{"id":620560,"date":"2026-06-04T09:59:43","date_gmt":"2026-06-04T09:59:43","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/620560\/"},"modified":"2026-06-04T09:59:43","modified_gmt":"2026-06-04T09:59:43","slug":"expanding-project-glasswing-anthropic","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/620560\/","title":{"rendered":"Expanding Project Glasswing \\ Anthropic"},"content":{"rendered":"<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><a href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a> is our collaborative effort to secure the world\u2019s most important software. In early April, we announced that roughly 50 initial partners had access to Claude Mythos Preview, and since then, they\u2019ve been deploying the model to scan their codebases for vulnerabilities. We recently <a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\" rel=\"nofollow noopener\" target=\"_blank\">described<\/a> how these partners have so far found more than 10,000 high- or critical-severity security flaws.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019re now expanding Project Glasswing. Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the US government, we\u2019re extending the partnership to approximately 150 new organizations. Each one will need to meet our security requirements before they gain access.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The organizations in this new group are based in more than 15 countries, and most provide critical infrastructure to many more. (In the future, we intend to expand our geographical reach much further.) The group covers several industries that weren\u2019t well represented in our initial cohort, such as power, water, healthcare, communications, and hardware. And many of the new partners are vendors\u2014companies or nonprofits that maintain codebases that are relied upon by lots of other organizations around the world, including governments.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This expansion is the next step toward our long-term goals: for AI to make all software more secure, and for us to help the industry adjust to how AI could change many of the core assumptions of cybersecurity.<\/p>\n<p>The role of Project Glasswing<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Project Glasswing and the capabilities of Claude Mythos Preview have sparked broad conversations\u2014both within the software industry and with governments\u2014about how AI is changing cybersecurity. These conversations have informed how we\u2019ve expanded the program. They\u2019ve also shaped our thinking about the very purpose of Project Glasswing.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Cheap, fast AI models with powerful cyber capabilities are around the corner. We want Project Glasswing to spur institutions toward operating norms that reflect this reality.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Mythos Preview continues a long-term trend that we\u2019ve been warning about for some time: within 6 to 12 months, we expect that many other AI companies will have Mythos-class models, and they could release them without safeguards that prevent misuse. In that world, cyberattacks could occur much more often, and in much more unpredictable forms. It\u2019s imperative that cyberdefenders <a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\" rel=\"nofollow noopener\" target=\"_blank\">adapt to maintain pace<\/a>.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We see our role as twofold. First, to help the software industry adapt by safely providing wide access to better models, tools, and common infrastructure. Second, to steadily shift the support we provide, from finding vulnerabilities to disclosing, fixing, and deploying patched software. We\u2019ll now discuss each of these in turn.<\/p>\n<p>Supporting cyberdefenders<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">So far, companies, nonprofits, maintainers, and researchers have acted quickly. Within the first weeks of Project Glasswing, each member began using Mythos Preview at large scale, sharing information and best practices with other partners, and working with third parties to triage the model\u2019s findings. These organizations\u2019 methods for adapting to new tools can, and should, be replicated widely across the millions of organizations and developers who are vulnerable to cyberattacks.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">To support this, we recently released <a href=\"https:\/\/claude.com\/product\/claude-security\" rel=\"nofollow noopener\" target=\"_blank\">Claude Security<\/a>, a product that uses our latest public frontier models, like Claude Opus 4.8, to scan codebases and suggest patches. We&#8217;re also releasing\u2014on request, to trusted security teams\u2014<a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\" rel=\"nofollow noopener\" target=\"_blank\">the tools<\/a> we developed to help Project Glasswing\u2019s partners find vulnerabilities more quickly.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We intend to go much further: our longer-term aim is to support the industry in creating new initiatives, standards, and infrastructure for the era of powerful cyber models.<\/p>\n<p>Accelerating patching and the rest of security<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">As we\u2019ve <a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\" rel=\"nofollow noopener\" target=\"_blank\">previously discussed<\/a>, the bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Mythos Preview itself can help. Many of Project Glasswing\u2019s partners now use the model to write patches, as well as for pre-release checks that prevent vulnerabilities from appearing in the first place. Models like Mythos Preview can also be used for penetration testing (simulating a cyberattack to identify how vulnerabilities might be exploited), automating threat detection and response, and rebuilding legacy codebases in memory-safe languages, among many other defensive tasks.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019re in discussions with third parties about how we might substantially scale up the reviewing and patching of vulnerabilities in open-source software. We\u2019re also working on sharing ideas and best practices for disclosing vulnerabilities to open-source maintainers, with the intent of making these reports easier to triage and to act upon.<\/p>\n<p>The path ahead<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">To address the scale of this coming challenge, hundreds of thousands of organizations, researchers, and maintainers will likely need access to the most advanced cyber capabilities and tools available.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We\u2019re working as quickly as we can to safely release Mythos-level capabilities in general access. To do so, we\u2019ll need highly robust safeguards that prevent the model\u2019s cyber capabilities from being misused\u2014safeguards that we (and, to our knowledge, all other AI developers) have yet to develop. Because cybersecurity has both helpful and destructive uses, making safeguards that are both strong and precise enough is a major challenge.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In the meantime, we plan to expand Project Glasswing even further\u2014prioritizing additional essential infrastructure providers, maintainers of critical open-source software, and safety testers. We intend for future expansions to cover organizations in the US and overseas, just as this one does. We also intend to scale up our Cyber Verification Program, which would grant Mythos-class capabilities to many more organizations for specific cyberdefense tasks.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In the future, frontier model releases will become increasingly high-stakes. Capabilities will continue to improve across all domains, including many that\u2014like cybersecurity\u2014can empower attackers and defenders alike. This will not be the last time we need to confront a challenge like this one. But Project Glasswing has taught us a great deal about how to respond when models cross important capability thresholds. If we\u2019re successful, we hope to enable a permanent advantage for defenders.<\/p>\n","protected":false},"excerpt":{"rendered":"Project Glasswing is our collaborative effort to secure the world\u2019s most important software. In early April, we announced&hellip;\n","protected":false},"author":2,"featured_media":620561,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-620560","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/620560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=620560"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/620560\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/620561"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=620560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=620560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=620560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}