Anthropic has released the first progress report for Project Glasswing, a collaborative initiative designed to secure critical software using artificial intelligence.
Launched last month with 50 partners, the initiative uses Claude Mythos Preview to find vulnerabilities. During the first month of operation, partners identified more than 10,000 high- or critical-severity vulnerabilities across major software systems.
Notably, the speed of finding these bugs has increased tenfold for several participating organizations. For example, Cloudflare detected 2,000 bugs, including 400 high-severity issues, in its critical systems.
Partner Evaluations and Real-World Impact
External testing organizations also validated the performance of the model. The UK’s Artificial Intelligence Security Institute reported that the model successfully solved both of its cyber range simulations.
Meanwhile, Mozilla identified and resolved 271 vulnerabilities in Firefox 150 during its initial tests.
“Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it is limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI.”
Anthropic, Project Glasswing Update
Open-Source Analysis by Project Glasswing
In addition to partner systems, the Project Glasswing initiative scanned more than 1,000 open-source projects that support global internet infrastructure.
The model identified 6,202 high- or critical-severity vulnerabilities out of 23,019 total detected issues. Security firms verified 1,752 of these findings, confirming a 90.6% true-positive rate.
One specific vulnerability was discovered in the wolfSSL cryptography library, which is used by billions of devices. The model constructed an exploit that could allow attackers to forge certificates and host spoofed websites. This vulnerability, registered as CVE-2026-5194, has now been patched.

Defensive Tools and Enterprise Solutions
To help organizations manage these findings, Anthropic released Claude Security in public beta for enterprise customers.
This tool uses Claude Opus 4.7 to scan codebases and has already patched over 2,100 vulnerabilities in three weeks. Furthermore, qualifying security teams can now request access to the specific scanning tools used in the project.
Future Outlook and Safety Safeguards
Anthropic stated that it has not released Mythos-class models to the general public due to current safeguard limitations.
However, the company plans to expand Project Glasswing to additional partners, including the United States and allied governments. General release of these models will occur only after stronger safety measures are established.





