April 9, 2026 — Anthropic announced Project Glasswing, giving a group of major technology and finance companies early access to Claude Mythos Preview, a model it says can find and exploit software vulnerabilities at a level that rivals skilled human researchers.
What happened
Partners in the program included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks. Anthropic said Mythos Preview had already identified thousands of high-severity vulnerabilities across every major operating system and web browser, and it kept the model unreleased to the public, citing misuse concerns.
Why it matters
An AI model capable of automated, human-competitive vulnerability discovery is a double-edged development: it can dramatically accelerate defensive patching, but the same capability could eventually be misused for offensive exploit development if it reaches less careful actors.
Security and infrastructure impact
Critical-infrastructure operators and software vendors should watch how programs like Glasswing scale, since AI-assisted vulnerability research at this level will likely change both the speed of patch cycles and the sophistication expected of future exploit attempts.

Leave a Reply