There is a particular moment in the life of a powerful new tool when the thing it was built to do stops being the hard part. Anthropic’s expansion of Project Glasswing marks exactly that moment for AI in cybersecurity — and the announcement is most interesting not for the headline number of new partners, but for what that number is quietly in service of: a deliberate pivot in where the effort is being applied, because the constraint has moved.

Project Glasswing is Anthropic’s collaborative effort to secure the world’s most important software. In early April, roughly 50 initial partners were given access to Claude Mythos Preview and began scanning their codebases for vulnerabilities. The result, reported since, is the fact that reframes everything: those partners found more than 10,000 high- or critical-severity security flaws. Now Anthropic is extending the partnership to approximately 150 new organizations. But read the piece closely and the expansion isn’t really about scanning more code. It’s about confronting what happens after you’ve found 10,000 holes — and racing a clock that Anthropic names with unusual specificity.

The bottleneck moved: expanding Project Glasswing — ThorstenMeyerAI.com
ThorstenMeyerAI.com
Project Glasswing · Field Note
Project Glasswing · the expansion

The bottleneck moved — from finding flaws to fixing them

50 partners found 10,000+ critical vulnerabilities in weeks. So the constraint is no longer detection — it’s verify, disclose, patch, deploy. Anthropic is expanding Project Glasswing to ~150 organizations, and pivoting its weight toward the new chokepoint.

~150 orgs · 15+ countries · critical infrastructure · a race against diffusion
01The expansion

From 50 partners to ~150 — aimed at the leverage points

Not just more headcount. The new group reaches sectors the first cohort underrepresented, and leans toward vendors whose code sits under thousands of downstream systems.

~50
~150
new organizations
each must meet Anthropic’s security requirements first
15+
countries · most serve critical infrastructure to many more
5 sectors
newly represented vs the initial cohort
vendors
maintainers of code relied on by orgs & governments worldwide
newly represented industries
⚡ Power 💧 Water 🏥 Healthcare 📡 Communications 🔧 Hardware 📦 Vendors · high-leverage
100M+ What they share: a successful attack on each partner’s codebase could be catastrophic — for most, affecting more than 100 million people, with global & national-security ramifications.
02The reframe · toggle the era
Mastering Nmap: Network Scanning, Security Auditing, and Ethical Hacking With NMAP (Practical Cybersecurity Toolkit Series)

Mastering Nmap: Network Scanning, Security Auditing, and Ethical Hacking With NMAP (Practical Cybersecurity Toolkit Series)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Finding used to be the hard part

For the whole history of the field, detection was the scarce, skilled work — the chokepoint. A model that surfaces 10,000 critical flaws in weeks inverts that. Toggle before/after and watch the bottleneck move.

The defensive pipeline — where the constraint sits

Same five stages. The chokepoint slides downstream.

🔍
Find
Verify
📣
Disclose
🔧
Patch
🚀
Deploy
♻️ The vertiginous move: the same class of model that created the backlog is aimed at clearing it — partners now use Mythos to write patches, run pre-release checks, and rebuild legacy code in memory-safe languages.
03Turning the tool on the new chokepoint
Funny Morale Patches Set for Programmer, 3D PVC Tech Humor Patches for Software Engineers, Developers, IT Guys & PC Gamers, Tactical Hook and Loop Backpack Patch with Geek Access Card (3-Pack)

Funny Morale Patches Set for Programmer, 3D PVC Tech Humor Patches for Software Engineers, Developers, IT Guys & PC Gamers, Tactical Hook and Loop Backpack Patch with Geek Access Card (3-Pack)

  • Set Includes: 3 humorous 3D PVC patches
  • Target Audience: Programmers, developers, IT professionals
  • Design Features: Legendary tech jokes and humor

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

AI redeployed downstream — and pushed beyond the cohort

Glasswing is consciously shifting its weight from finding toward disclosing, fixing & deploying. The same model helps at the new bottleneck.

Defensive tasks Mythos-class models now take on

Beyond scanning — the work that actually closes the gap.

🔧
Writing patches

Partners use the model to fix what it finds — not just flag it.

🛡️
Pre-release checks

Preventing vulnerabilities from appearing in the first place.

🎯
Penetration testing

Simulating attacks to see how a flaw might be exploited.

🔄
Rebuilding in memory-safe languages

Attacking whole vulnerability classes at the root.

Open source gets special attention: Anthropic is in talks to scale up reviewing & patching of OSS vulnerabilities, and is sharing best practices for disclosing to maintainers — so a flood of AI-found flaws arrives in a form a buried volunteer can actually triage and act on.
released — general market
Claude Security

Uses public frontier models like Claude Opus 4.8 to scan codebases & suggest patches.

released — on request
The Glasswing tooling

The vuln-finding tools, to trusted security teams — so partners’ methods replicate widely.

04The clock
Ghidra Software Reverse-Engineering for Beginners: Master the art of debugging, from understanding code to mitigating threats

Ghidra Software Reverse-Engineering for Beginners: Master the art of debugging, from understanding code to mitigating threats

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Why the urgency is named, not gestured at

The program’s tempo is the tempo of a race against diffusion. Anthropic puts a number on the deadline.

⏱ the window

Within 6–12 months, many other labs will have Mythos-class models — and could release them without safeguards.

In that world, cyberattacks could occur much more often, and in much more unpredictable forms. The strategic theory of the whole program: build the defensive head start now, while the capability is still scarce and gated — so when it’s cheap and everywhere, defenders already stand on higher ground.

today
Capability is scarce & gated

Mythos-class power sits with vetted Glasswing partners under Anthropic’s requirements.

6–12 months out
Capability goes ambient

Other labs ship Mythos-class models — possibly ungoverned. The window to prepare closes.

05The honest tension
SOC analyst Starter Kit

SOC analyst Starter Kit

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Read it with its difficulties in view

Several are real — some Anthropic states outright, some inherent to the situation. None cancels the core, but all deserve to be held.

⚖️

Dual use — and the safeguards don’t exist yet

The same capability that finds-and-patches can find-and-exploit. Anthropic says general release needs safeguards that it, and to its knowledge all other developers, have yet to develop. The caution is the clearest evidence of the power.

🚪

Gated, even as the logic demands breadth

Advanced defensive capability is allocated by one company’s selection — yet the announcement’s own case is that hundreds of thousands will need access. “Must be gated for safety” sits in tension with “must be widespread to work.”

🔎

Not a neutral observer

A frontier lab is at once warning of the danger, helping constitute it, and selling the response (Claude Security, the tooling, the Cyber Verification Program). The warning isn’t wrong — but the commercial frame is worth holding alongside the public-interest one.

06The aspiration · & what’s next

Toward a permanent advantage for defenders

Cybersecurity has long been asymmetric in the attacker’s favor — defenders close every hole, attackers need one. The north star is to flip that.

the north star
If it succeeds, Anthropic hopes to enable a permanent advantage for defenders.
Glasswing is framed partly as a rehearsal — learning how to respond when a model crosses a threshold faster than institutions can absorb it. “This will not be the last time.”
expand further
More essential infrastructure

Plus critical-OSS maintainers & safety testers, US & overseas.

scale a channel
Cyber Verification Program

Mythos-class capability for specific cyberdefense tasks — breadth without waiting on full-release safeguards.

the goal
Make all software secure

And help the industry adjust how AI changes the core assumptions of cybersecurity.

Reading it in proportion

  • The core is hard to argue with: AI made finding cheap & abundant; the bottleneck genuinely moved to patching & deployment; redirecting effort there is sane.
  • The caveats sit alongside, not against: one company’s program, one company’s gate, a timeline & products that company has reason to advance — and admittedly-missing release safeguards.
  • Hold both halves: the danger is plausible and the 10,000 flaws are real; the response is reasonable and commercially convenient; the aspiration is worthy and unproven.
ThorstenMeyerAI.com
Source: Anthropic, “Expanding Project Glasswing” (Jun 2, 2026) & the Glasswing initial update · figures & program details per the announcement · independent commentary · program & strategy only, no operational vulnerability detail.

What’s actually changing: who, where, and why it matters

Start with the concrete. The new group is based in more than 15 countries, and most provide critical infrastructure to many more — Anthropic notes it intends to expand the geographical reach much further in future. The expansion deliberately reaches into sectors the initial cohort underrepresented: power, water, healthcare, communications, and hardware. And a meaningful share of the new partners are vendors — companies or nonprofits that maintain codebases relied upon by lots of other organizations around the world, including governments.

That last category is the strategically important one, and it’s worth pausing on. A vendor whose code sits underneath thousands of downstream systems is a force multiplier in both directions: a vulnerability there propagates everywhere, but so does a fix. By prioritizing the maintainers of widely-relied-upon code, the expansion is aiming at the points of maximum leverage rather than simply adding headcount. Every new partner has to meet Anthropic’s security requirements before gaining access — a gate that matters, given what the access confers.

The common thread across all of them is stark. What each partner has in common is that a successful attack on their codebase could be catastrophic — for most, Anthropic estimates a major attack could affect more than 100 million people, with ramifications for both global and national security. This is not a developer-productivity program dressed in security language. It is triage for systems where failure is measured in nine-figure populations.

The reframe at the center: the bottleneck is no longer finding

Here is the sentence that organizes the whole effort, stated plainly in the announcement and in the initial update before it: the bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.

Sit with how large a shift that is. For the entire history of the discipline, finding the vulnerability was the expensive, skilled, scarce work — the thing that separated capable security teams from the rest. Detection was the chokepoint. A model that surfaces ten thousand critical flaws across a cohort in a matter of weeks doesn’t just speed that work up; it inverts the economics of the whole field. Suddenly finding is cheap and abundant, and the scarce resource is everything downstream: confirming each flaw is real, coordinating its disclosure responsibly, writing the patch, testing it, and deploying it across all the systems that carry the vulnerable code. The constraint moved from the front of the pipeline to the back.

This is why the expansion is framed the way it is. Anthropic describes its role as twofold, and the second half is the tell. First, to help the software industry adapt by safely providing wide access to better models, tools, and common infrastructure. Second — and this is the pivot — to steadily shift the support it provides from finding vulnerabilities to disclosing, fixing, and deploying patched software. Glasswing is consciously moving its weight downstream, toward the new chokepoint, rather than piling more capability onto the part that’s already solved.

Turning the tool on the new bottleneck

The elegant, and slightly vertiginous, move is that the same class of model that created the patching backlog is being aimed at clearing it. Mythos Preview itself can help, and the announcement is specific about how. Many partners now use the model to write patches, and for pre-release checks that prevent vulnerabilities from appearing in the first place. Beyond that, models like Mythos Preview can be used for penetration testing — simulating an attack to see how a flaw might actually be exploited — for automating threat detection and response, and for rebuilding legacy codebases in memory-safe languages, among many other defensive tasks. That last one is quietly ambitious: a great deal of the world’s critical software is written in languages where whole categories of vulnerability are possible by default, and using AI to systematically rewrite it in memory-safe languages would attack the problem at its root rather than patching symptoms.

Open-source software gets specific attention, and rightly, because it’s where the leverage and the fragility both concentrate. Anthropic says it’s in discussions with third parties about how to substantially scale up the reviewing and patching of open-source vulnerabilities, and working on sharing ideas and best practices for disclosing vulnerabilities to open-source maintainers — with the explicit intent of making those reports easier to triage and act upon. Anyone who has watched a volunteer maintainer get buried under an avalanche of automated, low-context vulnerability reports will recognize the problem being headed off here: a flood of AI-found flaws is only a gift to defenders if the reports arrive in a form a human can actually use.

To push the same adaptation out beyond the partner cohort, Anthropic points to two concrete releases. Claude Security, a product that uses the latest public frontier models — like Claude Opus 4.8 — to scan codebases and suggest patches, brings a version of the capability to the general market. And the tooling Glasswing’s partners used to find vulnerabilities faster is being released on request to trusted security teams. The stated logic is replication: the partners’ methods for adapting to these tools can and should be copied widely across the millions of organizations and developers who are vulnerable, and these releases are the vector for that.

The clock: why the urgency is explicit

What gives the whole piece its tempo is that Anthropic names the deadline rather than gesturing at it. Cheap, fast AI models with powerful cyber capabilities are around the corner — and more pointedly, within 6 to 12 months Anthropic expects that many other AI companies will have Mythos-class models, and that they could release them without safeguards that prevent misuse. In that world, the announcement warns, cyberattacks could occur much more often and in much more unpredictable forms.

That is the strategic theory of the entire program in one move. Glasswing is not presented as a permanent moat Anthropic alone controls; it’s presented as a head start the defensive side of the world needs to build before the offensive capability becomes ambient and ungoverned. The explicit aim is to spur institutions toward operating norms that reflect this reality — to get critical-infrastructure providers, vendors, and maintainers adapted to powerful cyber models while those models are still scarce and gated, so that when they’re cheap and everywhere, defenders are already standing on higher ground. The expansion’s tempo is the tempo of a race against diffusion.

The honest tension, stated plainly

A piece like this deserves to be read with its difficulties in view, and several are real — some acknowledged in the announcement, some inherent to the situation.

The first is dual use, which Anthropic does not dodge. The path to general access runs through safeguards that don’t yet exist: to release Mythos-level capabilities broadly, the company says, it will need highly robust safeguards preventing misuse — safeguards that it, and to its knowledge all other AI developers, have yet to develop. The reason is structural and worth stating clearly: because cybersecurity has both helpful and destructive uses, the same capability that finds-and-patches can find-and-exploit, and building safeguards that are both strong enough and precise enough to separate the two is a genuine, unsolved problem. This is the rare case where a company’s caution is the most concrete evidence of the capability’s power — they are gating it because they can’t yet make it safe to ungate.

The second is the gate itself. Powerful cyber capability is, for now, available to a curated set of organizations that meet Anthropic’s security requirements and pass through its program. That’s the responsible posture given the dual-use reality — but it does mean that, in the near term, an advanced defensive tool is allocated by one company’s selection process rather than broadly available, even as the announcement’s own logic is that hundreds of thousands of organizations, researchers, and maintainers will likely need access to confront the coming challenge. The tension between “this must be gated for safety” and “this must be widespread to work” is real, and the piece lives inside it rather than resolving it.

The third is the one worth naming directly: a frontier lab is simultaneously the entity warning that the danger is coming, the entity whose models help constitute that danger, and the entity offering the products and programs — Claude Security, the released tooling, the Cyber Verification Program — positioned as the response. None of that makes the warning wrong; the 10,000 flaws are real and the diffusion timeline is plausible. But a reader is right to hold the commercial frame in view alongside the public-interest one, and to remember that “we are warning you about a problem our technology creates, and here is our product that addresses it” is a structure that warrants ordinary skepticism even when the underlying concern is genuine.

What comes next, and the aspiration behind it

The announcement is candid that this is a waypoint, not a destination. Anthropic plans to expand Glasswing further, prioritizing additional essential-infrastructure providers, maintainers of critical open-source software, and safety testers, with future expansions reaching organizations in the US and overseas just as this one does. It also intends to scale up its Cyber Verification Program, which would grant Mythos-class capabilities to many more organizations for specific cyberdefense tasks — a narrower, task-scoped channel that may be how the capability reaches breadth without waiting for the general-release safeguards to be solved.

The longer-term framing is the part that connects this announcement to the larger arc of where AI is heading. Frontier model releases, Anthropic writes, will become increasingly high-stakes; capabilities will keep improving across all domains, including many that — like cybersecurity — empower attackers and defenders alike. This will not be the last time a model crosses a threshold that forces exactly this kind of scramble. The claim is that Glasswing is partly a rehearsal — a way of learning how to respond when capability jumps ahead of the institutions meant to absorb it.

And the aspiration at the end is the sentence the whole program is built toward: if it succeeds, Anthropic hopes to enable a permanent advantage for defenders. That is a genuinely consequential idea. Cybersecurity has long been described as asymmetric in the attacker’s favor — the defender must close every hole, the attacker needs only one. A world in which AI durably tilts that balance toward defense would be a meaningful change in the texture of digital life. Whether it’s achievable is unproven, and the safeguards gap is a real obstacle in the way of it. But as a north star, “a permanent advantage for defenders” is the right one to aim at — and the expansion of Project Glasswing is, at minimum, a serious and clearly-reasoned attempt to start walking toward it before the window to do so closes.

Reading it straight

The core of this is hard to argue with and doesn’t depend on taking the framing on faith: AI has already made finding vulnerabilities cheap and abundant, the bottleneck has genuinely moved to patching and deployment, and a sane response is to redirect effort toward that new chokepoint while building defensive capacity ahead of the moment the offensive version becomes ungoverned. The expansion to ~150 organizations across 15-plus countries, weighted toward critical infrastructure and high-leverage vendors, is a coherent expression of that logic.

The caveats sit alongside it without canceling it. This is one company’s program, allocated by that company’s gate, advancing a timeline and a set of products that company has commercial reasons to advance — and the safeguards that would make the capability safe to release broadly admittedly don’t yet exist. Hold both halves. The danger Anthropic describes is plausible and the 10,000 flaws are not hypothetical; the response is reasonable and also commercially convenient; the aspiration is worthy and also unproven. On the evidence in front of us, expanding Project Glasswing is a defensible and probably wise move in a genuinely hard situation — made by a party that is not a neutral observer of it.


Based on Anthropic’s announcement “Expanding Project Glasswing” (Jun 2, 2026) and its cited Project Glasswing initial update. This is independent commentary and analysis; figures, partner counts, and the program details originate with the source. Cybersecurity is a sensitive topic; this piece discusses the program and its strategy rather than any operational detail of vulnerabilities or techniques.

© 2026 · Thorsten Meyer · Powered by Thorsten Meyer AI.

You May Also Like

Europe’s Regulation Overload: Why the EU Risks Falling Behind in the AI Era

Introduction The European Union (EU) has styled itself a global rule‑setter for…

24,000 Fake Accounts and a Cloud Login: The Rent-and-Distill Playbook Behind China’s Frontier Models

By Thorsten Meyer — February 2026 – Thorsten Meyer AI Anthropic flagged…

From Conversation to Commerce: How Google’s AP2 and Coinbase’s x402 Could Unlock an Agentic Payments Economy

Published context: Google announced the Agent Payments Protocol (AP2) on September 16,…

Strategic Risk Assessment: The Transition to Comprehension Lock-In and Agentic Context Platforms

1. The Strategic Pivot: From AI Models to Institutional Context Platforms The…