2 Sources
[1]
Anthropic to let partners share Mythos cybersecurity findings with others
May 18 (Reuters) - Anthropic said on Monday it is revising its earlier position to allow users of its Mythos cybersecurity model to share information about cyber threats with others who may be exposed to similar vulnerabilities. Mythos, announced on April 7, is being deployed as part of
[2]
Anthropic to let partners share Mythos cybersecurity findings with others
May 18 (Reuters) - Anthropic said on Monday it is revising its earlier position to allow users of its Mythos cybersecurity model to share information about cyber threats with others who may be exposed to similar vulnerabilities. Mythos, announced on April 7, is being deployed as part of
Share
Copy Link
Anthropic has reversed its earlier confidentiality stance to allow Project Glasswing partners to share cybersecurity findings from its Mythos AI model. Major tech firms including Amazon, Microsoft, Nvidia, and Apple can now disclose vulnerabilities discovered through the program to security teams, regulators, and the public under responsible disclosure norms.
Anthropic announced on Monday a significant policy shift that allows users of its Mythos cybersecurity model to share cybersecurity findings with organizations facing similar vulnerabilities. The move marks a departure from earlier confidentiality restrictions that had governed the unreleased Claude Mythos Preview model since its April 7 announcement
1
. According to an Anthropic spokesperson, the company "fully support[s] our partners sharing findings with each other and companies outside of Glasswing to triage vulnerabilities"2
. This revision reflects the maturation of Project Glasswing and addresses the growing need for collaborative defense against cyber threats.
Source: Reuters
Project Glasswing operates as a controlled initiative where select organizations—including tech giants Amazon, Microsoft, Nvidia, and Apple—deploy the model for defensive cybersecurity purposes . Last week, Anthropic began informing partners they can now disclose their involvement in the program and, at their discretion, share findings, best practices, tools, or code developed through it. Partners may distribute this information to security teams at other companies, industry bodies, regulators, government agencies, open-source maintainers, the media, or the public, provided they follow responsible-disclosure norms
2
. The initial confidentiality protections were built into agreements after partners requested assurances before sharing sensitive findings and expressed concern about becoming targets for attackers.Experts note that Mythos' capabilities to code at a high level give it a potentially unprecedented ability to identify cybersecurity vulnerabilities and devise ways to exploit them
1
. This advanced functionality positions the model as a powerful tool for organizations seeking to proactively identify and patch vulnerabilities before malicious actors can exploit them. The Pentagon has already begun deploying Mythos to find and patch software vulnerabilities across the U.S. government, even as it completes a transition away from the AI company, according to the Defense Department's top technology official2
. This government adoption signals confidence in the model's defensive capabilities despite ongoing organizational changes.Related Stories
The policy adaptation aims to ensure key information can be shared broadly for "maximum defensive impact," as Anthropic's spokesperson explained
1
. While there was never a specific Glasswing non-disclosure agreement, confidentiality protections were incorporated into partner agreements at the program's outset. As the initiative has evolved, Anthropic recognized that limiting information sharing could hinder collective security efforts. The shift toward openness suggests that the benefits of collaborative threat intelligence outweigh concerns about exposing sensitive security research. Organizations participating in Project Glasswing can now contribute to a broader ecosystem of cyber defense, potentially accelerating the identification and remediation of vulnerabilities across multiple sectors. This approach aligns with industry trends favoring coordinated vulnerability disclosure and collective defense strategies against increasingly sophisticated cyber threats.Summarized by
Navi
[2]
29 May 2026•Technology

19 Jun 2026•Policy and Regulation

14 May 2026•Technology

1
Policy and Regulation

2
Technology

3
Policy and Regulation
