Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NewsAI-assisted

Anthropic Launches Project Glasswing to Automate Global Cybersecurity

Anthropic debuts Claude Mythos Preview, an autonomous AI model for cybersecurity, through a massive partnership with Nvidia, Apple, and Microsoft.

Anthropic Launches Project Glasswing to Automate Global Cybersecurity
Anthropic has officially unveiled **Claude Mythos Preview**, a highly advanced AI model designed to autonomously identify and patch system vulnerabilities. The launch is part of a broad cybersecurity initiative dubbed **Project Glasswing**, involving a coalition of tech giants including Nvidia, Google, Amazon Web Services, Apple, and Microsoft. ## A Private Powerhouse Unlike Anthropic’s flagship Claude models, Mythos Preview will not see a general public release. The company has cited severe security risks as the reason for keeping the model behind closed doors. By restricting access to a vetted group of partners, Anthropic aims to ensure the tool helps "cyber defenders" gain an advantage without providing a roadmap for malicious actors to exploit. While Mythos Preview was not built exclusively for security tasks, Anthropic credits its "strong agentic coding and reasoning skills" for its efficacy. According to the company, the model has already identified thousands of high-severity vulnerabilities across every major operating system and web browser. ## The Glasswing Partnership Project Glasswing includes an impressive roster of over 40 organizations. Key partners include: - **Financial Institutions:** JPMorgan Chase - **Security Firms:** CrowdStrike, Palo Alto Networks - **Infrastructure Providers:** Cisco, Broadcom, the Linux Foundation, and the Apache Software Foundation. To support the initiative, Anthropic is committing **$100 million in usage credits**, along with $4 million in direct donations to the Linux and Apache foundations. ## Autonomous Defense One of the most striking features of Mythos Preview is its level of autonomy. Newton Cheng, the cyber lead for Anthropic’s frontier red team, noted that the model functions with "virtually no human intervention." In testing, the AI was able to develop related exploits and identify flaws entirely without human steering. This leap in capability follows a data leak last month that first hinted at the model's existence. Anthropic’s head of product management, Dianne Penn, attributed that leak to human error rather than a software breach, stating the company is currently "solidifying processes" to prevent future exposure. ## Government Relations The debut comes amid a complex political landscape. Despite recent tensions with the Trump administration, Anthropic confirmed it is in ongoing discussions with U.S. government officials regarding the model’s offensive and defensive capabilities. Penn stated the company has "briefed senior officials" and remains committed to working with various levels of government. While the program is currently subsidized, it marks a potential shift toward a high-value revenue stream. As AI firms face increasing pressure to monetize their innovations, a specialized, autonomous cybersecurity service could become a cornerstone of Anthropic’s long-term business model.

Based on reporting by Anthropic.

Anthropic has officially unveiled **Claude Mythos Preview**, a highly advanced AI model designed to autonomously identify and patch system vulnerabilities.
Louise Perrin · The Hacking Post
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories