Project Glasswing: the largest cybersecurity initiative of the AI era brings together tech giants to protect the software that runs the world
Cybersecurity has never been as urgent a topic as it is right now.
Artificial intelligence has reached a point where it can do what only the best human specialists could do, and it does so autonomously, at a scale and speed that no security team can keep up with. For years, the idea that a machine could surpass the analytical ability of a senior security engineer sounded like science fiction. Today, that reality is already happening, and it didn’t exactly send a heads-up before arriving.
This is exactly the scenario that sparked the birth of Project Glasswing, an initiative that brings together some of the biggest names in global technology — AWS, Apple, Microsoft, Google, Cisco, CrowdStrike, NVIDIA, Broadcom, JPMorganChase, Palo Alto Networks, and the Linux Foundation — led by Anthropic, to tackle head-on a problem that is growing faster than traditional defenses can respond. The project’s name says a lot about the mission: glasswing, the butterfly with transparent wings, represents the idea of making the hidden visible, illuminating what was in the shadows, bringing to the surface vulnerabilities that the human eye simply couldn’t see.
At the center of it all is Claude Mythos Preview, a frontier model not yet publicly released that has already found thousands of high-severity zero-day vulnerabilities across all major operating systems and browsers in the world. Flaws that survived for decades without any human, and not even millions of automated tests, being able to detect them. And the most important point here isn’t just what this model found, but what this discovery means for the future of digital security.
If AI has already reached this level, the question that remains is: who will get to the next vulnerabilities first, the defenders or the attackers? That’s the race Project Glasswing wants to win, and what’s at stake goes far beyond lines of code. 🔐
What Project Glasswing actually proposes
The core proposal of Project Glasswing goes beyond a simple partnership between tech companies. What’s being built here is a collaborative cyber defense infrastructure powered by artificial intelligence, where the goal isn’t just to find flaws but to create an ecosystem capable of identifying, classifying, prioritizing, and reporting vulnerabilities in critical software continuously and on a global scale. This represents a profound paradigm shift in how the industry thinks about digital security, moving from a reactive model to an essentially proactive one.
For decades, the cybersecurity playbook was basically this: someone discovers a flaw, reports it, a patch is developed, and the cycle starts over. The problem is that this cycle has always been way too slow, especially when you consider that malicious actors have also evolved. With AI tools available on the market, automated attacks, mass exploitation of known vulnerabilities, and even autonomous discovery of new flaws by hostile actors are already a documented reality. Glasswing emerges precisely to flip that equation, putting proactive discovery capability on the defenders’ side.
The Claude Mythos Preview model, developed by Anthropic, is the main engine behind this initiative. Unlike conventional static code analysis tools or traditional fuzzing, this model can reason about software behavior at a much deeper level, identifying patterns that completely escape existing automated approaches. The early results have already been striking: vulnerabilities in widely used operating systems and browsers that form the backbone of the modern internet, flaws that existed for years, some for decades, without ever being detected. This isn’t a minor detail. It’s concrete evidence that AI is operating at an entirely different level of analysis than anything that came before.
The partners and the investment behind the initiative
The list of launch partners for Project Glasswing is impressive on its own: Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Each of these organizations brings a specific expertise to the table that complements the others, from cloud infrastructure providers to network security leaders, open source maintainers, and global-scale financial institutions.
But the consortium doesn’t stop at the launch partners. Anthropic has also extended access to Claude Mythos Preview to a group of more than 40 additional organizations that build or maintain critical infrastructure software. These organizations can use the model to scan and protect both proprietary systems and open source projects, which significantly expands the project’s defensive reach.
From a financial standpoint, Anthropic is committing up to $100 million in usage credits for Claude Mythos Preview across these efforts. On top of that, the company made direct donations of $2.5 million to Alpha-Omega and OpenSSF through the Linux Foundation, and $1.5 million to the Apache Software Foundation, totaling $4 million in direct donations to open source security organizations. This investment is particularly important because many of the world’s most critical software systems are maintained by open source communities with limited resources, and historically these communities have been left on their own when dealing with security issues.
After the initial research period, Claude Mythos Preview will be available to participants at a cost of $25 per million input tokens and $125 per million output tokens, with access through the Claude API, Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry. 💰
The vulnerabilities Claude Mythos Preview has already found
The practical results from Claude Mythos Preview are what really grab attention in this whole story. Over the past few weeks, the model was used to identify thousands of zero-day vulnerabilities — meaning flaws that were completely unknown to the developers of the affected software. Many of these vulnerabilities are classified as critical and affect all major operating systems and browsers, along with a range of other widely used software.
Three specific examples illustrate exactly what we’re talking about:
- A 27-year-old flaw in OpenBSD: OpenBSD is known as one of the most security-hardened operating systems in the world and is widely used to run firewalls and other critical infrastructure. Mythos Preview found a vulnerability that allowed an attacker to remotely crash any machine running the system simply by connecting to it. Twenty-seven years without anyone noticing.
- A 16-year-old flaw in FFmpeg: FFmpeg is an essential library used by countless software applications for encoding and decoding video. The vulnerability was in a line of code that automated testing tools had processed five million times without ever identifying the problem. Five million executions, zero detections, until Mythos Preview analyzed the code.
- Privilege escalation in the Linux kernel: The model found and autonomously chained together multiple vulnerabilities in the Linux kernel — the software that runs on most servers in the world — allowing an attacker to escalate from regular user access to full control of the machine. And it did this without any human guidance.
All of these vulnerabilities have already been reported to the respective software maintainers and have been fixed. For many other discovered flaws, Anthropic published cryptographic hashes of the details on the Frontier Red Team blog and will reveal the full specifics once the fixes are in place. The fact that the model was able to identify nearly all of these vulnerabilities and develop related exploits in a fully autonomous way, without human guidance, is the most impressive data point in this equation. 🤖
Why critical software is the priority target
When we talk about critical software, we’re talking about systems that directly affect the lives of billions of people: operating systems, browsers, widely distributed open source libraries, cloud infrastructure, communication platforms, and financial systems. A single vulnerability in this type of software can have an enormous cascading effect, compromising not just one user or one company but an entire chain of technological dependencies.
The global costs of cybercrime are difficult to estimate precisely, but data suggests they may be in the range of $500 billion per year. And the consequences go far beyond the financial. We’ve already seen serious attacks compromising corporate networks, healthcare systems, energy infrastructure like the Colonial Pipeline incident, airports, and the information security of government agencies across multiple countries. State-sponsored attacks from actors like China, Iran, North Korea, and Russia threaten to compromise the infrastructure that supports both civilian life and military readiness. Even smaller attacks targeting individual hospitals or schools cause substantial economic damage, expose sensitive data, and can put lives at risk.
Project Glasswing understands that protecting this type of software is a priority of a different order. We’re not talking about protecting a single app or a specific service. We’re talking about protecting the foundations on which all modern digital infrastructure has been built. And that’s why the consortium formed by the project brings together precisely the companies that develop, maintain, and distribute these systems.
The logic here is both simple and powerful: if you can identify and fix vulnerabilities in critical software before malicious actors find and exploit them, you effectively shift the balance of power in cyber warfare. And with an AI model capable of analyzing millions of lines of code in a timeframe that would be impossible for any human team, this proactive identification stops being an ambitious goal and becomes an operational reality.
What partners are saying about the results
The partners who already had access to Claude Mythos Preview over the past few weeks shared impressions that reinforce the gravity of the moment and the relevance of the project.
Cisco’s CEO emphasized that AI capabilities have crossed a threshold that fundamentally changes the urgency needed to protect critical infrastructure, and that there’s no going back. According to him, the initial work with these models showed that it’s possible to identify and fix security vulnerabilities in hardware and software at a pace and scale that were previously impossible.
AWS highlighted that their teams analyze more than 400 trillion network flows per day looking for threats, and that AI is central to their ability to defend at scale. They’re already testing Mythos Preview in their own security operations and applying it to critical codebases.
Microsoft mentioned that when tested against CTI-REALM, their open source security benchmark, Claude Mythos Preview showed substantial improvements compared to previous models. Igor Tsyganskiy, Executive VP of Cybersecurity and Microsoft Research, emphasized the unprecedented opportunity to use AI responsibly to improve security and reduce risk at scale.
CrowdStrike pointed out that the window between discovering a vulnerability and its exploitation by an adversary has completely collapsed: what used to take months now happens in minutes with AI. George Kurtz, the company’s president, highlighted that Mythos Preview demonstrates what is now possible for defenders at scale, and that adversaries will inevitably seek to exploit the same capabilities.
Palo Alto Networks confirmed that over the past few weeks, they used the model to identify complex vulnerabilities that previous-generation models simply couldn’t find. And they issued a direct warning: everyone needs to prepare for AI-assisted attackers, because there will be more attacks, faster attacks, and more sophisticated attacks.
The importance of open source in this equation
A fundamental aspect of Project Glasswing that deserves special attention is the focus on the open source ecosystem. Jim Zemlin, executive director of the Linux Foundation, put the issue bluntly: historically, security expertise has been a luxury reserved for organizations with large security teams, while open source maintainers, whose software serves as the foundation for much of the world’s critical infrastructure, were left to figure out security on their own.
Considering that open source software makes up the vast majority of code in modern systems — including the very systems that AI agents use to write new software — giving these maintainers access to AI models capable of proactively identifying and fixing vulnerabilities at scale represents a real shift in the equation. AI-augmented security can become a reliable ally for every maintainer, not just those who can afford expensive security teams.
That’s why the donations to Alpha-Omega, OpenSSF, and the Apache Software Foundation, along with the Claude for Open Source program for maintainers who want to request access, are so significant in this context. They represent a practical acknowledgment that protecting open source is protecting the internet as a whole. 🌐
Long-term plans and next steps
Project Glasswing was designed to grow in scope and continue for many months. Partners will work on tasks including local vulnerability detection, black-box testing of binaries, endpoint protection, and penetration testing of systems. Anthropic plans to share as many learnings as possible so that other organizations can apply the lessons to their own security.
Within 90 days, Anthropic will publish a report on what was learned, the vulnerabilities that were fixed, and the improvements made that can be disclosed. Additionally, the company will collaborate with leading security organizations to produce a set of practical recommendations on how security practices should evolve in the AI era. Topics on the agenda include:
- Vulnerability disclosure processes
- Software update processes
- Open source security and supply chain
- Secure development lifecycle and secure-by-design practices
- Standards for regulated industries
- At-scale triage and automation
- Patch automation
Anthropic also shared that they have been in discussions with U.S. government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. The company recognizes that protecting critical infrastructure is a national security priority for democratic countries and that the emergence of these cyber capabilities is yet another reason for the U.S. and its allies to maintain a decisive lead in AI technology.
An important point: Anthropic does not plan to make Claude Mythos Preview available to the general public. The eventual goal is to allow Mythos-class models to be deployed at scale safely, but that requires advancing the development of safeguards that detect and block the model’s most dangerous outputs. The company plans to launch new safeguards with a future Claude Opus model, allowing them to refine those safeguards with a model that doesn’t present the same level of risk as Mythos Preview.
What this means for the future of digital security
Glasswing isn’t just a research project or a PR initiative from big tech companies. It represents a concrete bet that artificial intelligence can be the primary line of defense for global digital infrastructure in the years ahead. And that bet has solid technical backing, especially considering what Claude Mythos Preview has already demonstrated before any public launch.
But there’s an important dimension to this story that goes beyond the technology itself. The fact that such a diverse consortium — bringing together direct competitors like Google, Apple, and Microsoft around a common goal — already signals that the industry recognizes some threats are too big to be faced alone. Vulnerabilities in critical software don’t carry a corporate flag, don’t respect market boundaries, and don’t choose victims by brand preference. When a flaw of this caliber is exploited, the impact is collective, and the response needs to be collective too.
Ten years after the first DARPA Cyber Grand Challenge, frontier AI models are becoming competitive with the best humans at discovering and exploiting vulnerabilities. Without the necessary safeguards, these powerful cyber capabilities could be used to exploit the many existing flaws in the world’s most important software, making cyberattacks of all kinds far more frequent and destructive.
What’s being built with Glasswing also sets an important precedent for how the industry will handle the advancement of AI’s offensive capabilities. If frontier language models can already identify complex flaws in critical software, it’s reasonable to assume that bad actors will seek to use that same capability to find and exploit those flaws before patches arrive. The race between offense and defense in cybersecurity has always existed, but with AI in the game, it’s happening at a speed and scale without historical precedent. 🧠
While the risks are serious, there’s room for optimism: the same capabilities that make AI models dangerous in the wrong hands make them invaluable for finding and fixing flaws in important software, and for producing new software with far fewer security bugs.
Project Glasswing arrives as a structured response to this new reality — not as a definitive solution, but as the beginning of an approach that matches the challenge artificial intelligence poses to global digital security.
The mid-term vision includes the possibility of creating an independent third-party body capable of bringing together organizations from the public and private sectors as the ideal home for ongoing work on these large-scale cybersecurity projects. No single organization can solve these problems alone. Frontier AI developers, other software companies, security researchers, open source maintainers, and governments worldwide all have essential roles to play.
And that’s the most relevant part of all this: for the first time in a long while, the defense community may actually be running ahead. Not by much, but enough to make a difference.
