Anthropic's Glasswing Results: What AI-Powered Vulnerability Hunting Means for AI Infrastructure Operators

Anthropic's Glasswing partners used Claude Mythos Preview to find 10,000+ critical vulnerabilities in a month. Here is the routing and operator lens on what this new AI security phase means for your infrastructure.

Published via Anthropic

Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

Abstract dark background with interconnected security nodes and routing paths representing AI-powered vulnerability detection across software infrastructure

One month into Project Glasswing, Anthropic's latest update changes the threat model for every team shipping software that depends on AI APIs. The operational decision is not whether to care about AI-generated vulnerability scanning — it is how quickly your dependency stack can keep up with the new patch velocity it creates.

What happened

Anthropic published the first quantitative results from Project Glasswing, the initiative where approximately 50 infrastructure partners — including Cloudflare, Mozilla, Palo Alto Networks, Microsoft, and Oracle — used Claude Mythos Preview to scan their critical-path codebases for security vulnerabilities.

The numbers are striking:

  • 10,000+ high- or critical-severity vulnerabilities found across partner systems in one month.
  • 1,000+ open-source projects scanned independently by Anthropic; Mythos estimated 6,202 high- or critical-severity findings out of 23,019 total.
  • Of the 1,752 findings that have been independently verified, 90.6% are confirmed true positives, with 62.4% confirmed high- or critical-severity.
  • Cloudflare alone found 2,000 bugs across critical-path systems with a false-positive rate "better than human testers."
  • Mozilla found 271 vulnerabilities in Firefox 150 — over ten times more than with Claude Opus 4.6 in the prior version.
  • UK's AI Security Institute confirmed Mythos Preview is the first model to solve both of its cyber ranges end to end.

One illustrative case: Mythos constructed a working exploit for a certificate-forgery vulnerability in wolfSSL (CVE-2026-5194), a cryptography library used by billions of devices. That exploit would allow an attacker to host a convincing phishing site for a bank or email provider.

Anthropic also disclosed its thinking on broader Mythos availability. The plan is to gate a wider release on new safeguards built for an upcoming Claude Opus model — meaning a Mythos-class API is not yet available but is being actively staged.

Why it matters for AI engineering teams

The first-order implication is familiar: patch faster. The patch velocity across major infrastructure vendors is already accelerating — Microsoft's Patch Tuesday volume "will continue trending larger for some time," Palo Alto's latest release included five times the usual patch count, and Oracle is fixing vulnerabilities multiple times faster than before.

But the second-order implication is less visible: the open-source libraries that underpin AI API clients, routing gateways, observability stacks, and orchestration frameworks are all on the list being scanned. wolfSSL is not an obscure library — it is embedded in countless edge runtimes, secure enclaves, and embedded devices that handle TLS termination for API traffic. A certificate-forgery vulnerability there is directly relevant to anyone routing API requests over TLS.

The third implication is systemic: the bottleneck has shifted from finding vulnerabilities to triaging and patching them. Mythos Preview is finding bugs faster than maintainers can review and fix them. Some open-source maintainers have asked Anthropic to slow down disclosures. That is a supply-chain pressure signal — your dependencies may be sitting on a backlog of unpatched, disclosed vulnerabilities.

The router/operator angle

For teams that route AI API traffic through an OpenAI-compatible gateway, this update creates four concrete operational concerns:

1. Dependency audit cadence. The libraries your routing gateway uses — HTTP clients, TLS stacks, JSON parsers, retry logic — are the same class of open-source software being scanned by Glasswing. The 90-day coordinated disclosure window means vulnerabilities found today may become public knowledge in August. A proactive audit cycle now is lower-risk than a reactive patch sprint later.

2. Provider-tier access and model capability asymmetry. Mythos Preview is not generally available. It runs through an invitation-only program (Project Glasswing) and through Claude Security — not through the standard API. Teams building security-critical agent workflows on top of routed API calls should map which model tier their security-sensitive tasks actually need, versus what is available through standard endpoints. Routing a security-audit agent task to claude-opus-4-7 or claude-sonnet-4-6 is not equivalent to Mythos-class work, even if the OpenAI-compatible interface looks the same.

3. Supply-chain risk in AI infrastructure dependencies. The same open-source projects being scanned are the ones your AI toolchain depends on. If you are running LangChain, LlamaIndex, OpenAI SDK, Anthropic SDK, or any HTTP client library in your routing layer, watch the patch advisories from the vendors named in Glasswing. Cloudflare and Mozilla are both partners; their patches are high-signal indicators of what is being found.

4. Governance posture. For teams with enterprise security or compliance requirements, Glasswing changes the audit conversation. You can now cite AI-accelerated vulnerability discovery as a reason to shorten your patch SLA from 90 days to 30 days for high-severity open-source dependencies — and frame it as a proactive posture, not a reactive one.

What TheRouter users should watch or try

If you are routing through TheRouter or any OpenAI-compatible gateway, the near-term actions are operational rather than configuration changes:

  • Pin dependency versions in your gateway deployment and set up Dependabot or equivalent with CVE alerts for libraries in your HTTP/TLS/JSON stack. The Glasswing disclosure tracker at red.anthropic.com/2026/cvd/ is a live signal of what is being disclosed.
  • Track Anthropic's Mythos availability roadmap. The upcoming Claude Opus model safeguards are described as the gate for a wider Mythos-class release. When a Mythos API tier becomes available, it will change which routing policy makes sense for security-review agents — a task that today routes to Opus 4.7 may route differently when a Mythos tier is accessible.
  • Understand that model capability and model availability are different routing dimensions. An agent task that requires Mythos-class security research capability cannot be routed through standard API endpoints today, regardless of which gateway you use. Design your agent workflows with that tier distinction in mind.

For teams building coding agents, security-review workflows, or dependency-audit automation on top of a routed AI API: the Glasswing results set a new performance baseline for what a capable model can do in this domain. That benchmark is worth tracking both as a threat-modeling input and as a capability target when the access path opens.

Help & contact