/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Anthropic says Claude Mythos Preview has been used to find more than 10,000 high- or critical-severity vulnerabilities since the launch of Project Glasswing

Last month, we launched Project Glasswing, our collaborative effort to secure the world's most critical software before increasingly capable AI models can be turned against it.

Anthropic

Context & Ripple Effects

Project Glasswing was introduced as a collaborative effort to use Claude Mythos Preview to identify and remediate flaws in critical software, with access initially limited to more than 40 organizations maintaining that software.

The latest reported tally extends Anthropic’s earlier claim that the general-purpose model could uncover severe issues across major operating systems and browsers, turning a benchmark-and-demonstration narrative into an operational security program.

First-order effects

  • Organizations participating in Project Glasswing now have a substantially larger identified backlog of high- and critical-severity vulnerabilities to validate, prioritize, and patch.
  • Anthropic gains concrete deployment evidence for Mythos Preview’s use in vulnerability discovery, while retaining a restricted-distribution model rather than making the system generally available.

Second-order effects

  • Maintainers of widely used software may face increased remediation and disclosure workload as AI-assisted discovery raises the volume of actionable findings.
  • Other AI vendors and security-tool providers are pressured to demonstrate not only coding benchmarks but reliable, coordinated vulnerability-finding workflows for critical software owners.

Third-order effects

  • If AI systems consistently expand defensive discovery faster than maintainers can resolve findings, software security will shift toward continuous AI-assisted auditing paired with stronger triage and patch-management capacity.
  • Restricted access to highly capable cyber models may become a more common deployment pattern as providers balance defensive use cases against the risk that the same capabilities could aid attackers.

The trend: This is one data point in the move from general-purpose coding models being evaluated on benchmarks to being selectively deployed as infrastructure-security tools under controlled access.

Discussion

  • @anthropicai @anthropicai on x
    Last month we launched Project Glasswing, our collaborative AI cybersecurity initiative. Since then, we and our partners have found more than ten thousand high- or critical-severity vulnerabilities in essential software.
  • @scaling01 @scaling01 on x
    The compute story is cope. The gatekeeping story is cope. Mythos is genuinely much stronger than anything we've seen so far, and if Anthropic simply let it loose instead of starting Project Glasswing there would be millions-billions of dollars in damages.
  • @levie Aaron Levie on x
    Here's a key line in this mythos update. This is precisely an example of why engineers don't go away, ever. We've made it far easier to create and find security issues, which means the new bottleneck is our ability to actually review, respond to, and fix the issues. Far from [ima…
  • @anthropicai @anthropicai on x
    Patching these vulnerabilities will make us safer. But the software industry will need to adapt to the volume of vulnerabilities that models like Claude Mythos Preview will be able to find. We discuss this in our initial update on Project Glasswing: https://www.anthropic.com/...
  • @newton_cheng Newton Cheng on x
    An update on Project Glasswing, as well as some recent evaluation results on Mythos Preview.  One of the capabilities my team has been interested in since our initial testing is exploitation.  This is an area where we believe Mythos Preview has been a real leap over previous mode…
  • @scaling01 @scaling01 on x
    I don't understand how people are still coping about Mythos. Here's a few benchmarks: SWE-bench Pro: Mythos -> 77.8%, GPT-5.5 -> 58.6% HLE: Mythos -> 56.8%, GPT-5.5 -> 41.4% UK AISI cyber ranges: - “The Last Ones”: Mythos -> 6/10, GPT-5.5 3/10 - “Cooling Tower”: Mythos -> [image]
  • @ziv_ravid Ravid Shwartz Ziv on x
    Anthropic isn't releasing Mythos. The Official reason is that it's too dangerous and could be used to exploit zero-days at scale. Honest poll: how many of you think that if Anthropic had the compute to serve Mythos to everyone, they would still be holding it back? Quite the
  • Grant Anthony Grant Anthony on linkedin
    Anthropic just released the interim findings of Project Glasswing (Mythos Preview), and the TL:DR is as expected, Mythos found ten's of thousands …
  • @ericajoy.astrel.la Erica Joy Astrella on bluesky
    i suspect there's gonna be a race to burn 0-days before they get patched.  if so, things might get wild for a bit!  —  www.anthropic.com/research/gla...
  • @jjaron Jacob Aron on bluesky
    This is not a good change?  If the bottleneck is patching then we're becoming less secure www.anthropic.com/research/gla...  [image]
  • @isolyth.dev Eris on bluesky
    Glasswing update: they used mythos to find 10k+ high or critical severity vulnerabilities, cloudflare has found the false positive rate to be better than human testers, and they've used mythos to scan 1k+ OSS projects, finding 6k+ bugs with high or crit severity, and 23k total). …
  • Liia Sarjakoski Liia Sarjakoski on linkedin
    Anthropic published the first results from the Project Glasswing today.  —  Participating software companies have been releasing multiple times as many patches as usual. …
  • Dagobert L. Dagobert L. on linkedin
    Anthropic just released yesterday an initial Glasswing update, and with no surprises, the new bottleneck in cybersecurity is patching capabilities. …
  • @moultano Ryan Moulton on bluesky
    What would you count as intelligent?  Most recently, it reasoned for 250 pages and proved an important open math result, and found thousands of critical security vulnerabilities in important software.  Surely that's at least intelligence within those domains?  —  www.anthropic.co…