Expanding Project Glasswing
Anthropic is expanding Project Glasswing to about 150 more organizations to help them find, fix, and prevent serious software vulnerabilities.
Intelligence analysis by GPT-5.4 Mini

Anthropic says Project Glasswing is moving from a small initial group to a much wider set of critical infrastructure providers, vendors, maintainers, and security teams. The company frames the expansion as a response to faster, cheaper AI models with stronger cyber capabilities and the need for defenders to adapt.
A powerful computer helper found lots of hidden holes in big software systems. Anthropic is now giving that helper to more trusted groups, so they can spot problems faster and patch them like fixing cracks in a dam before water leaks through.
Analysis
What Anthropic is expanding
Anthropic says it is extending Project Glasswing, its collaborative effort to secure important software, from an initial group of roughly 50 partners to about 150 new organizations. The new participants must meet security requirements before they get access. The company says the group spans more than fifteen countries and includes organizations in power, water, healthcare, communications, and hardware.
What the program is for
The article says the partners are using Claude Mythos Preview to scan codebases for vulnerabilities, and that the initial group has already found more than ten thousand high- or critical-severity security flaws. Anthropic describes the goal as helping software become more secure while preparing the security industry for AI systems that can find and exploit bugs far more quickly than before.
The defensive focus
Anthropic says it is releasing some of the tools built for Project Glasswing on request to trusted security teams. It also says it has created Claude Security, a product that uses its frontier public models, including Claude Opus 4.8, to scan codebases and suggest patches. Beyond finding bugs, the company says the model can help with patch writing, penetration testing, threat detection and response, and rebuilding legacy code in memory-safe languages.
The broader warning
The company argues that within 6 to 12 months, many other AI companies may have Mythos-class models, possibly without safeguards that prevent misuse. In that scenario, Anthropic expects cyberattacks to become more frequent and less predictable, which is why it sees stronger defensive tooling, better disclosure workflows, and faster patching as urgent next steps.
Key points
- Anthropic is expanding Project Glasswing from about 50 initial partners to roughly 150 new organizations.
- The new group includes critical infrastructure and vendor organizations across more than fifteen countries.
- The company says the initial partners have already found more than ten thousand high- or critical-severity flaws.
- Anthropic is releasing some internal support tools to trusted security teams and promoting Claude Security for scanning and patch suggestions.
- The article argues that AI will force cybersecurity defenders to adapt to faster vulnerability discovery and patching.
If the expansion works as intended, more critical systems could find and fix dangerous flaws before attackers exploit them. The tools and practices from the program could also spread to more organizations, making software safer across the industry.
The article says the main bottleneck is now verifying, disclosing, and patching the huge number of flaws AI can uncover, so teams could still be overwhelmed. It also warns that if similar cyber-capable models spread without safeguards, attacks could become more frequent and harder to predict.



