惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Threat Research - Cisco Blogs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Schneier on Security
Schneier on Security
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
Help Net Security
Help Net Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
P
Privacy International News Feed
AWS News Blog
AWS News Blog
Forbes - Security
Forbes - Security
N
News and Events Feed by Topic
L
LINUX DO - 最新话题
A
Arctic Wolf
Hacker News: Ask HN
Hacker News: Ask HN
P
Proofpoint News Feed
N
News and Events Feed by Topic
S
Security @ Cisco Blogs
Cyberwarzone
Cyberwarzone
Google Online Security Blog
Google Online Security Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
PCI Perspectives
PCI Perspectives
Know Your Adversary
Know Your Adversary
The Hacker News
The Hacker News
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Tenable Blog
S
Security Affairs
P
Privacy & Cybersecurity Law Blog
W
WeLiveSecurity
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
S
Securelist
AI
AI
Latest news
Latest news
T
The Blog of Author Tim Ferriss
Application and Cybersecurity Blog
Application and Cybersecurity Blog
C
Cybersecurity and Infrastructure Security Agency CISA
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
C
CXSECURITY Database RSS Feed - CXSecurity.com
美团技术团队
G
GRAHAM CLULEY
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
Hacker News - Newest:
Hacker News - Newest: "LLM"
C
Cisco Blogs
V
Visual Studio Blog
L
LangChain Blog

The New Stack | DevOps, Open Source, and Cloud Native News

Agentic development hinges on verification. For cloud-native software, that is a runtime problem. AI agents need infrastructure: Why Europe’s regional cloud strategy matters Transform your AI coding agent into a deterministic Java Spring expert WeAreDevelopers is coming to the US to give unsung developers a bigger voice Cleaner AI training data, fewer bugs: Sonar’s SonarSweep explained Observability overload is drowning engineers Google’s DiffusionGemma is 4x faster than its other Gemma models Fable 5: Guardrails and burn rate are annoying users, who say it’s still better than Opus 4.8 The Anthropic leader who built Claude Code says he ditched prompting — now he just writes loops. AWS can now mathematically prove your VMs are isolated Microsoft pulled 73 GitHub repos after malware attack — but still won’t say who’s compromised Databricks wants to kill the “email me a file” problem for AI agent skills Ramp bets forward deployed engineers can do what off-the-shelf finance AI can’t Git real: AI agents aren’t just for solo developers anymore Anthropic launches Claude Mythos/Fable 5, but you better try it soon Spring is 23 years old. AI just made it a security emergency. This AI agent startup ditched Anthropic for DeepSeek — and says it’s saving millions When your data model is the bottleneck: lessons from Medium’s feature store How long before we stop reading the code? The tokenmaxxing party is over, and Revenium is mopping up How AI is solving the memory crunch it created Microsoft’s pitch to enterprises: Ditch Azure Repos for GitHub, despite its rocky reliability record Claude Code’s biggest upgrade yet ran 5 agents at once — here’s what happened Why Anthropic just doubled Claude Cowork limits at no charge For years, Apache Cassandra handed this work to your team — 6.0 takes it back “A dangerous combination”: The 2 factors that can “corrupt” AI agent workflows With Foundry, Microsoft bets the enterprise AI battle is about reliability, not capability Microsoft unlocks Visual Studio for developers left behind by its own AI AI teams now deploy 1,000 times a month. Your pipeline wasn’t built for that. Microsoft just made the agent runtime free — and kept everything around it “Whoever builds the most joyous product wins”: The agent war begins Netlify CTO Dana Lawson: Writing code is no longer the job From Jupyter Notebook to production: How to ship AI systems that actually work OpenClaw used Gavriel Cohen’s code and exposed the AI Agent accountability problem Replit shows how vibe coding is getting its own financial stack — and a path to profit Cloudflare aqui-hires VoidZero: Did a piece of the open web just stabilize, or become more brittle? Cursor cuts prices and adds enterprise spend controls amid “tokenomics” reckoning Google Gemma 4 12B nearly matches 26B benchmarks — and runs on your laptop Snowflake thinks it knows what’s really slowing developers down Autonomous agents have met their biggest challenge yet: The database. Why agentic AI makes the ops platform the most important layer in the enterprise How to dramatically improve enterprise security alert tuning to battle cyberattacks Why the need for humans won’t disappear in the age of autonomous databases How to secure Kubernetes in the age of AI workloads Asana says its new AI “chief of staff” turns your Slack chaos into trackable work Nvidia’s best model is now live Mate Security’s Asaf Wiener made every backend engineer a model router. He’s right to. The AI cost crisis finally has a watchdog — just not the companies causing it How to get operational data off the factory floor without creating an IT breach Why CPUs still matter in the age of AI agents Rayfin: Microsoft’s answer to the gap between vibe coding and enterprise production Microsoft bets the enterprise AI race will be won on data context, not model power How GitHub plans to win developers back Microsoft really, really, really wants developers to love Windows again With Intelligent Terminal, Microsoft is reinventing the Windows terminal Microsoft debuts “Scout” at Build, a new personal agent for work OpenAI’s Codex adds new tools — Sites, Annotations, more plugins — for knowledge workers GitHub Copilot’s usage-based billing is live: Here’s what you need to know OpenAI, Anthropic, Google, Amazon, and xAI all fail on type of attack, study finds JetBrains open-sources Mellum2 to go where Claude Code can’t Claude Code vs. Cursor vs. Codex vs. Antigravity — six months in This coding agent doesn’t want your feedback — it ships without it “Blowing things up”: The one move vendors got wrong on AI agents At Sapphire, SAP makes the case that enterprise AI is a context problem Gavriel Cohen found his own code inside OpenClaw, so he walked away AI retrieval at scale is becoming a systems problem, not a tooling problem The DIY platform trap that’s burning out engineering teams I tested Cursor’s new Jira integration and it’s 5 stars, no notes. Here’s why. Why GPT-5.4, Claude, and Gemini can’t agree on basic, real-world facts Replit’s vibe coding platform just got a Visa-backed identity layer for AI agents — and it changes how agents spend money Opus 4.8 Made Claude Smarter. Token Discipline Got Urgent. Why Linux creator Linus Torvalds gets angry hearing “99% of code is AI” Vendor neutrality isn’t magic: A hard look at the OpenTelemetry ecosystem “The AI did it” won’t save you when EU regulators come knocking The fix for soaring AI cloud bills exists — so why won’t we trust it? AI is shipping code faster than security was built to handle Why AWS scrapped OpenSearch’s architecture to chase agent workloads Claude Opus 4.8 is here: effort controls, dynamic workflows, cheaper fast mode, better honesty, less deception Percona celebrates 20th birthday with new foundation — and a goat cake Why OpenAI and Anthropic are hiring forward deployed engineer teams Claw-style AI agents are coming to the enterprise. The governance infrastructure is still catching up. The agentic identity crisis: Why your security isn’t ready for the AI revolution Debugging the undebuggable: building observability into probabilistic AI systems Snowflake commits $6B to AWS as it pushes deeper into AI Why MotherDuck refuses to fork DuckDB Researcher “gave Claude Code ‘ADHD’… and it thinks 2x better now.” Outside experts want more proof. “There is no accountability”: AI coding agents are installing packages no one owns “Tokenmaxxing is real, expensive & it’s spreading”: AI budgets are exploding With Google’s debut, the most important AI agent feature is now the most boring one Why AI agents need a Context Lake Google ranks the best AI for building Android apps, and the winner isn’t Gemini Google pushes Pro, Ultra, and free users from open-source Gemini CLI to closed-source Antigravity CLI The reason enterprise outages almost never start where ops teams think Taming the agentic influx: a blueprint for AI business observability How the AC/DC framework helps teams govern AI coding agents GitLab 19.0 trades its string section for a full DevSecOps orchestra Who’s monitoring the agents? How Jaeger hit 8.6× compression on 10 million spans with ClickHouse What ClickHouse learned from a year of coding with AI agents OpenClaw passed 300,000 GitHub stars. Then Google launched Spark.
“A successful attack could be catastrophic”: Anthropic gives more groups access to Claude Mythos
Adrian Bridgwater · 2026-06-03 · via The New Stack | DevOps, Open Source, and Cloud Native News

Anthropic laid down some sobering words on Tuesday.

A successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security,” reads an announcement from the AI giant.

The organization’s warning aligned with news of an expansion of Project Glasswing, a collaborative effort designed to secure global software code resources. The project provides secure, approved access to Claude Mythos Preview, which comprises Anthropic’s group of models that are more powerful than the Opus family of large language models available to the general public. 

“AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” —Anthropic

Anthropic announced Project Glasswing on April 7, stating that 50 organizations would have access to its powerful AI tools. The announcement came paired with a statement that reads in part, “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.”

Initial Project Glasswing members

Key initial member partners in Project Glasswing included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and Anthropic itself.

On Tuesday, Anthropic announced that it was adding to the Glasswing project “approximately 150 new partners:

We’re now expanding Project Glasswing. Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the US government, we’re extending the partnership to approximately 150 new organizations. Each one will need to meet our security requirements before they gain access.

Those groups, as well as the 50 or so that were part of Glasswing when it was announced in April, crucially have early access to Mythos Preview, its highly advanced AI model that Anthropic says has already found “thousands of high-severity vulnerabilities”, including a number in “every major operating system and web browser” today. Given the rate of AI progress, the organization has predicted that “it will not be long” before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely.

Highly aware of the risks associated with model misuse by bad actors and emphasizing the use of Claude Mythos to prevent, rather than aid, cyber risk from the start, Project Glasswing partners pointed the pre-release software at their codebases and found more than 10,000 high- or critical-severity security flaws.

How is Project Glasswing being expanded?

The 150 or so new partners — Anthropic doesn’t offer a specific figure — joining Project Glasswing were not identified in Tuesday’s announcement. Originating in around 15 countries, the project seeks to further expand its geographical reach.

“The group covers several industries that weren’t well represented in our initial cohort, such as power, water, healthcare, communications, and hardware. And many of the new partners are vendors — companies or nonprofits that maintain codebases that are relied upon by lots of other organizations around the world, including governments,” the company said.

A multiplicity of Mythos-class models 

The initiative was formed in response to what Anthropic has said it has been “warning about for some time,” i.e., that within 6 to 12 months the team expects that “many other AI companies” will have Mythos-class models, which, of course, could be released without safeguards to prevent misuse.

“We see our role as twofold,” states Anthropic. “First, to help the software industry adapt by safely providing wide access to better models, tools, and common infrastructure. Second, to steadily shift the support we provide, from finding vulnerabilities to disclosing, fixing, and deploying patched software.”

Apparently, as genuinely collaborative as it was described, the first weeks of Project Glasswing saw participants sharing information and best practices with other partners while working with third parties to triage the model’s findings. Those best practices are intended to lay down methods that can be “replicated widely” by other organizations adapting to new tools of this nature.

Claude Security scans codebases & suggests patches

To support its work in this space. Anthropic also released Claude Security in February, a service that draws upon the company’s latest public frontier models, including Claude Opus 4.8, to scan codebases and suggest patches. “We’re also releasing – on request, to trusted security teams – the tools we developed to help Project Glasswing’s partners find vulnerabilities more quickly,” said Anthropic.

As Anthropic has said, it views the cybersecurity bottleneck as a matter of now verifying, disclosing, and patching the large number of vulnerabilities that Mythos-class models can surface.

As the super AI model race continues, OpenAI released GPT-5.5-Cyber as part of its Trusted Access for Cyber (TAC) program on May 7, and subsequently scaled it up on April 14, promising that the company is “Fine-tuning our models specifically to enable defensive cybersecurity use cases.” 

OpenAI backed up this move and said its approach of scaling cyber defense would move “in lockstep with increasing model capabilities” to guide the testing and deployment of future releases.

“Anthropic’s Project Glasswing program runs on the opposite model [to open, peer-reviewed standards]. It chooses which findings to send for independent review, and the reviewers are contractors who have been hired in. That’s not third-party validation, that’s editing.”
—Justin Beals, Strike Graph

Edited validation by Anthropic is not good enough

Justin Beals, CEO & founder of Strike Graph, an AI-native GRC and compliance management platform, tells The New Stack that he thinks a controlled rollout of frontier AI is the right instinct. But he has stated that he has concerns over how vulnerabilities are being assessed and analyzed.

“The engineering community has spent years building open, peer-reviewed standards for how software gets evaluated and trusted,” says Beals. “Anthropic’s Project Glasswing program runs on the opposite model. It chooses which findings to send for independent review, and the reviewers are contractors who have been hired in. That’s not third-party validation; that’s editing.”

Beals wants the broader security community involved with access to independent, third-party evaluation across the full corpus.

“Developers building on top of these models need to know what they’re actually integrating, not a summary of what Anthropic decided to share. As frontier models get deeper into the stack, the technical debt of opaque safety claims compounds. The standard for any infrastructure this consequential should be verifiable transparency, not curated receipts,” Beals clarifies.

It seems like the need for approval is widespread, but a more open and even balance is, too. Guy Currier, an analyst at the Futurum Group, tells The New Stack that if we thought drones were the frontier of automated warfare, we’re wrong. 

“Software is an equally advanced front, and cyberthreats follow no Geneva Convention and are pervasively present in corporate, public, personal, and political spheres, not just military,” Currier says. “Mythos has had its stumbles and Project Glasswing its valid criticisms (lack of transparency, self-policing), but something broad-based has to be done, and the sooner the better. Anthropic’s leadership is welcome, helpful, and on brand.”

What’s next for Project Glasswing in 2026?

Looking ahead (which in AI circles may be later this month), Anthropic envisages more for initiatives like Project Glasswing and any that come after it. 

“We’re in discussions with third parties about how we might substantially scale up the reviewing and patching of vulnerabilities in open-source software. We’re also working on sharing ideas and best practices for disclosing vulnerabilities to open-source maintainers, with the intent of making these reports easier to triage and to act upon,” states Anthropic in its Tuesday announcement.

Mythos Preview can also be used for penetration testing (simulating a cyberattack to identify how vulnerabilities might be exploited), automating threat detection and response, and rebuilding legacy codebases in memory-safe languages, among many other defensive tasks.

The organization has said it has a “longer-term aim” to support the industry in creating new initiatives, standards, and infrastructure for the era of powerful cyber models.

YOUTUBE.COM/THENEWSTACK

Tech moves fast, don't miss an episode. Subscribe to our YouTube channel to stream all our podcasts, interviews, demos, and more.

Created with Sketch.