Anthropic Launches Project Glasswing with Mythos AI Model to Address Cybersecurity Vulnerabilities
Anthropic has introduced a preview version of its AI model, Claude Mythos, through Project Glasswing, a collaboration with over 40 tech and cybersecurity firms. The initiative aims to identify and mitigate vulnerabilities in software systems before broader release. Partners including Microsoft, Google, and Apple will test the model on their infrastructure to uncover potential exploits.
WiredAnthropic announced Project Glasswing on Tuesday, a cybersecurity initiative centered on a preview of its new AI model, Claude Mythos. The model demonstrates advanced capabilities in vulnerability discovery, exploit development, and penetration testing.
Over 40 organizations, including Microsoft, Apple, Google, Amazon Web Services, Nvidia, Cisco, Broadcom, the Linux Foundation, CrowdStrike, and Palo Alto Networks, have private access to Mythos Preview for testing on their systems.
The collaboration provides participants time to address vulnerabilities identified by the model, following principles of coordinated vulnerability disclosure. Anthropic states that Mythos Preview has already uncovered thousands of critical vulnerabilities, including decades-old bugs in scrutinized code.
The model excels at tasks such as producing attack chains, proofs of concept, endpoint security assessments, hunting system misconfigurations, and evaluating software binaries without source code access.
Model Capabilities and Industry Implications Claude Mythos was trained for code proficiency, which results in strong performance in cybersecurity tasks without specific training for them.
Anthropic CEO Dario Amodei noted that the model's abilities represent a significant advancement in AI-assisted security analysis.
“Claude Mythos preview is a particularly big jump," Anthropic CEO Dario Amodei said on Tuesday in a Project Glasswing launch video. "We haven't trained it specifically to be good at cyber. We trained it to be good at code, but as a side effect of being good at code, it's also good at cyber.”
The model has identified security problems in every major operating system and web browser, according to Anthropic. This capability raises concerns about AI's dual-use potential, where it can aid defenders but also enable attackers to develop exploits more efficiently.
Partners expressed support for the initiative. Google's vice president of security engineering, Heather Adkins, stated that AI poses new challenges and opportunities in cyber defense. Microsoft's global CISO, Igor Tsyganskiy, highlighted the opportunity to use AI to improve security at scale.
Broader Context and Future Plans Anthropic is limiting the initial rollout of Mythos to this industry group to mitigate risks from its cybersecurity prowess. The company emphasizes the need for preparation as more powerful AI models emerge across the sector, potentially disrupting current security paradigms. > "The real message is that this is not about the model or Anthropic," Logan Graham, the company's frontier red team lead, tells WIRED. "We need to prepare now for a world where these capabilities are broadly available in 6, 12, 24 months. Many things would be different about security." Logan Graham, Anthropic's frontier red team lead, indicated that the model achieves results comparable to those of a senior security researcher. Project Glasswing serves as a starting point for broader industry exploration, with Anthropic calling for expanded global collaboration to address emerging AI-driven threats.
Story Timeline
4 events- Tuesday
Anthropic announced Project Glasswing and provided private access to Claude Mythos Preview to over 40 partner organizations.
6 sourcesWired · CNBC · TechCrunch · NYT - Prior to Tuesday
Mythos Preview testing uncovered thousands of critical vulnerabilities in partner systems, including decades-old bugs.
2 sourcesWired · The Verge - Ongoing since launch
Partners began using Mythos Preview to identify exploits and mitigations in operating systems and web browsers.
3 sourcesWired · The Verge · NYT - 6-24 months ahead
Anthropic anticipates broader availability of similar AI capabilities, prompting security paradigm preparations.
1 sourceWired
Potential Impact
- 01
Tech firms patch thousands of vulnerabilities identified by Mythos in their systems.
- 02
AI tools integrate into standard cybersecurity workflows at partner companies.
- 03
Attackers gain easier access to exploit development tools as models proliferate.
- 04
Industry adopts coordinated disclosure practices for AI-discovered exploits.
- 05
Global collaboration expands beyond initial 40 organizations to include more entities.
Transparency Panel
Related Stories
SemaforAnthropic Co-Founder Warns of Upcoming AI Capabilities for Exploiting Web Vulnerabilities
Anthropic's co-founder stated that powerful AI models capable of exploiting website vulnerabilities will emerge soon. The company's new model, Claude Mythos, identified unknown security flaws in major web browsers and operating systems. Financial authorities have responded by dis…
Los Angeles TimesGallup Poll Shows Increasing AI Use Among US Workers with Persistent Skepticism
A Gallup poll conducted in February indicates that more American workers are using artificial intelligence in their jobs, with about 3 in 10 using it frequently. However, skepticism remains common, with many non-users citing preferences for traditional methods, ethical concerns,…
Federal Bureau of Investigation / Wikimedia (Public domain)AI Assistant Poke Charges Billionaire $136,000 Monthly Fee
Poke, an AI assistant without a price ceiling, charged one billionaire $136,000 a month. Marvin von Hagen stated this pricing detail. The information highlights Poke's premium service model.