StableLearn Logo

Search Content

News 9 min read

Anthropic Drops a 'Nuclear Bomb': AI Vulnerability Detection Surpasses Humans, 12 Tech Giants Unite for Project Glasswing

Anthropic launches Project Glasswing with AWS, Apple, Microsoft, Google, and 8 other tech giants, investing $100M in usage credits and $4M in donations. The core is Claude Mythos Preview, an AI model that surpasses human capability in vulnerability detection, having discovered thousands of critical vulnerabilities including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw.

Cover image for Anthropic Drops a 'Nuclear Bomb': AI Vulnerability Detection Surpasses Humans, 12 Tech Giants Unite for Project Glasswing

Published 164 days ago. Content may be outdated.

Anthropic is going all in this time!

Today, they announced the launch of Project Glasswing, partnering with 12 tech giants including AWS, Apple, Microsoft, Google, NVIDIA, and Cisco, with one singular goal: to identify and fix vulnerabilities in the world’s most critical software before the AI era fully arrives.

What’s even more striking is that Anthropic has unveiled an unreleased frontier model called Claude Mythos Preview, whose capability in finding and exploiting software vulnerabilities has surpassed all but the most elite human experts.

Here are the numbers:

  • Thousands of critical vulnerabilities discovered, including in every major operating system and browser
  • 27-year-old bug (OpenBSD) and 16-year-old bug (FFmpeg) uncovered
  • $100 million in usage credits + $4 million in direct donations
  • 40+ organizations granted model access

What does this mean? AI can now automate tasks that previously only top security experts could perform—and do it faster with broader coverage.

Why Project Glasswing? The “Tipping Point” in AI Cybersecurity

Anthropic is blunt in their announcement: AI models have reached a tipping point in coding capability where they can surpass nearly all humans in finding and exploiting software vulnerabilities.

This isn’t fear-mongering. Global annual losses from cybercrime are estimated at around $500 billion, and AI is now dramatically lowering the cost, difficulty, and expertise barrier for finding vulnerabilities.

Traditional ApproachAI Era
Requires elite security expertsAI models automate the process
Vulnerabilities can hide for years or decadesRapid scanning discovers legacy issues
Manual review has limited efficiencyMassive parallel processing
High costSignificantly reduced cost

The question is: What if attackers also gain access to this AI capability?

This is the core logic behind Project Glasswing—find and fix vulnerabilities with AI before malicious actors acquire this capability, giving defenders the advantage.

In Anthropic’s words: “For defenders to win, we must act now.”

Claude Mythos Preview: The “Nuclear Weapon” of Vulnerability Detection

Core Capabilities: Autonomous Discovery + Autonomous Exploitation

Claude Mythos Preview isn’t an ordinary code analysis tool—its capabilities can be described as “terrifying”:

Capability DimensionSpecific PerformanceDescription
Autonomous Vulnerability DiscoveryThousands of zero-day vulnerabilitiesFully autonomous, no human guidance needed
Coverage ScopeAll major operating systems + all major browsersWindows, macOS, Linux, Chrome, Firefox, Safari all affected
Vulnerability AgeUp to 27 years oldSurvived decades of human review and millions of automated tests
Autonomous Exploit DevelopmentComplex exploit chainsNot only finds vulnerabilities but writes attack code

Simply put, it doesn’t just tell you where the problem is—it demonstrates how to attack it.

Three Shocking Case Studies

1. OpenBSD’s 27-Year-Old Vulnerability

What is OpenBSD? One of the world’s most security-hardened operating systems, specifically used for firewalls and critical infrastructure.

The result? Mythos Preview found a 27-year-old remote crash vulnerability—an attacker could crash the entire system just by connecting to the target machine.

27 years! This means from 1998 to 2025, this vulnerability was sitting there. Countless security experts reviewed this code, but no one caught it.

2. FFmpeg’s 16-Year-Old Vulnerability

FFmpeg is the foundational library for video encoding/decoding, used by virtually all video software.

Mythos Preview discovered a 16-year-old vulnerability, and here’s the kicker: automated testing tools had executed this line of code 5 million times without ever detecting the issue.

What does that mean? Traditional fuzzing tools ran 5 million times and missed it—AI spotted it at a glance.

3. Linux Kernel Exploit Chain

The Linux kernel powers most of the world’s servers. Mythos Preview not only found multiple vulnerabilities but autonomously chained them together to achieve privilege escalation from ordinary user access to complete machine control.

This “exploit chain” attack is a hallmark skill of advanced hackers—now AI can do it too.

Performance Data: Crushing Advantage

In cybersecurity benchmarks like CyberGym, Mythos Preview’s performance far exceeds Anthropic’s previous strongest model, Claude Opus 4.6.

It has also reached new heights in coding capabilities:

BenchmarkDescriptionPerformance
SWE-bench VerifiedReal-world software engineering tasksHighest score
Terminal-Bench 2.0Terminal operations and system tasks92.1%
BrowseCompBrowser automation tasksHigher than Opus 4.6, using 4.9× fewer tokens

The key point: These coding capabilities directly translate into cybersecurity capabilities. An AI that can write code can naturally find vulnerabilities in code.

What Do the 12 Tech Giants Say?

AWS: “We Analyze 400 Trillion Network Flows Daily"

"At AWS, we build defenses before threats emerge. Our teams analyze over 400 trillion network flows every day for threats, and AI is central to our ability to defend at scale. We’ve been testing Claude Mythos Preview in our own security operations, applying it to critical codebases, where it’s already helping us strengthen our code.”

Microsoft: “The Attack Window Has Collapsed from Months to Minutes"

"When tested against our open-source security benchmark CTI-REALM, Claude Mythos Preview showed substantial improvements compared to previous models. We look forward to partnering with Anthropic and the broader industry to improve security outcomes for all.”

CrowdStrike: “The Window Between Discovery and Exploitation Has Collapsed"

"The window between a vulnerability being discovered and being exploited by an adversary has collapsed—what once took months now happens in minutes with AI. Claude Mythos Preview demonstrates what is now possible for defenders at scale, and adversaries will inevitably look to exploit the same capabilities. That is not a reason to slow down; it’s a reason to move together, faster.”

Cisco: “The Old Ways of Hardening Systems Are No Longer Sufficient"

"AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back. Our foundational work with these models has shown we can identify and fix security vulnerabilities across hardware and software at a pace and scale previously impossible. That is a profound shift, and a clear signal: the old ways of hardening systems are no longer sufficient.”

Linux Foundation: “Open Source Maintainers Finally Have Security Expertise"

"In the past, security expertise has been a luxury reserved for organizations with large security teams. Open source maintainers—whose software underpins much of the world’s critical infrastructure—have historically been left to figure out security on their own. By giving the maintainers of these critical open source codebases access to a new generation of AI models that can proactively identify and fix vulnerabilities at scale, Project Glasswing offers a credible path to changing that equation. This is how AI-augmented security can become a trusted sidekick for every maintainer, not just those who can afford expensive security teams.”

Project Glasswing: $100M + 40+ Organizations

Participation Structure

Participation TypeOrganizationsWhat They Get
Core PartnersAWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto NetworksMythos Preview access for defensive security work
Critical Software Organizations40+ organizations building or maintaining critical software infrastructureScan and secure first-party and open-source systems
Open Source Security OrganizationsAlpha-Omega, OpenSSF, Apache Software FoundationDirect financial donations (total $4M)

Financial Investment

Investment TypeAmountPurpose
Model Usage Credits$100 millionCover substantial usage across Glasswing participants
Open Source Security Donation$2.5 millionAlpha-Omega and OpenSSF (through Linux Foundation)
Open Source Security Donation$1.5 millionApache Software Foundation
Total$104 million-

Pricing

For participants, Mythos Preview pricing is:

  • Input: $25 / million tokens
  • Output: $125 / million tokens

Available via Claude API, Amazon Bedrock, Google Cloud Vertex AI, and Microsoft Foundry.

Work Focus Areas

Task TypeDescription
Local Vulnerability DetectionScan codebases for security issues
Black Box TestingTest binary security
Endpoint SecurityHarden endpoint devices
Penetration TestingSimulate attacks to test system defenses

90-Day Public Report

Anthropic commits to publicly reporting within 90 days:

  • Vulnerabilities fixed (disclosable portions)
  • Lessons learned and best practices
  • Recommendations for evolving security practices in the AI era

Potential recommendation areas include:

  • Vulnerability disclosure processes
  • Software update processes
  • Open-source and supply chain security
  • Secure development lifecycle
  • Standards for regulated industries
  • Triage scaling and automation
  • Patching automation

Why Not Release Mythos Preview Publicly?

This is a critical question. Anthropic explicitly states: they do not plan to make Claude Mythos Preview generally available.

The reason is simple: this model is too dangerous.

It can find vulnerabilities and develop exploit code. If it falls into the hands of malicious actors, the consequences would be catastrophic.

Anthropic’s plan is:

  1. First use Mythos Preview to help defenders find and fix vulnerabilities
  2. Simultaneously develop cybersecurity safeguards that can detect and block the model’s dangerous outputs
  3. Deploy these safeguards in an upcoming Claude Opus model
  4. Ultimate goal is to enable users to safely deploy Mythos-class models at scale

In Anthropic’s words: “We need to make progress in developing safeguards with a model that does not pose the same level of risk.”

Technical Deep Dive: Why Is Mythos Preview So Powerful?

Core Capability: Agentic Coding + Reasoning

Mythos Preview’s cybersecurity capabilities fundamentally stem from its powerful agentic coding and reasoning abilities.

Capability DimensionDescription
Code UnderstandingDeep comprehension of complex code logic
Vulnerability ReasoningInfer potential security issues
Exploit DevelopmentWrite complex exploit code
Autonomous OperationFully autonomous, no human guidance needed

Simply put, it doesn’t just write code—it “reads” code and can spot problems in it.

Coding Capabilities: Comprehensive Leadership

Across multiple software engineering benchmarks, Mythos Preview achieves the highest scores of any model to date:

  • SWE-bench Verified / Pro / Multilingual: Real-world software engineering tasks
  • SWE-bench Multimodal: Multimodal software engineering tasks
  • Terminal-Bench 2.0: Terminal operation tasks (92.1% accuracy)
  • Humanity’s Last Exam: Comprehensive capability test
  • BrowseComp: Browser automation tasks

These coding capabilities directly translate into cybersecurity capabilities—an AI that can write code can naturally find vulnerabilities in code.

Use Cases: Who Can Use It? How?

Application ScenarioTarget UsersCore Value
Critical Infrastructure SecurityOS, browser, network equipment vendorsDiscover and fix core software vulnerabilities
Open Source Software HardeningOpen source project maintainersGive small teams enterprise-grade security capabilities
Enterprise Security OperationsLarge enterprise CISO teamsAutomate vulnerability scanning and penetration testing
Financial System ProtectionBanks, payment institutionsProtect critical financial infrastructure
Cloud Service SecurityCloud service providersHarden cloud platforms and customer environments
Supply Chain SecuritySoftware supply chain stakeholdersIdentify third-party component vulnerabilities

Collaboration with the U.S. Government

Anthropic explicitly states they have been in ongoing discussions with U.S. government officials about Mythos Preview’s offensive and defensive cyber capabilities.

Key points:

  • Securing critical infrastructure is a top national security priority for democratic countries
  • The U.S. and its allies must maintain a decisive lead in AI technology
  • Governments have an essential role in assessing and mitigating national security risks associated with AI models

Anthropic states: “We are ready to work with local, state, and federal representatives to assist in these tasks.”

Final Thoughts: Defenders’ “Last Chance”?

The launch of Project Glasswing marks the entry of cybersecurity into a completely new era.

It’s no longer “human experts vs. human hackers”—it’s “AI defense vs. AI attack.”

The key is: the time window is extremely short.

Anthropic repeatedly emphasizes in their announcement:

  • “For defenders to win, we must act now"
  • "Frontier AI capabilities are likely to advance substantially over just the next few months"
  • "For cyber defenders to come out ahead, we need to act now

CrowdStrike puts it more bluntly: “The window between discovery and exploitation has collapsed from months to minutes.”

Project Glasswing is essentially a race against time:

  • Before malicious actors gain AI vulnerability detection capabilities
  • Use AI to find and fix vulnerabilities in the world’s most critical software first
  • Give defenders a durable advantage in the AI era

$100 million, 12 tech giants, 40+ critical organizations, thousands of discovered vulnerabilities—behind these numbers is the entire tech industry’s heightened awareness of AI cybersecurity threats.

More importantly, Anthropic isn’t just releasing the model—they’re providing funding, technical support, and best practice sharing. Developers and maintainers can get started immediately, no waiting required.

The AI-era cybersecurity war has begun.


References:

Related Links:

Share Article

More Articles