2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Claude Mythos and Project Glasswing Reveal Thousands of Severe Flaws in Critical Software


Anthropic announced on Friday that its defensive program, Project Glasswing, has played a role in surfacing more than 10,000 potential high- or critical-severity software vulnerabilities since the initiative began operations last month.

Project Glasswing is a security-focused effort by Anthropic aimed at protecting vital pieces of global software infrastructure. The program gives roughly 50 select partners early, exclusive access to Claude Mythos Preview – an advanced model designed to autonomously hunt for flaws in commonly used code before malicious actors can weaponize them.

From the pool of candidates identified by the model, 6,202 were singled out as high- or critical-severity issues affecting over 1,000 open-source projects. Follow-up triage and analysis determined that 1,726 of those candidates were genuine vulnerabilities (true positives), and of those confirmed problems, about 1,094 were judged to be high- or critical-severity.

Among the notable findings was a critical vulnerability in WolfSSL tracked as CVE-2026-5194 with a CVSS score of 9.3; this flaw could enable an attacker to forge certificates and impersonate legitimate services. Overall, the Glasswing effort has contributed to 97 upstream patches and spurred 88 security advisories to be published.

Anthropic acknowledged the asymmetry in cybersecurity work: locating vulnerabilities can be relatively straightforward compared with the often much harder job of repairing them. The company said successfully addressing that imbalance will materially improve software safety.

The disclosure arrives as vendors are issuing more fixes than ever, a trend Anthropic ties to a rise in AI-assisted vulnerability discovery. Microsoft has warned that its monthly patch volume is likely to “continue trending larger for some time.” Security firm XBOW – which builds autonomous offensive security tools – praised Mythos Preview as a significant step forward, saying it outperforms earlier models at finding candidate vulnerabilities and is particularly capable of reviewing source code with a security-oriented lens. Independent evaluations have also shown the model can chain individual bugs into complete end-to-end attack scenarios.

Anthropic highlighted that Mythos Preview’s role isn’t limited to code scanning. In one instance a Glasswing partner, a bank, used the model to detect and stop a fraudulent $1.5 million wire after an attacker compromised a customer’s email and placed spoofed phone calls.

Given the likelihood that similar capabilities will become more widely available, Anthropic urged software producers to accelerate their patch cycles and release security updates more quickly. The company pointed out that Oracle recently moved to a monthly patch cadence to better address critical flaws. Anthropic recommended defenders tighten the time between testing and deployment of fixes and adopt measures such as hardening default configurations, enforcing multi-factor authentication, and maintaining thorough logging to aid detection and response.

To enable vetted security work, Anthropic said it has launched a Cyber Verification Program that permits security professionals to run its models without the usual guardrails for legitimate activities like vulnerability research, penetration testing, and red teaming. That program echoes offerings such as OpenAI’s Daybreak, which gives defenders access to GPT-5.5-Cyber for specialized tasks.

Anthropic noted that models with the power of Mythos Preview and GPT-5.5-Cyber have not been made generally public because adequate safeguards to prevent widespread misuse are still lacking. The company argued that Glasswing helps the most systemically important defenders gain an asymmetric advantage, while stressing the urgent need for as many organizations as possible to strengthen their cyber defenses. Anthropic said it hopes its publicly available models, along with the new tools, research, and resources it is publishing, will help organizations improve their security posture.

First published on May 24, 2026.
Last updated on July 15, 2026.