Anthropic Expands Restricted AI Vulnerability Program to Critical Infrastructure
Anthropic adds 150 new organizations to its Project Glasswing initiative, bringing its highly restricted Claude Mythos Preview model to critical infrastructure sectors. The AI model has already uncovered over 10,000 severe software vulnerabilities for initial partners.
Anthropic is significantly expanding its Project Glasswing program by granting access to approximately 150 new organizations across 15 countries. These new partners operate in critical infrastructure sectors that were underrepresented in the initial cohort, including power, water, healthcare, communications, and hardware. Sources indicate that cloud security and data management firms like NetSkope and Rubrik are part of this latest wave of participants receiving access to the restricted AI model.
The Claude Mythos Preview model is Anthropic's most capable and heavily restricted AI system due to concerns about potential misuse. Despite these restrictions, the model demonstrates unprecedented ability in identifying software vulnerabilities, having surfaced more than 10,000 high- or critical-severity bugs since the program launched in early April. The initial cohort of roughly 50 partners included major technology and financial firms such as Amazon Web Services, Cisco, CrowdStrike, Google, Microsoft, and JPMorgan Chase.
Early testing results from partners highlight the transformative impact of the model on cybersecurity practices. Cloudflare reports that the AI identified 2,000 bugs in its critical-path systems, including 400 high or critical issues, with a false-positive rate that outperforms human testers. Similarly, Mozilla discovered and fixed 271 vulnerabilities in Firefox 150, which is more than ten times the number found in a previous version using an older Anthropic model, reflecting a broader trend of tenfold increases in bug discovery rates across the program.