Early yesterday morning, Anthropic unveiled Project Glasswing.
The list of 12 companies lined up: AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, plus Anthropic itself. Add to that more than 40 organizations maintaining critical infrastructure — a lineup rarely seen in the enterprise AI space.
The origin of this initiative is quite interesting.
What Mythos Uncovered Shocked Everyone
Over the past few weeks, Claude Mythos Preview independently discovered thousands of zero-day vulnerabilities. They affected every major operating system and every major browser.
Three specific examples:
- A 27-year-old bug in OpenBSD: A network connection alone could crash the system
- A 16-year-old flaw in FFmpeg video codec code: Automated tests had run over 5 million times without finding it; Mythos uncovered it
- A multi-vulnerability chain in the Linux kernel: Could escalate from regular user privileges to full system control
On the CyberGym cybersecurity benchmark, Mythos scored 83.1. Opus 4.6 scored 66.6. The gap isn't measured in 10 or 20 points — this is a qualitative leap from "can help you review code" to "can independently discover 0-days."
Those familiar with the space know that FFmpeg's code has been repeatedly scanned by security teams, fuzzers, and static analysis tools worldwide. A vulnerability that evaded 5 million tests means traditional methods have reached a certain limit.
Why Project Glasswing Needs an Alliance
Here's the delicate part: Mythos's capability is a double-edged sword.
On one side, companies like Anthropic can use it for defense. On the other, anyone capable of invoking a similar model could theoretically use it for attack. Anthropic's previous approach was to hold back from public release — granting restricted access to only about 40 companies.
What Project Glasswing does is essentially organize the defenders first.
Among the 12 launch partners: AWS, Microsoft, Google, Apple — cloud providers; Cisco, CrowdStrike, Palo Alto Networks — cybersecurity giants; JPMorganChase represents financial critical infrastructure; the Linux Foundation piece is even more crucial, as open-source ecosystem security maintenance has long been a challenge.
CrowdStrike's Elia Zaitsev made a significant statement:
The window between vulnerability discovery and exploitation has collapsed — it used to be months, now it's minutes.
Linux Foundation's Jim Zemlin added: Open-source maintainers have historically handled security on their own. The implication is clear — previously, a few volunteers guarded millions of lines of code; now, large models automate scanning, and the offensive-defensive rhythm is on an entirely different level.
Who Truly Benefits
The capital markets have already started calculating. Mizuho issued a report favoring CrowdStrike — the logic being that Project Glasswing will make enterprises re-evaluate the value of endpoint protection. Motley Fool is betting on Palo Alto Networks, looking at its platform strategy and token consumption capacity (PANW has 1,550 platform customers, up 35% year-over-year, with a net retention rate of 119%).
But ultimately, this isn't about which stock rises.
It's about this question: When an AI model can discover thousands of high-risk vulnerabilities in two weeks, who ensures this capability reaches defenders first?
Anthropic's answer: Form an alliance, let the companies best positioned to patch use it first, then gradually expand outward.
A Counterintuitive Detail
One more thing worth noting is how Mythos works.
It's not a "press a button and get a report." According to Anthropic's disclosed technical details, the model performs advanced code reasoning on its own, chains multiple exploits into attack chains, and develops complex attack paths independently — all without human guidance.
This level of autonomy would have been science fiction five years ago. Today, it's a reality that urgently needs guardrails.
The 27-year-old bug in OpenBSD eluded generations of security researchers. The FFmpeg flaw evaded 5 million tests. Put these two numbers together, and it's hard not to question whether the entire methodology of traditional software security needs rewriting.
Glasswing is just the beginning. The next step is to see whether these 12 giants can patch these vulnerabilities cleanly in their own products before they are exploited.
The window is very small.
Sources: CocoLoop, Project Glasswing: Securing critical software for the AI era (Anthropic official); Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them? (The Hacker News); CrowdStrike to rally as Anthropic spotlights AI cybersecurity threats (CNBC)