upplyst.ai

AI is changing what is worth knowing

Anthropic opens Project Glasswing to 150 more organisations

Anthropic opens Project Glasswing to 150 more organisations

·1 min read

Written by AI · Translated by AI · Read the Swedish original

Anthropic's AI found more than 10,000 serious security flaws for 50 organisations. Once finding them is easy, the problem moves to patching what turns up.


Anthropic announced on 2 June that Project Glasswing is growing from roughly 50 to around 200 partner organisations. The new organisations sit in more than 15 countries and work in sectors like power, water, healthcare, communications and hardware. Many of them also supply or maintain code that other organisations depend on.

Project Glasswing is Anthropic's attempt to give trusted parties access to Claude Mythos Preview, a cyber model used to find security flaws in large codebases. Access is not open: every new partner has to meet Anthropic's security requirements first.

The reason is that the same kind of AI that helps organisations find flaws can help attackers find them too. Anthropic expects many other AI companies to have models at the Mythos level within six to twelve months. Those models may ship without adequate guardrails, meaning the restraints that stop them being turned on targets.

The results from the first group of partners show why this is bigger than one more security tool. The first 50 partners have together found more than 10,000 security flaws rated high or critical. Those are not marginal improvements, they are plainly substantial.

It also moves the real problem. If AI can find more vulnerabilities faster, the hunt stops being the hard part. The hard part becomes verifying the findings, reporting them properly, ranking them, and shipping patches before someone else exploits the same holes.

For Swedish organisations in critical infrastructure the signal is clear, even though Sweden is not named in Anthropic's text. The question is not whether organisations have old flaws in their systems. They do. The question is whether their processes for security, ownership and patching survive a world where AI makes hunting for vulnerabilities faster, cheaper and more available.

Ask upplyst.ai

Why does it matter?

Finding vulnerabilities stops being the hard part. The bottleneck moves to verifying the findings, ranking them, and shipping patches before someone else exploits the same holes.

What is the background?

Anthropic announced on 2 June that Project Glasswing is growing from roughly 50 to around 200 partner organisations across more than 15 countries, in power, water, healthcare, communications and hardware. Partners get access to Claude Mythos Preview, a cyber model that hunts for flaws in large codebases, and have to meet Anthropic's security requirements first.

What is uncertain?

The 10,000 flaws are what the first 50 partners reported themselves, not an audited result. The same capability helps attackers, and Anthropic expects other companies to have models at the same level within six to twelve months, possibly without guardrails.

What does it mean in Sweden?

Sweden is not named in Anthropic's text. The question for Swedish critical infrastructure is not whether old flaws sit in the systems, they do, but whether the routines for ownership and patching survive a world where hunting for vulnerabilities becomes fast and cheap.