Project Glasswing targets AI-powered software vulnerability hunting

Anthropic announced Project Glasswing, a security initiative with AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, Palo Alto Networks and others to use its unreleased Claude Mythos Preview model for defensive cyber work. The company said the model has already found thousands of high-severity and zero-day vulnerabilities across major operating systems and browsers, and that it will share findings with partners and the broader industry.

Project Glasswing targets AI-powered software vulnerability hunting

Anthropic has launched Project Glasswing, a security initiative it says will use its unreleased Claude Mythos Preview model for defensive cyber work alongside a long list of technology and security partners, including AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike and Palo Alto Networks.

The announcement, published on Anthropic’s news site on April 7, positions the project as an effort to use frontier AI models for finding and reporting software flaws before attackers can exploit them. Anthropic said the model has already identified thousands of high-severity vulnerabilities, including zero-day issues, across major operating systems and web browsers.

⚡ New to this?

Project Glasswing is Anthropic’s name for a security program that uses an unreleased version of Claude to look for software vulnerabilities. A vulnerability is a weakness in code that attackers can use to break into systems, and a zero-day is one that the software maker does not know about yet, so there is no fix ready at the time it is found.

The reason this matters is that AI is starting to move from helping people write code to helping security teams find bugs in that code. If these models can reliably spot serious flaws in operating systems and browsers, they could change how quickly vendors discover and patch problems that affect a lot of users.

🦞 OpenClaw angle

For builders and self-hosters, this is a sign that AI-assisted vuln discovery is moving from theory to production security workflows. For IT and security teams, it raises the bar for patch management, disclosure processes and safe use of frontier models in defensive tooling.

Zero-day vulnerabilities are security bugs that are unknown to the vendor at the time they are found, which means there is no patch available yet. High-severity flaws are the kinds of issues that can lead to serious compromise if they are abused, especially in systems that are widely deployed or exposed to the internet.

Project Glasswing is notable because it is framed as a partner-driven security effort rather than a narrow internal research exercise. Anthropic said it is working with companies across cloud infrastructure, device platforms, network security and endpoint protection, a mix that reflects how modern vulnerability research often spans multiple layers of the software stack.

That matters because many of the most damaging security problems are not isolated to one product. A flaw in a browser, operating system component or common library can affect large numbers of users and create a path for persistence, data theft or broader system compromise.

Anthropic said findings from the project will be shared with partners and the wider industry. That implies a disclosure pipeline, where security researchers or vendors notify affected companies so they can validate the issue, develop fixes and coordinate release of patches or advisories.

The company has not publicly released the model behind the project. Claude Mythos Preview appears to be an internal or unreleased variant of Anthropic’s Claude line, and the name suggests the work is happening in a controlled preview environment rather than as a general-purpose product feature.

Using an unreleased model for cyber defense is also a sign of where AI security research is headed. Instead of relying only on human researchers to manually inspect code, fuzz applications or triage results, companies are increasingly testing whether large models can help surface bugs faster and at larger scale.

That shift comes with its own risks. AI systems can generate false positives, miss context or produce findings that need careful human validation before they are treated as real vulnerabilities. In security work, speed matters, but so does accuracy, especially when reporting bugs that may affect operating systems, browsers and widely used infrastructure.

Anthropic’s project also lands in a broader industry push to apply AI to defensive security rather than just content generation or coding assistance. Vendors across cloud, endpoint and network security have been trying to fold machine learning into detection, triage and analysis for years, but frontier models may change how quickly researchers can identify patterns in source code, binaries and exploit paths.

The company said the project is intended to expand collaboration with major platform and security vendors, while sharing discovered issues with the broader industry as they are validated and disclosed.

Source: Anthropic News ↗

More from Security News