Author Topic: Anthropic - Project Glasswing  (Read 1963 times)

0 Members and 2 Guests are viewing this topic.

Offline gmb42Topic starter

  • Frequent Contributor
  • **
  • Posts: 335
  • Country: gb
Anthropic - Project Glasswing
« on: April 08, 2026, 11:04:34 am »
From Anthropic, today we’re announcing Project Glasswing, a new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.

We formed Project Glasswing because of capabilities we’ve observed in a new frontier model trained by Anthropic that we believe could reshape cybersecurity. Claude Mythos2 Preview is a general-purpose, unreleased frontier model that reveals a stark fact: AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.

Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout—for economies, public safety, and national security—could be severe. Project Glasswing is an urgent attempt to put these capabilities to work for defensive purposes.

https://www.anthropic.com/glasswing
 
The following users thanked this post: voltsandjolts

Offline voltsandjolts

  • Supporter
  • ****
  • Posts: 3720
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #1 on: April 08, 2026, 11:10:14 am »
Time to search the garage for my old Nokia 3210?
Or maybe the Morse key?
 
The following users thanked this post: TUMEMBER

Offline woofy

  • Frequent Contributor
  • **
  • Posts: 510
  • Country: gb
    • Woofys Place
Re: Anthropic - Project Glasswing
« Reply #2 on: April 08, 2026, 12:23:00 pm »
Given the apparent ease that mythos can escape secure containers, maybe back to signal fires!

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17761
  • Country: fr
Re: Anthropic - Project Glasswing
« Reply #3 on: April 08, 2026, 05:30:14 pm »
From Anthropic, today we’re announcing Project Glasswing, a new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.

It's like the list of the top 12 worst tech companies in the world. Nice.
I wish I could exclude the Linux Foundation and I kind of do, but it's on a very slippery slope so, unsure.
 
 

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11121
  • Country: fi
Re: Anthropic - Project Glasswing
« Reply #4 on: April 08, 2026, 05:59:08 pm »
From Anthropic, today we’re announcing Project Glasswing, a new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.

It's like the list of the top 12 worst tech companies in the world. Nice.

So, what would be your list of top 12 best tech companies in the world of similar size (thus relevance)?

Or, maybe, easier question, name 2-3 good tech companies of similar size?

My point being - all megacorporations feel (and actually are, to some extent), nasty. Calling everyone bad guys however is unproductive. For example, for me it is very easy to choose between Google and Microsoft if I have to. One of them gives much much worse vibes (and actually dysfunctional products that cause 1000x more pain). That doesn't mean I have to be a Google fanboy.
« Last Edit: April 08, 2026, 06:10:57 pm by Siwastaja »
 

Offline gmb42Topic starter

  • Frequent Contributor
  • **
  • Posts: 335
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #5 on: April 10, 2026, 01:27:03 pm »
I was pointing out that AI is deployed in security, for good or bad. The need to make it about companies is the wrong thing to think about.
 
The following users thanked this post: Siwastaja

Offline voltsandjolts

  • Supporter
  • ****
  • Posts: 3720
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #6 on: April 11, 2026, 08:58:01 am »
Paywalled  :-[;
https://www.telegraph.co.uk/business/2026/04/10/bank-of-england-raises-alarm-over-threat-from-ai-too-danger/

Anyway, more trouble at mill;

Quote
The Bank of England is to warn City chiefs about the risk of a new artificial intelligence model it is feared could break into the financial system and wreak havoc.

Officials will meet top bank and insurance bosses to discuss how they are preparing for the threat posed by Claude Mythos, a new AI system from Anthropic.

Anthropic, a Silicon Valley AI company, has deemed the tool too dangerous to release to the public after the AI discovered previously hidden flaws in computer systems quicker than any human.

The revelations about the new AI’s capabilities prompted Scott Bessent, the US treasury secretary, and Jerome Powell, the chairman of the US Federal Reserve, to summon Wall Street bank executives to a crisis meeting this week.

Meanwhile, Duncan Mackinnon, the Bank of England’s risk chief, will chair a gathering of the Cross Market Operational Resilience Group in the next fortnight that will discuss the new AI threat, The Telegraph understands.

Officials from the Treasury, the Financial Conduct Authority and the National Cyber Security Centre will also attend the meeting.

It comes amid fears the AI model could breach the IT security of the financial system.
 

Offline Picuino

  • Super Contributor
  • ***
  • Posts: 1453
  • Country: es
    • Picuino
Re: Anthropic - Project Glasswing
« Reply #7 on: May 09, 2026, 11:16:31 am »
The forum software (Simple Machines Forum) is quite old and doesn't seem to be actively maintained anymore. Unfortunately, forums like this one are becoming increasingly rare, and most of the conversation has shifted to short posts on X, Instagram, and other major social media platforms.
This means that SMF isn't as well-maintained as it was years ago, and this could eventually lead to security issues.
I think this is something to keep in mind.
 

Offline paulca

  • Super Contributor
  • ***
  • Posts: 6325
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #8 on: May 16, 2026, 09:36:43 am »
Given the apparent ease that mythos can escape secure containers, maybe back to signal fires!

Interesting inversion.

I was mostly thinking of "What can mythos break into"

You went to:  "Where do we keep mythos so it can't get out?"
"What could possibly go wrong?"
Current Open Projects:  68000 Self Build computer + OS.
 

Offline paulca

  • Super Contributor
  • ***
  • Posts: 6325
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #9 on: May 16, 2026, 09:49:35 am »
There are several things adjacent to this project and it's members, where on the Linux Foundation stand out as suspiciously OSS supporting.  The rest are mostly antiOSS advocates or would be if they could be.

The other current security problems surround using plain old, 'claude' to create supply chain attacks in many different "trust centres" across the open source infra. npm, nuget, github etc.

That 'trust' system is heavily ingrained in the OSS infra.  So much so that github these days automates repos, builds and releases based on just trusting on what someone pushes to a repo.

Someone adds a githook in their repo, along with a .claude folder. 
There repo is a dependency listed in 100 other projects.
Those projects "pull" the update and run their own pipelines to produce a build.
The automated tests and security scans run, but find nothing.
Build is automatically promoted to production... at 4am.

Unfortunately.  The damage is already done when you "pull" the repo.  The githook fire, runs a script which launches claude in the users terminal context, rapidly harvests all the cloud API tokens for company infra from the build container and uploads it to a block chain.

That's without a user at all.  If it's a developer who pull's the repo and runs claude in it... well that's the jackpot.  A far better set of cloud API tokens, far wider, richer and deeper than the build servers.

These payloads often then infest other packages the local user's API token allow them to "push" to.  It pushes commits of it's self into their CI/CD pipeline launching a new set of propogation releases.

There are a lot of ways to mitigate it, but what it has made the direct target is "trust".  Without being able to trust that the person who "maintains" an OSS project will not upload malicious code...  the OSS infra will begin to fail.

Breaking OSS philosppy or even removing it from mainstream commercial and enterprises would move any and all public accountability in the global software infra, what little of that there is today.  Software basically stops being "amateur access".  If you want to run a program on your own hardare you will need a license from the OS vendor to do so.
"What could possibly go wrong?"
Current Open Projects:  68000 Self Build computer + OS.
 

Online dobsonr741

  • Frequent Contributor
  • **
  • Posts: 967
  • Country: us
Re: Anthropic - Project Glasswing
« Reply #10 on: May 16, 2026, 02:19:43 pm »
If the build job can execute arbitrary repo-controlled code, then the build job is hostile by definition. At that point you already lost the trust boundary.

You do not need AI for this. It’s just bad design.
 

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11121
  • Country: fi
Re: Anthropic - Project Glasswing
« Reply #11 on: June 14, 2026, 04:47:12 pm »
So the "safe" version of Mythos, the Fable 5, was available for whopping 3 days, until it was effectively banned by US authorities  ::)

So what do you think?

1) Mythos is truly so much greater than anything before, that it truly can find total new types of security vulnerabilities, or build totally new types of attacks, cyber or otherwise, AND the guardrails of Fable were not reliable

2) It (obviously) is better, but not magically much more so than what state-of-the-art has been capable of doing already for the last 6-12 months (say, Opus 4.5 level - the stuff open source communities see finding real bugs, doing good bug reports, with few false positives) - Anthropic's strategy of bringing more attention to them by claiming they have dangerously good product, to balloon the company valuation for IPO - is creating backlash: cry wolf for too long at see what happens;

3) See 2, but with the twist that the whole US official ban is planned by Anthropic, or if not planned, very desirable at least - "dangerously good (source: Anthropic)" might be good marketing, but "dangerously good (source: US Government)" is even better! The ban will be eventually lifted anyway, maybe by demonstrating some "new guardrails".

4) Anthropic don't want the ban, it's hurting them - it's a conspiracy by competing AI vendors like OpenAI (Microsoft, reptilian-Gates) or Grok (Musk, Trump's best friend 4ever).

5) Other, ______________

I vote for 2. Sadly, I didn't have time to try it in my projects. Some public descriptions are saying it is crazily good - e.g. https://simonwillison.net/2026/Jun/11/fable-is-relentlessly-proactive/ shows it's pretty creative in figuring out ways to solve problems. Others say it's doing structured longer-time planning, something people have tried to emulate for a long time with multi-agent planning coordinator systems, with varying results; but this time the trait of planning ahead and following the plan would come from the model itself.
 

Offline nctnico

  • Super Contributor
  • ***
  • Posts: 30091
  • Country: nl
    • NCT Developments
Re: Anthropic - Project Glasswing
« Reply #12 on: June 14, 2026, 05:23:15 pm »
Having gained quite a bit of hands-on experience using Claude opus 4.7 and 4.8 for debugging I can't say these models are particulary good at finding faults (corner cases) that could potentially be exploited. So I would guess that the more sophisticated models would be much better at this job. Maybe the opus model has had it wings clipped on purpose. At some point the ability to reason seems to reach a plateau. The brains of the operation are still located in front of the screen.
There are small lies, big lies and then there is what is on the screen of your oscilloscope.
 

Offline paulca

  • Super Contributor
  • ***
  • Posts: 6325
  • Country: gb
Re: Anthropic - Project Glasswing
« Reply #13 on: June 15, 2026, 07:37:32 am »
The brains of the operation are still located in front of the screen.

Indeed.  Are you a security researcher?  Are you in cyber security? Have you ever worked on secure software?
"What could possibly go wrong?"
Current Open Projects:  68000 Self Build computer + OS.
 

Offline SpacedCowboy

  • Frequent Contributor
  • **
  • Posts: 419
  • Country: gb
  • Aging physicist
Re: Anthropic - Project Glasswing
« Reply #14 on: June 15, 2026, 08:19:07 am »
So the "safe" version of Mythos, the Fable 5, was available for whopping 3 days, until it was effectively banned by US authorities  ::)

So what do you think?

1) Mythos is truly so much greater than anything before, that it truly can find total new types of security vulnerabilities, or build totally new types of attacks, cyber or otherwise, AND the guardrails of Fable were not reliable

2) It (obviously) is better, but not magically much more so than what state-of-the-art has been capable of doing already for the last 6-12 months (say, Opus 4.5 level - the stuff open source communities see finding real bugs, doing good bug reports, with few false positives) - Anthropic's strategy of bringing more attention to them by claiming they have dangerously good product, to balloon the company valuation for IPO - is creating backlash: cry wolf for too long at see what happens;


I think it's probably a combination of the two. I tried Fable for my compiler/hardware project and I wasn't overly impressed, it hunted down a bug, but also made a whole bunch of mistakes that Opus didn't. This runs *very much* counter to the prevailing view, but it was my experience.


5) Other, ______________


Probably surfaced credible evidence for Trump's involvement with Epstein.
 

Offline woofy

  • Frequent Contributor
  • **
  • Posts: 510
  • Country: gb
    • Woofys Place
Re: Anthropic - Project Glasswing
« Reply #15 on: June 15, 2026, 08:48:12 am »
I also had a brief chance to try fable before it was shutdown and I was impressed. With its debugging skill anyway, I didn't get it to write any code. I have been having an issue with a web server on an STM32. it would sometimes go unresponsive after a reset. Opus 4.8 said it was insufficient buffers but increasing them only made marginal difference. Fable looked and diagnosed a TLS handshaking cascade caused by resetting at the wrong moment (the webpage is displaying real time data). It offered a fix with guard code and no more problem.

Offline Simmed

  • Frequent Contributor
  • **
  • Posts: 680
  • Country: 00
Re: Anthropic - Project Glasswing
« Reply #16 on: June 19, 2026, 02:06:23 am »
So the "safe" version of Mythos, the Fable 5, was available for whopping 3 days, until it was effectively banned by US authorities  ::)


well the nooby me
i was wondering why they named the models in HF "fable5"
looks like someone has the chance to use it (in the 3 days?) to finetune other models ?

there are many smaller models like 34B
Qwen3.6-34B-80L-Fable-5-Heretic

there is also a 120B
gpt-oss-120b-Fable-5-Distilled

and then i also noticed there is also the Qwable spin off
Quote
Qwable 3.6 35b is a full Hugging Face checkpoint fine-tuned from unsloth/Qwen3.6-35b on a cleaned Fable 5-style reasoning and instruction dataset.

https://huggingface.co/models
 

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11121
  • Country: fi
Re: Anthropic - Project Glasswing
« Reply #17 on: June 19, 2026, 07:58:13 am »
Funny how in just 3 days the probably largest and most complex LLM in history became synonymous to "can follow a multi-step process" (which earlier models also could do), and everyone slaps terms like "Fable mode" to anything that they think can follow steps, regardless of actual capabilities or size  :D
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf