"Project Glasswing: An initial update" is a report published by Anthropic on May 21, 2026, one month after the launch of Project Glasswing. It is the first formal operational report on the program, quantifying what Claude Mythos Preview found across partner organizations and open-source software during that month, naming several partner-side disclosures, and setting out Anthropic's framing of the defensive-ai paradox. Anthropic's central operational claim is that frontier cyber capability is now bottlenecked by patching speed rather than discovery speed.
Operational results
In its first month, Project Glasswing covered roughly 50 partner organizations, which together found more than 10,000 high- or critical-severity (H/C) vulnerabilities using Claude Mythos Preview. Multiple partners reported a bug-finding rate more than 10× their pre-Mythos baseline. Separately, Mythos Preview scanned more than 1,000 open-source projects.
The open-source scan produced a layered set of figures, reflecting the gap between Mythos's own estimates and independently triaged results. Mythos estimated it surfaced 23,019 vulnerabilities of all severities, of which it estimated 6,202 were H/C-severity. Of those, 1,752 were independently triaged by third parties or by Anthropic. Within that triaged sample, 1,587 were confirmed to exist, a post-triage true-positive rate of 90.6% (1,587 / 1,752), and 1,094 were confirmed H/C-severity, or 62.4% (1,094 / 1,752) of the triaged set. At current rates, Anthropic projected roughly 3,900 total H/C-severity open-source vulnerabilities surfaced. As of the report, 530 H/C-severity bugs had been disclosed to maintainers, of which 75 had been patched (65 with a public advisory), with an average time from disclosure to patch of about two weeks. A further 1,129 disclosures of any severity were made unvetted at maintainer request, of which 175 were estimated H/C. The report also noted 827 confirmed H/C vulnerabilities still awaiting disclosure.
Snapshot — reported metrics (as of 2026-05-21)
| Metric | Value |
|---|---|
| Partner organizations | ~50 |
| Total H/C-severity vulnerabilities found by partners | >10,000 in one month |
| Bug-finding rate increase (multiple partners) | >10× over pre-Mythos baseline |
| Open-source projects scanned | >1,000 |
| Open-source vulns surfaced by Mythos (all severities) | 23,019 (Mythos's own estimate) |
| Open-source vulns Mythos estimated H/C | 6,202 |
| Independently triaged by third parties or Anthropic | 1,752 |
| Post-triage true-positive rate | 90.6% (1,587 / 1,752) |
| Of triaged true positives, confirmed H/C-severity | 62.4% (1,094 / 1,752) |
| Projected total H/C-severity OSS vulns surfaced (at current rates) | ~3,900 |
| H/C-severity bugs disclosed to maintainers | 530 |
| H/C bugs patched to date | 75 / 530 (65 with public advisory) |
| Average time from disclosure to patch | ~2 weeks |
| Unvetted disclosures (per maintainer request) | 1,129 of any severity; 175 estimated H/C |
| Confirmed H/C vulns still awaiting disclosure | 827 |
Partner-level disclosures
The report named several partners and their results. Cloudflare found about 2,000 bugs, 400 of them H/C-severity, with a false-positive rate the report described as "better than human testers"; Cloudflare published its own engineering review of Mythos Preview, summarized in Project Glasswing — What Mythos Showed Us (Cloudflare engineering blog, May 17 2026). The UK AI Security Institute reported that Mythos Preview was the first model to solve both of its cyber ranges, which are multistep cyberattack simulations, end-to-end. Mozilla found and fixed 271 vulnerabilities in Firefox 150 during Mythos Preview testing, which it stated was more than 10× the number found in Firefox 148 using Claude Opus 4.6, a within-organization comparison across two adjacent Claude model versions. XBOW described Mythos Preview as "a significant step up over all existing models" on its web exploit benchmark, with "absolutely unprecedented precision on a token-for-token basis."
On academic benchmarks, the report stated that Mythos Preview was the strongest performer on ExploitBench and ExploitGym, two recently released exploit-development benchmarks; Anthropic supports the development of both through its External Researcher Access Program.
The report cited a vulnerability in wolfSSL, an open-source cryptography library used by billions of devices, as a flagship case. Mythos Preview discovered the vulnerability and constructed an exploit that the report said would let an attacker forge certificates, enabling a malicious actor to host a fake bank or email-provider website indistinguishable to end users from a legitimate one. The vulnerability was patched and assigned CVE-2026-5194, with a full technical writeup to follow. In a separate operational case, Mythos Preview was reported to have prevented a $1.5M fraudulent wire transfer at a Project Glasswing partner bank after a threat actor compromised a customer's email account and made spoofing phone calls, described in the report as the first reported case of Mythos-class AI deployed in a real-time anti-fraud workflow.
Patch-cycle acceleration
The report described downstream effects on patching volume at several vendors. Palo Alto Networks' latest release contained more than 5× the usual number of patches. Microsoft publicly stated that the count of new patches per Patch Tuesday would "continue trending larger for some time." Oracle reported finding and fixing vulnerabilities across its products and cloud "multiple times faster than before." Anthropic presented these figures in support of its claim that defensive-side patch velocity, rather than discovery, has become the binding constraint, an inversion of the historical asymmetry that favored attackers.
Defender-side framing and recommendations
The report framed the central tension as follows: "the bottleneck in fixing bugs has become the human capacity to triage, report, and design and deploy patches for them. Finding them in the first place has become vastly more straightforward with Mythos Preview." For software developers, Anthropic recommended shortening patch cycles, making security fixes available as quickly as possible, helping users stay up-to-date, and being persistent with users running known-vulnerable versions. For network defenders, it recommended shortening patch-testing-and-deployment timelines and emphasizing NIST and UK NCSC baseline controls to "improve security without depending on any single patch landing in time," including hardened default configurations, MFA, and comprehensive logging.
Anthropic also acknowledged an externality: maintainers of open-source projects are now "severely capacity constrained," and some had asked Anthropic to slow down its disclosures. The report presented this as an ecosystem-overload signal and the first measurable cost of the defensive-ai paradox. Anthropic characterized the maintainer-overload externality as a soft cap on how responsibly the program can expand.
Defender tooling
The report named several defender tools and partnerships:
| Tool | Status | Scope |
|---|---|---|
| Claude Security | Public beta for Claude Enterprise customers | Vulnerability scanning and fix-generation; >2,100 vulnerabilities patched in 3 weeks since launch via Opus 4.7 |
| Cyber Verification Program | Live | Legitimate-cyber-use-case verification allowing security professionals to bypass certain cyber-misuse safeguards |
| Cyber tooling release to qualifying customers | Live on request | The skills, scanning-subagent harness, and threat-model builder used by Anthropic and partners |
| Cisco Foundry Security Spec | Open-sourced (Cisco-led, per the report) | Evaluation-system template for Glasswing-style defender deployments |
| OpenSSF Alpha-Omega partnership | Active | Linux Foundation maintainer-support funding (announced March 2026, linked in report) |
| Claude for Open Source | Live | Supports OSS maintainers and contributors; Anthropic committing to scan any open-source package it adopts internally |
Claude Security's reported 2,100-plus enterprise patches in three weeks served, in Anthropic's account, as evidence that maintainer capacity can scale with Mythos-class AI assistance in enterprise contexts, even as open-source maintainer overload indicated the opposite in volunteer contexts.
Position on Mythos-class general release
The report stated Anthropic's position on releasing Mythos-class models: "no company — including Anthropic — has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm. That is why we have yet to release Mythos-class models to the public." Anthropic framed Project Glasswing as a bridge providing an asymmetric advantage to defenders until safeguards are sufficient, adding that once they are, it "look[s] forward to making Mythos-class models available through a general release." As of May 2026, this was Anthropic's stated public position on release-gating for cyber-capable models, made while the capability was already deployed in production with partners.
Anthropic positioned the May 2026 results as quantitative evidence for AI-driven vulnerability research at scale (roughly 50 partners plus more than 1,000 open-source repositories yielding over 10,000 H/C vulnerabilities in one month) and as evidence that the offense-defense balance is inverted at the discovery stage. Whether the inversion holds at the patching and deployment stage, in Anthropic's framing, depends on whether maintainer capacity scales with Mythos-class AI assistance. The report functions as Anthropic's published deployment case for Mythos-class models, gated by safeguards but deployed under Project Glasswing.
Relationships
- supports: Claude Mythos Preview, AI and Cybersecurity, Autonomous cyber-agents, Defensive AI Paradox, Cloudflare, UK AI Safety Institute (AI Security Institute).
- depends-on: Coordinated Vulnerability Disclosure — the operational framework within which Project Glasswing operates.
- related: Project Glasswing — What Mythos Showed Us (Cloudflare engineering blog, May 17 2026) (partner-side technical review), Anthropics Little Brother (broader Anthropic-as-cyber-actor narrative).
- instance-of: Safety Cases (Frontier AI) (Glasswing functions as Anthropic's published safety-deployment case for Mythos-class models).
Citation form
For wiki pages drawing on the report, cite as [[sources/anthropic-project-glasswing-initial-update]].