Glasswing's one-month tally is 10,000-plus vulnerabilities, and the day also brought claude-mythos-1-preview briefly into Claude Code before Anthropic pulled it.
Anthropic published its first formal update on Project Glasswing today, reporting that roughly 50 partners have found more than 10,000 high- or critical-severity vulnerabilities using Claude Mythos Preview in the program's first month. (anthropic.com/research/glasswing-initial-update) The numbers are specific: Cloudflare reported 2,000 bugs (400 high/critical), with a false-positive rate Cloudflare's team rated better than human testers. Mozilla fixed 271 vulnerabilities in Firefox 150, ten times the rate from an earlier Claude model. Anthropic's own parallel scan of more than 1,000 open-source projects found an estimated 6,202 high- and critical-severity findings out of 23,019 total.
The company's summary of the underlying problem: "The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity." The program is expanding to additional partners, including U.S. and allied government critical infrastructure. Mythos Preview remains gated. Anthropic said it expects to make Mythos-class models available for general release once stronger safeguards exist, with no date announced.
Anthropic and approximately 50 partners found more than 10,000 high- or critical-severity vulnerabilities using Claude Mythos Preview in the program's first month. Partner results: Cloudflare reported 2,000 bugs (400 high/critical) with a false-positive rate better than human testers. Mozilla fixed 271 vulnerabilities in Firefox 150, a 10x improvement over an earlier Claude model. Anthropic's own independent scan of 1,000-plus open-source projects identified an estimated 6,202 high/critical findings out of 23,019 total. Program expanding to additional partners including U.S. and allied government critical infrastructure organizations. Mythos Preview remains gated; Anthropic stated Mythos-class models will eventually ship for general release, pending stronger safeguards.
Users briefly spotted model identifiers including "claude-mythos-1-preview" in Claude Code's model picker and in Claude Security. Source code contained the string: "Access to the Claude Mythos model in Claude Code and Claude Security." Both appearances were removed quickly. Not an official release. No comment from Anthropic. Reported by BleepingComputer, TestingCatalog, and TechLusive.
No Claude Code release in this window. Last version: v2.1.150 (May 23), infrastructure only, no user-facing changes. No SDK releases. Python SDK last at v0.104.1 (May 22). TypeScript SDK last at sdk-v0.98.0 (May 21). No API or Claude Apps updates detected. docs.anthropic.com endpoints returned 403 throughout this sweep.
Daily digest at 9 PM ET. Weekly magazine every Friday morning. Six labs, one feed. No spam, one-click unsubscribe.