cyberivy
AI SecurityCyber IvyJune 2026AnthropicClaude MythosProject GlasswingVulnerability Research

Anthropic Expands Project Glasswing for Software Security

June 3, 2026

Anthropic is expanding Project Glasswing. Partners are using Claude Mythos Preview to find severe vulnerabilities in real codebases.

Anthropic describes Project Glasswing as a collaborative program to secure important software. After starting with roughly 50 partners, teams used Claude Mythos Preview on real codebases and reportedly found more than 10,000 high or critical severity flaws. The focus is not generic chat, but specialized security analysis.

Why it matters: If AI finds vulnerabilities at scale, it changes patch prioritization, disclosure processes, and the role of classic SAST tools.

What teams should do now: Treat AI findings as requiring triage, require reproducibility, and define disclosure processes before large-scale scanning.

πŸ’‘ In plain English

Specialized AI is not just reading text; it is checking code for real security problems.

Key Takeaways

  • β†’Project Glasswing targets important software supply chains.
  • β†’Mythos Preview is being used with selected partners.
  • β†’The scale of vulnerability findings becomes a governance issue itself.

FAQ

Is this an immediate production risk?

Not automatically. It becomes critical when companies turn AI findings into patch panic without triage or reproduction.

Sources & Context