Anthropic Project Glasswing Expands to 150+ Organizations in 15+ Countries Including NATO and ENISA
Summary
- • Project Glasswing expands to 150+ organizations across 15+ countries including NATO, ENISA, Samsung, and Okta
- • Initial 50-partner cohort found 10,000+ critical vulnerabilities; bottleneck has shifted from finding to patching
- • Expansion targets power, water, healthcare, and hardware — sectors underrepresented in initial U.S.-focused cohort
- • OpenAI launched rival GPT-5.5-Cyber; Anthropic filed IPO confidentially at nearly $1 trillion valuation
Details
Project Glasswing expands from ~50 to 200+ partner organizations across 15+ countries
The second wave adds roughly 150 organizations. Named participants include Okta, Samsung, SK Hynix, SK Telecom, NATO, and the EU cybersecurity agency ENISA. Countries covered include Australia, Canada, France, Germany, Italy, Switzerland, Netherlands, Spain, Belgium, Sweden, India, Japan, New Zealand, and South Korea — all U.S.-aligned nations.
Expansion deliberately targets critical infrastructure sectors absent from the initial cohort
Power, water, healthcare, communications, and hardware were underrepresented in the first 50 partners. The new cohort focuses on organizations whose codebases underpin systems that other companies and governments depend on — maintainers of shared infrastructure rather than individual enterprises.
For most partners, Anthropic estimates a major attack on their codebase could affect more than 100 million people
This is Anthropic's stated criterion for inclusion in the expanded cohort. The company explicitly frames the stakes in terms of both national security and global security implications, not purely commercial risk.
Initial 50-partner cohort found 10,000+ critical vulnerabilities within the program's first month
The scale of discovery in a single month underscores the step-change in throughput that AI-assisted vulnerability research represents. The bottleneck has since shifted from finding flaws to verifying, disclosing, and patching them at comparable speed.
Cloudflare found 2,000 bugs — 400 high or critical — with false positive rates better than human testers
Low false positive rates are operationally significant: high false positive rates cause security teams to deprioritize AI-generated findings. Cloudflare's results suggest Mythos Preview is producing actionable output, not noise.
Mozilla found 271 vulnerabilities in Firefox 150, more than 10x the count achieved with Claude Opus 4.6
The Opus 4.6 comparison provides a direct generational benchmark. A 10x uplift in a single model generation on the same codebase signals nonlinear capability growth in this domain.
UK AI Security Institute confirmed Mythos Preview is the first model to complete both cyber range exercises end-to-end
The cyber ranges test a model's ability to execute multistep cyberattacks autonomously. Government validation that a commercial model can complete these exercises marks a threshold: frontier AI offensive capability is now operationally real.
OpenAI released GPT-5.5-Cyber, a competing cybersecurity model now in large-scale partner testing
Anthropic had publicly anticipated that rival models of comparable capability would arrive quickly. GPT-5.5-Cyber's release validates that prediction and adds urgency to Glasswing's mission of establishing defensive norms before such tools proliferate broadly.
Anthropic filed confidentially for an IPO following a $65B funding round at a nearly $1 trillion valuation
The funding round and IPO filing were disclosed the day before the Glasswing expansion announcement. At a ~$1 trillion valuation, Anthropic would rank among the most valuable technology companies at the time of any public offering.
Claude Mythos Preview is Anthropic's most powerful model, purpose-evaluated for offensive and defensive cybersecurity
Released in early April 2026 specifically in the context of Project Glasswing. Its ability to identify thousands of zero-day vulnerabilities over several weeks, combined with UK AISI end-to-end cyber range results, distinguishes it from prior general-purpose models in this domain.
Anthropic is racing to build disclosure and patching infrastructure before Mythos-level capability becomes widely available
The company has framed Glasswing's urgency explicitly around proliferation risk: once comparable models are in broad circulation, the defensive advantage of controlled access disappears. The expansion to allied-nation critical infrastructure is partly an attempt to institutionalize secure disclosure norms while a window remains.
The structural bottleneck in software security has shifted from vulnerability discovery to verification, disclosure, and patching
This framing emerged from Glasswing's first-month results and is now being tested at scale across international critical infrastructure. Traditional security team workflows built around human-paced discovery are no longer the rate-limiting constraint.
Industry Update = program/business development, Strategy = deliberate positioning, Insight = analytical finding, Stat = quantified result, Research = third-party validation, Market Impact = competitive landscape, Financials = funding/valuation, New Tech = model capability, Policy = governance/norms
What This Means
Project Glasswing has moved in the span of weeks from a controlled U.S.-centric pilot to a multinational program covering the most consequential codebases in allied-nation critical infrastructure — power grids, water systems, healthcare networks, and military alliances. The inclusion of NATO and ENISA alongside commercial hardware and identity platforms signals that governments are treating AI-assisted vulnerability research as a national security tool, not merely a developer productivity feature. The competitive pressure is real: OpenAI's release of GPT-5.5-Cyber confirms Anthropic's own stated fear that Mythos-level offensive capability will soon be widely available, making the race to patch faster than adversaries can exploit a structural feature of the security landscape. For the security industry, the question is no longer whether AI can find vulnerabilities at scale — that has been answered — but whether the institutions responsible for critical infrastructure can absorb and remediate findings at the speed AI now generates them.
Sentiment
Cautious interest focused on the new patching bottleneck and dual-use risks
“anthropic's project glasswing found 10,000+ critical vulnerabilities in essential software in a month. that number is getting passed around as good news. it only stays good news if every capable model out there is aimed at that code by someone friendly”
“The real gateway from Anthropic’s Glasswing update isn’t « Claude find vulnerabilities » It’s more uncomfortable: AI may now be finding serious vulnerabilities faster than humans can verify, disclose and patch them.”
“For decades, cybersecurity’s biggest problem was finding vulnerabilities fast enough. Now the problem has completely changed. AI can discover security flaws faster than the global developer community can patch them. THE FUTURE IS AI!!!!”
“So far, Project Glasswing has reportedly helped identify 10,000+ critical vulnerabilities in essential systems. Interesting direction to watch.”
Split
~60/40 split between those highlighting the 'patching bottleneck' as the new problem vs. those focused on offensive misuse risks; very limited overall volume.
Sources
Updates
Linked a new low-trust aggregator article (Hacker News AI Labs, trust 0.5) reporting on a Project Glasswing status report. Article claims few vulnerabilities have been patched and criticizes Anthropic's opacity. No content update applied — the patching bottleneck is already covered in the existing event, the source is low-trust, and the claims are vague/unsubstantiated. Article linked for source coverage only.
Project Glasswing expanded from ~50 U.S.-focused partners to 150+ organizations in 15+ countries, adding critical infrastructure sectors (power, water, healthcare, hardware) absent from initial cohort. Named new partners include Okta, Samsung, SK Hynix, SK Telecom, NATO, and EU cybersecurity agency ENISA. OpenAI launched competing GPT-5.5-Cyber model. Anthropic disclosed confidential IPO filing at ~$1T valuation following $65B funding round. Minor factual correction applied: scope of 100M+ impact estimate changed from "any partner" to "most partners" per source.
