security
Apr 7, 2026
By Teun
Project Glasswing targets AI-powered software vulnerability hunting
Anthropic announced Project Glasswing, a security initiative with AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, Palo Alto Networks and others to use its unreleased Claude Mythos Preview model for defensive cyber work. The company said the model has already found thousands of high-severity and zero-day vulnerabilities across major operating systems and browsers, and that it will share findings with partners and the broader industry.
Anthropic has launched Project Glasswing, a security initiative it says will use its unreleased Claude Mythos Preview model for defensive cyber work alongside a long list of technology and security partners, including AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike and Palo Alto Networks.
The announcement, published on Anthropic’s news site on April 7, positions the project as an effort to use frontier AI models for finding and reporting software flaws before attackers can exploit them. Anthropic said the model has already identified thousands of high-severity vulnerabilities, including zero-day issues, across major operating systems and web browsers.
Zero-day vulnerabilities are security bugs that are unknown to the vendor at the time they are found, which means there is no patch available yet. High-severity flaws are the kinds of issues that can lead to serious compromise if they are abused, especially in systems that are widely deployed or exposed to the internet.
Project Glasswing is notable because it is framed as a partner-driven security effort rather than a narrow internal research exercise. Anthropic said it is working with companies across cloud infrastructure, device platforms, network security and endpoint protection, a mix that reflects how modern vulnerability research often spans multiple layers of the software stack.
That matters because many of the most damaging security problems are not isolated to one product. A flaw in a browser, operating system component or common library can affect large numbers of users and create a path for persistence, data theft or broader system compromise.
Anthropic said findings from the project will be shared with partners and the wider industry. That implies a disclosure pipeline, where security researchers or vendors notify affected companies so they can validate the issue, develop fixes and coordinate release of patches or advisories.
The company has not publicly released the model behind the project. Claude Mythos Preview appears to be an internal or unreleased variant of Anthropic’s Claude line, and the name suggests the work is happening in a controlled preview environment rather than as a general-purpose product feature.
Using an unreleased model for cyber defense is also a sign of where AI security research is headed. Instead of relying only on human researchers to manually inspect code, fuzz applications or triage results, companies are increasingly testing whether large models can help surface bugs faster and at larger scale.
That shift comes with its own risks. AI systems can generate false positives, miss context or produce findings that need careful human validation before they are treated as real vulnerabilities. In security work, speed matters, but so does accuracy, especially when reporting bugs that may affect operating systems, browsers and widely used infrastructure.
Anthropic’s project also lands in a broader industry push to apply AI to defensive security rather than just content generation or coding assistance. Vendors across cloud, endpoint and network security have been trying to fold machine learning into detection, triage and analysis for years, but frontier models may change how quickly researchers can identify patterns in source code, binaries and exploit paths.
The company said the project is intended to expand collaboration with major platform and security vendors, while sharing discovered issues with the broader industry as they are validated and disclosed.