Anthropic is expanding Project Glasswing, its vulnerability-hunting initiative, to 150 organizations across 15+ countries using Claude Mythos Preview. The program has already uncovered over 10,000 serious security flaws in critical infrastructure.
Anthropic's Project Glasswing is entering a major expansion phase, enlisting 150 new partners to scan critical infrastructure for vulnerabilities using Claude Mythos Preview. The initiative targets organizations in power, water, healthcare, and communications sectors across more than 15 countries.
The program's scope reflects the security stakes involved. A successful cyberattack on the systems being monitored could potentially affect 100 million people. Partners already engaged with Glasswing have identified over 10,000 serious vulnerabilities through the AI-powered scanning process.
Claude Mythos Preview, Anthropic's specialized model for security analysis, appears designed to automate the detection of critical flaws in legacy and modern systems alike. The expanded rollout suggests the model has demonstrated sufficient accuracy and utility to warrant broader deployment.
Anthropics's dual approach to the security market is notable. While Glasswing identifies vulnerabilities through its partner network, the company simultaneously offers Claude Security as a commercial product—positioning itself on both the detection and remediation sides of the cybersecurity equation.
The geographic distribution across 15+ countries indicates Anthropic's push to establish itself as a global security player. Critical infrastructure protection has become a priority for governments worldwide, particularly as digital systems face escalating threats from state actors and other adversaries.
The expansion comes amid broader industry emphasis on using AI to strengthen cybersecurity defenses. Large language models like Claude have shown capability in analyzing code and identifying potential vulnerabilities, though debate continues around their accuracy rates and false positive percentages.
Anthropics has not disclosed specific timelines for the program's rollout or performance metrics beyond the 10,000 vulnerability figure. The company plans to continue scaling partnerships and expanding geographic coverage in coming months.
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.
Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.
A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.
A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.