Project Glasswing is Anthropic’s controlled program for applying advanced cyber capabilities to important software. The current story includes expanded partner access, a public disclosure dashboard, Claude Security, Fable 5, and Mythos 5—not only the initial April cohort.
Current as of 2026-08-15
Anthropic’s June 2 update says the initial group of roughly 50 partners was being expanded by approximately 150 organizations. Anthropic’s disclosure dashboard said human triage and review remained the rate-limiting step.
Decision summary
- Use current Anthropic program updates instead of freezing the April launch narrative.
- Separate model findings from validated and disclosed vulnerabilities.
- Give maintainers time and evidence to triage, patch, test, and coordinate disclosure.
- Expect capability and access models to continue changing.
How the program evolved
Anthropic launched Glasswing with a limited set of critical software and infrastructure partners using Mythos Preview. By June 2, it described a broader international expansion and a longer-term goal of supporting disclosure, remediation, and deployment—not only discovery.
What the disclosure dashboard shows
Anthropic’s coordinated vulnerability disclosure dashboard reported 1,596 disclosed vulnerabilities across 281 open-source projects as of May 22, 2026, with 97 patched. Anthropic explicitly says disclosed items are a subset and that independent human triage and review are the limiting step.
Current model context
Anthropic’s Fable 5 and Mythos 5 announcement describes the two as sharing an underlying model with different safeguards and access. Mythos-class capability is restricted; Fable is designed for broader use with cyber safeguards.
What enterprises should do
- Maintain current asset, dependency, and software-owner inventories.
- Subscribe to vendor and open-source advisories.
- Fund triage, testing, coordinated disclosure, and patch deployment.
- Protect source code and security-tool access with least privilege.
- Measure time from validated finding to safe production fix.
Next step for your environment
Build a vulnerability intake path that can absorb faster discovery without bypassing validation, disclosure coordination, testing, or change control. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
- Anthropic — Expanding Project Glasswing
- Anthropic — Coordinated vulnerability disclosure dashboard
- Anthropic — Claude Fable 5 and Claude Mythos 5
Review trigger: Review whenever Anthropic changes Glasswing scope, disclosure metrics, model access, or safeguards.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles