MITINDIA PRIVY
Trigent-Banner

Anthropic Begins Project Glasswing to Hunt Software Flaws With AI

The restricted program gives select technology companies and software maintainers early access to Anthropic’s unreleased Claude Mythos Preview model for defensive cyber work.

Topics

  • Anthropic has launched a restricted cybersecurity program giving companies such as Apple, Microsoft and Google early access to its unreleased Claude Mythos Preview model, betting defenders need a head-start as AI gets better at finding software flaws.

    The initiative, called Project Glasswing, also includes Amazon Web Services, Broadcom, Cisco, CrowdStrike, JPMorgan Chase, the Linux Foundation, Nvidia and Palo Alto Networks.

    The company said Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.

    Under Glasswing, the launch partners will use the model in defensive security work, while Anthropic says it will share what it learns with the broader industry.

    Anthropic is also extending access to more than 40 additional organizations that build or maintain critical software infrastructure, including open-source systems.

    The company said the work is likely to focus on vulnerability detection, black-box testing of binaries, endpoint security and penetration testing across systems that make up a large share of the world’s cyberattack surface.

    The model remains under tight control. Anthropic said it does not plan to make Claude Mythos Preview generally available, reflecting its view that the same capabilities that can help defenders fix flaws could also make attacks more frequent and more destructive if they spread too quickly.

    Anthropic said it will commit as much as $100 million in usage credits to Glasswing participants and another $4 million in donations to open-source security groups.

    The donations include $2.5 million through the Linux Foundation for Alpha-Omega and OpenSSF, and $1.5 million for the Apache Software Foundation.

    Within 90 days, Anthropic said it will publish what the program has learned, including vulnerabilities fixed and improvements that can be disclosed.

    Anthropic has separately outlined examples of why it is treating the model as unusually sensitive, saying Mythos Preview found a now-patched 27-year-old bug in OpenBSD, identified a 16-year-old vulnerability in FFmpeg, and in separate tests chained Linux kernel flaws to gain root access.

    These show that that the model can not only spot bugs, but that it can reason through how to turn them into working exploits.

    The company has said that frontier AI models are approaching a point where keeping the strongest systems tightly held, while giving select defenders early access, may be safer than broad release.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.