Glasswing Goes Critical Infrastructure
Anthropic, the maker of Claude, extends Project Glasswing to roughly 150 new organizations across 15+ countries. The expanded cohort covers power, water, healthcare, communications, and hardware - sectors where a successful attack could affect 100M+ people.
First wave (50 partners, April) found 10,000+ critical vulnerabilities. Mozilla fixed 271 Firefox bugs - 10x the previous baseline. Cloudflare flagged 2,000, with 400 high or critical.
The new group targets critical infrastructure - vendors whose codebases run governments, utilities, and global comms. Anthropic also shipped Claude Security, a public product using Opus 4.8 to scan codebases and suggest patches. Dario Amodei's lab is setting the playbook before competitors hit the same capability. Their own warning: Mythos-class models arrive at other labs in 6 to 12 months, possibly without safeguards. The bottleneck has shifted from finding bugs to patching and disclosing them at scale.
For PMs in security, the threat surface just collapsed and re-expanded at once. Procurement is shifting from 'find more bugs' to 'patch faster.' Expect every major vendor to ship an AI security product within 90 days.