Apple, Google, Microsoft join Anthropic's Project Glasswing to find critical software vulnerabilities
Twelve major technology companies—including Apple, Google, Microsoft, Amazon, and Nvidia—have launched Project Glasswing, a coordinated effort to identify and patch critical software vulnerabilities using Anthropic's unreleased Mythos Preview model. The initiative discovered thousands of zero-day vulnerabilities in mission-critical software, including a 27-year-old bug in OpenBSD and a 16-year-old vulnerability in widely-used video software that automated testing tools had missed.
Project Glasswing: Twelve Tech Rivals Unite to Defend Critical Infrastructure
Twelve major technology companies have announced Project Glasswing, a coordinated cybersecurity initiative that deploys Anthropic's unreleased Mythos Preview model to identify thousands of zero-day vulnerabilities in the world's most critical software systems before adversaries exploit them.
The Coalition
Participants include Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. The coalition is investing $4 million in direct donations and $150 million in Claude usage credits—a commitment that signals the existential nature of the threat.
What Mythos Preview Discovered
According to Anthropic, the unreleased Mythos Preview "general-purpose frontier model" with strong agentic coding and reasoning capabilities identified thousands of zero-day vulnerabilities in recent weeks. Many are critical and difficult to detect through conventional means.
Key findings include:
- A 27-year-old vulnerability in OpenBSD, an operating system renowned for security
- A 16-year-old vulnerability in widely-used video software that automated testing tools had analyzed 5 million times without detection
- Vulnerabilities present in core mission-critical software deployed for 10-20 years undetected
The Accelerating Threat Timeline
CrowdStrike CTO Elia Zaitsev described the compressed attack window: "The window between a vulnerability being discovered and being exploited by an adversary has collapsed. What once took months now happens in minutes with AI."
This compression—from months to minutes—represents a fundamental shift in cybersecurity dynamics that motivated competitors to collaborate rather than compete.
Why These Rivals Are Cooperating
The willingness of fierce competitors to share intellectual property and unreleased models indicates the threat has moved from competitive risk to mutual infrastructure vulnerability. Cisco's Anthony Grieco stated: "AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back."
The involvement of foundational infrastructure companies—Linux Foundation, Cisco, Broadcom—underscores that this addresses shared dependencies across the entire technology ecosystem. Modern civilization relies on networked digital infrastructure, much of it built on open-source software created by individual developers.
Strategic Restrictions on Mythos Preview
Anthropic confirmed it will not make Mythos Preview generally available, citing weaponization concerns. The model was not trained specifically for cybersecurity but demonstrated unexpected capability in identifying subtle vulnerabilities that eluded conventional security testing.
The strategic distribution of $150 million in usage credits ensures participating companies can deploy the model against their own critical systems while preventing its use by potential adversaries.
What This Means
Project Glasswing represents a rare moment of forced cooperation among competitors facing a common existential threat. The discovery of ancient, critical vulnerabilities undetectable by gold-standard automated testing confirms that AI-powered vulnerability detection has fundamentally altered the cybersecurity landscape. The 5-million-times-analyzed vulnerability in video software suggests conventional security approaches have reached their limits. For enterprise infrastructure operators, this signals both urgent vulnerability patching requirements and the reality that closed-circle collaboration rather than public disclosure now characterizes critical infrastructure defense.
Related Articles
Anthropic adds Mods to Claude Code, a plugin system that hooks into tool calls, prompts and UI rendering
Anthropic released Mods for Claude Code, a plugin system built on JavaScript and TypeScript functions that hook into events such as tool calls, user prompts and UI rendering. Mods are not sandboxed and run with the user's permissions. They work in the CLI, the desktop app and, partly, the VS Code extension.
AWS adds managed Web Search to Claude Desktop via Bedrock AgentCore Gateway in three Regions
AWS published a walkthrough for connecting Claude Desktop on Amazon Bedrock to a managed, MCP-compatible Web Search capability through Amazon Bedrock AgentCore Gateway. According to AWS, the search is backed by an Amazon web index spanning tens of billions of documents, and query traffic stays within AWS infrastructure. Web Search is available in three AWS Regions; pricing is not disclosed in the post.
Anthropic launches Claude for Government for US civilian agencies in FedRAMP High environment
Anthropic is now offering Claude for Government to US federal and state agencies. The platform has been in open beta since July and runs in a FedRAMP High environment. The launch comes as the company's legal fight with the Pentagon continues.
OpenAI says it shut down a 15,000-account campaign to extract model reasoning; the attack still worked on Azure
OpenAI says it detected and shut down an adversarial distillation campaign involving more than 15,000 accounts, linked in part to people associated with Moonshot AI. Researchers report that the same reasoning-extraction attack still worked on Microsoft Azure on September 13 against every OpenAI model they tested, including GPT-6 Astra.
Comments
Loading...