models; we\u2019re working to make this much easier to do.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">To begin, we\u2019ve released <a href=\"https:\/\/claude.com\/product\/claude-security\" rel=\"nofollow noopener\" target=\"_blank\">Claude Security<\/a> in public beta for Claude Enterprise customers. It\u2019s a tool that helps teams scan their codebases for vulnerabilities, and which can generate proposed fixes for them. In the three weeks since launch, Claude Opus 4.7 has been used to patch over 2,100 vulnerabilities. (This is faster than the open-source patching described above in large part because enterprises are fixing their own code, whereas open-source fixes usually require volunteer maintainers who work through coordinated disclosure.)<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019ve also begun our <a href=\"https:\/\/support.claude.com\/en\/articles\/14604842-real-time-cyber-safeguards-on-claude\" rel=\"nofollow noopener\" target=\"_blank\">Cyber Verification Program<\/a>, which allows security professionals using our models for legitimate cybersecurity purposes (such as vulnerability research, penetration testing, and red-teaming) to do so without certain safeguards designed to prevent cyber misuse.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Now, we\u2019re making the tools that we and our partners have used with Mythos Preview available to qualifying customers\u2019 security teams on request. Our aim is to make it much easier to get the best performance out of highly capable public models without extensive setup. This release includes:<\/p>\n<p>The <a href=\"https:\/\/code.claude.com\/docs\/en\/skills\" rel=\"nofollow noopener\" target=\"_blank\">skills<\/a> (custom instructions for repeated work) that we and our partners have built and shared;A harness that helps Claude map the codebase, spin up scanning subagents, triage its findings, and write reports;A threat model builder, which maps a codebase to identify potential targets for attack and prioritizes the model\u2019s work accordingly.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Cisco, one of our Project Glasswing partners, has also recently open-sourced its <a href=\"https:\/\/blogs.cisco.com\/ai\/announcing-foundry-security-spec\" rel=\"nofollow noopener\" target=\"_blank\">Foundry Security Spec<\/a> to help other defenders build an evaluation system similar to the one they use themselves.<\/p>\n<p>Supporting the ecosystem<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019ve formed a <a href=\"https:\/\/openssf.org\/press-release\/2026\/03\/17\/linux-foundation-announces-12-5-million-in-grant-funding-from-leading-organizations-to-advance-open-source-security\/\" rel=\"nofollow noopener\" target=\"_blank\">partnership<\/a> with the Open Source Security Foundation\u2019s Alpha-Omega project, which will support the foundation\u2019s efforts to assist maintainers in processing and triaging bug reports. We\u2019re also continuing to publish research into how frontier model capabilities can best support cyberdefenders.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019ve also supported the development of <a href=\"http:\/\/exploitbench.ai\" rel=\"nofollow noopener\" target=\"_blank\">ExploitBench<\/a> and <a href=\"https:\/\/rdi.berkeley.edu\/blog\/exploitgym\/\" rel=\"nofollow noopener\" target=\"_blank\">ExploitGym<\/a>, the two new benchmarks that allow researchers to track frontier AI models\u2019 exploit development capabilities over time, as we discuss <a href=\"https:\/\/red.anthropic.com\/2026\/exploit-evals\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>. We\u2019re supporting the development of other high-quality quantitative benchmarks through our <a href=\"https:\/\/support.claude.com\/en\/articles\/9125743-what-is-the-external-researcher-access-program\" rel=\"nofollow noopener\" target=\"_blank\">External Researcher Access Program<\/a>. Finally, <a href=\"https:\/\/claude.com\/contact-sales\/claude-for-oss\" rel=\"nofollow noopener\" target=\"_blank\">Claude for Open Source<\/a> supports maintainers and contributors, and we\u2019re committing to scan any open-source package that we adopt ourselves in the future.<\/p>\n<p>What&#8217;s next for Project Glasswing<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The speed of AI progress means that models as capable as Mythos Preview will soon be developed by many different AI companies. At present, no company\u2014including Anthropic\u2014has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm. That is why we have yet to release Mythos-class models to the public. But it\u2019s also why we began Project Glasswing: if a similarly capable model is released without such safeguards, it will soon become dramatically cheaper and easier for almost anyone in the world to exploit flawed software.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Glasswing helps the most systemically important cyber defenders gain an asymmetric advantage. However, there is an urgent need for as many organizations as possible to shore up their cyber defenses. We hope that our generally available models, and the new tools, resources, and research we\u2019re providing to accompany them, will support those organizations to improve their cybersecurity posture.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Next, we will work with critical partners\u2014including US and allied governments\u2014to expand Project Glasswing to additional partners. And in the near future, once we\u2019ve developed the far stronger safeguards we need, we look forward to making Mythos-class models available through a general release.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">On the far side of these risks, there\u2019s an encouraging world available to us: one in which important code is hardened far better than it is today, and in which hacking is far less prevalent. There are many obstacles, but we\u2019re nonetheless confident that Project Glasswing can help get us there.<\/p>\n","protected":false},"excerpt":{"rendered":"Last month, we launched Project Glasswing, our collaborative effort to secure the world\u2019s most critical software before increasingly&hellip;\n","protected":false},"author":2,"featured_media":598647,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-600938","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/600938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=600938"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/600938\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/598647"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=600938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=600938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=600938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}