Advertisement · 728 × 90
#
Hashtag

#GlassWing

Advertisement · 728 × 90
AI: Promise & Peril The big AI companies are simultaneously touting the promise and peril of their wares. So… which is it? ## So Good It’s Scary In the last week, two of the leading AI companies announced the availability of new AI models that were so good at coding that they were basically afraid to release these models to the general public. It started with a press release from Anthropic announcing a new model named Claude Mythos. But unlike previous releases, Anthropic claimed that this one was so good at finding software vulnerabilities that they couldn’t, in good conscience, make it available to the public… yet. They instead formed Project Glasswing, which would make this powerful tool available to the good guys first. The idea is that the makers of **widely used** software could use the tool to find and _fix_ the bugs – because surely the bad guys would use Mythos to find and _exploit_ these bugs for nefarious purposes, if allowed to do so. As is often the case these days with Anthropic and OpenAI (arguably the two top AI companies in the world), when one company puts out a major release, the other quickly follows suit. And so it was that OpenAI released ChatGPT 5.4 Cyber. The press release didn’t mention Mythos or Anthropic by name, but it was obviously a bit of a dig at Project Glasswing. And yet, it was basically taking the same position: this is so good that we’re going to control its release to keep it from being (ab)used by the bad guys. This kind of alarmist messaging has been going on since the debut of ChatGPT 3.5, which kicked off this modern generative AI (genAI) race in late 2022. There was the famous Statement on AI Risk in mid-2023 and many offhand soundbite-worthy remarks from tech leaders, including Elon Musk saying (years ago) that AI will be more dangerous than nuclear weapons. ## Hype & Reality So, which is it? Is genAI really that dangerous? Will it replace all human jobs? Will it enable cyber bad guys to hold the world hostage? Are these AI chatbots going to become sentient and take over the world? The answer to all three is: probably not. But genAI is already being used to justify layoffs, cybercriminals are using AI to craft much better scams, and certainly many people believe that AI chatbots are sentient – to the point of even falling in love with them – or worse. (You should watch the movie _Her_.) There’s no doubt that this technology is highly disruptive, but it’s absolutely _not_ sentient. And like many disruptive technologies, it will replace some jobs, create others, and in most cases will just make people more productive in their current jobs. But we also need to realize that all this talk of danger and power, true or not, serves to promote the whole industry, garnering new users and attracting investment. It’s worth noting that both OpenAI and Anthropic are hoping to IPO in 2026. ## AI Superpower: Coding However, there is one particular area where genAI is supremely well-suited: **coding** – as in, writing, reading, changing and (yes) exploiting bugs in software. Modern AI chatbots, or Large Language Models (LLMs), are almost tailor-made for software because, unlike most _spoken_ languages, computer languages are unambiguous, tightly structured, and very well defined. There’s also a _massive amount_ of example code out there to learn from. Granted, not all of that code is _good_ code, but in the vast majority of cases, it’s _working_ code. Furthermore, you can test software to verify that you got it right – that is, that it actually works. That includes code that exploits vulnerabilities. These genAI tools can grade their own work and tweak it until it works perfectly. I’ve written software for well over four decades and I’m here to tell you: the current AI models are astonishingly good at writing and analyzing software. This has caused no end of consternation among my colleagues (this is a great article that illustrates the point). I actually have no trouble believing that Mythos and ChatGPT Cyber _could_ be as good as their owners claim. But here’s the key point: even if they’re not that good yet, _they will be_ – and it won’t take long. I don’t mean years, either – we’re talking months. These tools are improving at a _remarkable_ pace. One reason for this is that the AI companies are _using_ AI to improve their products! And so, despite the hype, I actually support the controlled release of these new AI tools – it’s rational and smart. These tools will also be used, feverishly, to improve the security of our existing software and the tools used to detect and prevent attacks. The real shift isn’t that attackers can do new things – it’s that they can do the same things at much greater scale and with much less technical skill. We can hope that when the dust settles, these tools will benefit the creators more than the attackers, but we should be prepared for the reverse. Bruce Schneier has a short, well-written write-up on all of this that’s worth a read. ## What Should I Do? First of all, don’t freak out. AI will be used for good and ill alike. It will be disruptive. But it’s not going to doom our species – at least not the type of AI we’re talking about here. However, the next 3 to 12 months is going to be a bumpy ride. All software has bugs, many of which are vulnerable to attack over the internet. These bugs exist right now – but the number and skill of the ‘bad guys’ limits how many can be found and exploited successfully. GenAI is going to change that. We need to get old, unsupported (or practically unsupportable) devices off the internet, now. And we need to fix and update whatever is left ASAP. I’m talking both about individuals like you and me, but also critical infrastructure companies, financial institutions, and government agencies of all kinds. To protect ourselves, we need to keep doing all the things we’ve already been doing – but **more urgently**. I’ve written articles on all of these already: 1. Reduce your attack surface 2. Delete online data where you can 3. Backup your important data 4. Avoid “agentic AI”, at least until it’s safer This next recommendation may seem counterintuitive… but you should absolutely _use_ AI – so you can familiarize yourself with what it can – and can’t – do. I would play with the free versions of ChatGPT and Claude. (Google’s Gemini is good, too, but I find it hard to recommend Google for privacy reasons.) You don’t have to install the app – you can just use it in a web browser. But also try privacy-respecting chatbots like Proton’s Lumo (or others). These products are improving constantly, so I would make an effort to try new versions as they come out every few months. I may write a whole article on this topic… #### Need practical security tips? Sign up to receive Carey's favorite security tips + the first chapter of his book, _Firewalls Don't Stop Dragons_. Don't get caught with your drawbridge down! **Get started**

#AI: Promise & Peril

https://firewallsdontstopdragons.com/ai-promise-peril/

#Mythos #Anthropic #cybersecuritiy #OpenAI #ClaudeMythos #ProjectGlasswing #Glasswing

1 1 0 0
Post image

Mythos: Responsible disclosure (unknown false +ve rate), Big Tech, and the wider research community

www.schneier.com/blog/archive...

#project #glasswing #vulnerabilities #exploits #attacks #code #analysis

0 0 0 0
Preview
#mythos | Katie Moussouris Anyone who knows me knows I’m pro Vulnerability Disclosure. To the vendor first, then publicly ideally when it’s fixed, but also if they won’t fix it or drag their feet. I’m also pro Vulnerability Coo...

Want to know which throttled release of the latest #AI models I think is best and why?

Read my opinion on @anthropic.com ‘s Project #Glasswing #Mythos private release vs OpenAI’s Trusted Cyber Program application & vetting process.

www.linkedin.com/posts/kmouss...

10 2 1 0
Mythos and Cybersecurity Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an initiative called Project Glasswing. The announcement was accompanied by a barrage of hair-raising anecdotes: thousands of vulnerabilities uncovered across every major...

#Mythos and #Cybersecurity

www.schneier.com/blog/archives/2026/04/my...

#Anthropic #Claude #ClaudeMythos #AI #ProjectGlasswing #Glasswing

1 0 0 0

Today's PSA: folks, you'll likely be seeing a lot of security updates to your devices in the next few months, as Project Glasswing does its stuff. Even if (like me) you normally wait a while before updating – just in case – I'd recommend early updates while this plays out.

#glasswing #security

1 0 0 0
Preview
Comment les Américains évaluent les risques de Mythos, l’IA d’Anthropic qui effraie la planète Le nouveau système du géant mondial de l’intelligence artificielle fait craindre la divulgation massive de failles informatiques, qui ferait le bonheur des cybercriminels. « Glasswing », le groupe de...

qui ferait le bonheur des #cybercriminels. « #Glasswing », le groupe de travail mis en place par l’entreprise pour identifier et corriger les vulnérabilités, laisse de côté les #Européens et les #Chinois.
www.lemonde.fr/economie/art...

0 0 0 0
Preview
Goldman Sachs chief ‘hyper-aware’ of risks from Anthropic’s Mythos AI US bank has the Claude model and is working closely with the tech firm to improve cyber protection

AI “Mythos”… or Just Smart Marketing www.theguardian.com/business/202... #newsbit #newsbits #dofthings #ai #artificialintelligence #analytics #data #tech #technology #software #cloudcomputing #digitaltransformation #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Preview
Goldman Sachs chief ‘hyper-aware’ of risks from Anthropic’s Mythos AI US bank has the Claude model and is working closely with the tech firm to improve cyber protection

AI “Mythos”… or Just Smart Marketing www.theguardian.com/business/202... #newsbit #newsbits #dofthings #ai #artificialintelligence #analytics #data #tech #technology #software #cloudcomputing #digitaltransformation #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0

Projekt #glasswing jetzt ihre System härten und in 2 Monaten in den Griff bekommen, ist völlig illusorisch in meinen Augen. Gleichzeitig müssen deutsche Firmen und Behörden, und damit auch #KRITIS Unternehmen, ihren Quellcode der US Firma Anthropic zum Prüfen geben, 4/5

0 0 1 0
Preview
Claude Mythos and Project Glasswing: why an AI superhacker has the tech world on alert A new AI model could automate the process of searching for cybersecurity bugs and flaws – for better or worse.

“Superhackers”… Real Threat or Tech Hype? theconversation.com/claude-mytho... #newsbit #newsbits #dofthings #ai #artificialintelligence #analytics #datamanagement #tech #technology #software #automation #cloudcomputing #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Preview
Claude Mythos and Project Glasswing: why an AI superhacker has the tech world on alert A new AI model could automate the process of searching for cybersecurity bugs and flaws – for better or worse.

“Superhackers”… Real Threat or Tech Hype? theconversation.com/claude-mytho... #newsbit #newsbits #dofthings #ai #artificialintelligence #analytics #datamanagement #tech #technology #software #automation #cloudcomputing #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Preview
Claude Mythos and Project Glasswing: why an AI superhacker has the tech world on alert A new AI model could automate the process of searching for cybersecurity bugs and flaws – for better or worse.

“Superhackers”… Real Threat or Tech Hype? theconversation.com/claude-mytho... #newsbit #newsbits #dofthings #ai #artificialintelligence #analytics #datamanagement #tech #technology #software #automation #cloudcomputing #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Original post on mastodon.bits-und-baeume.org

"Now, under the title of Project #Glasswing, over 50 selected companies and orgs are allowed to test the hyped up #LLM to find security holes in their own products. But just how many problems have they really discovered?
According to #VulnCheck researcher Patrick Garrity, the answer is […]

0 1 0 0
Preview
Project Glasswing: Securing critical software for the AI era A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.

Glasswing Are We Finally Seeing Inside AI… or Just Better Illusions? www.anthropic.com/glasswing #newsbit #newsbits #dofthings #ai #artificialintelligence #datamanagement #tech #technology #cloudcomputing #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Preview
Project Glasswing: Securing critical software for the AI era A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.

Glasswing Are We Finally Seeing Inside AI… or Just Better Illusions? www.anthropic.com/glasswing #newsbit #newsbits #dofthings #ai #artificialintelligence #datamanagement #tech #technology #cloudcomputing #agenticAI #AIagent #aiagents #anthropic #claudeai #claude #glasswing

1 0 0 0
Post image

OpenAI reveals its Mythos rival designed for cybersecurity pros - TechRadar www.techradar.com/pr... #cybersecurity #GPT5.4-Cyber #OpenAI #Mythos #GlassWing

0 0 0 0
Original post on eweek.com

Anthropic Briefed Trump Administration on Mythos Cyber Capabilities Anthropic briefed senior Trump administration officials on its new Mythos model before giving outside organizations access, highl...

#Anthropic #Artificial #Intelligence #Cybersecurity #Latest #News #cybersecurity #mythos […]

0 0 0 0
Preview
L’administration britannique s’inquiète: Mythos, l’une des IA les plus puissantes d’Anthropic, réussit 73% d’un test inédit de cybersécurité, qu’aucun modèle ne parvenait à boucler en 2025 L’AI Security Institute, un organisme de recherche rattaché au ministère britannique des Sciences, de l’Innovation et de la Technologie, a testé une version "preview" de l’IA Mythos d’Anthropic afin d...

#Mythos et #Glasswing : les 10 secousses qui attendent les #DSI et les #RSSI selon Forrester
👉Possibilité de mener des attaques autonomes contre de petits systèmes d’entreprise faiblement protégés
www.bfmtv.com/tech/intelli...

0 0 0 0

RE: https://infosec.exchange/@neilmadden/116402717947589117

Neil has a good, balanced writeup of #Mythos and #Glasswing that I can definitely get behind. Recommended to break through the hype / hate duality that has been going on the last few days.

0 0 0 0
You Actually Do Need to Understand Mythos
You Actually Do Need to Understand Mythos YouTube video by Hank Green

#glasswing #anthropic #hacking #ai

Also know that #OpenAI is 2 weeks behind releases of #Anthropic

youtu.be/V6pgZKVcKpw?...

0 0 0 0
Preview
Synack Unveils Glasswing-Readiness Assessment to Enhance AI Security Strategies Discover how Synack's innovative Glasswing-Readiness Assessment helps organizations fortify their defenses against advanced AI-driven cyber threats, ensuring robust security coverage.

Synack Unveils Glasswing-Readiness Assessment to Enhance AI Security Strategies #USA #Redwood_City #AI_Security #Synack #Glasswing

0 0 0 0
Preview
Synack Introduces Glasswing Readiness Assessment to Bridge AI Security Gaps Synack has launched the Glasswing Readiness Assessment, aimed at helping organizations identify critical attack surface gaps before AI-driven threats can exploit them.

Synack Introduces Glasswing Readiness Assessment to Bridge AI Security Gaps #USA #Redwood_City #AI_Security #Synack #Glasswing

0 0 0 0
Preview
Synack Launches Glasswing-Readiness Assessment to Enhance AI Security Strategies Synack has introduced a new assessment to help businesses identify and address critical vulnerabilities in light of emerging AI-driven threats, marking a significant advance in cybersecurity.

Synack Launches Glasswing-Readiness Assessment to Enhance AI Security Strategies #United_States #Redwood_City #AI_Security #Synack #Glasswing

0 0 0 0
Preview
Synack Launches Glasswing-Readiness Assessment to Address AI Security Gaps Synack unveils the Glasswing-Readiness Assessment, aiming to help businesses identify critical AI security vulnerabilities before threats can exploit them.

Synack Launches Glasswing-Readiness Assessment to Address AI Security Gaps #USA #Redwood_City #AI_Security #Synack #Glasswing

0 0 0 0
Post image

Anthropic limita Glasswing: l’AI che trova zero-day è un vantaggio strategico e fa paura

📌 Link all'articolo : www.redhotcyber.com/post/zeroday...

A cura di Massimiliano Brolli

#redhotcyber #news #intelligenzaartificiale #cyberwar #cybersicurezza #zeroday #glasswing

0 0 0 0
Preview
Project Glasswing: Securing critical software for the AI era A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.

If you missed the initial announcement from #Anthropic regarding their latest #AI developments & the release of #Glasswing, you can catch up on the full details here…

www.anthropic.com/glasswing

1 0 0 0

Project Glasswing just dropped - AWS, Apple, Broadcom, Cisco, Google, Microsoft & NVIDIA teamed up to secure critical software. When giants align like this, the threat landscape got taken seriously. https://www.anthropic.com/glasswing #AI #Security #Glasswing

0 0 0 0
Preview
Uncovering The Glasswing Butterfly’s See-through Wings Most butterflies sport colourful, eye-catching wings. But some species flit about using mostly transparent wings. Researchers have now uncovered the tricks that one of these — the glasswing butterf…

The stunning #GreatOto or #Glasswing #Butterfly flits around #SouthAmerica with almost transparent wings 🦋🎇✨💖 to protect from predators. Yet they face #extinction from #deforestation 😿 Take action #BoycottPalmOil #Boycott4Wildlife @palmoildetect.bsky.social palmoildetectives.com/2023/03/08/u...

1 1 0 0

Project #glasswing has very serious implications. How are you all thinking about it?

0 0 0 0
Preview
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs GlassWorm uses a fake WakaTime VS Code extension to infect IDEs, deploy RATs, and steal data, prompting urgent credential rotation.

#ide #glasswing #vscode #winsurf

thehackernews.com/2026/04/glas...

1 0 0 0