






























When Anthropic launched Project Glasswing earlier this month, it did so with the kind of announcement that sounded like public service and read like a market consolidation.
The initiative brought together Amazon Web Services (AWS), Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks — essentially the who’s who of the global technology industry — under a single coordinated effort to secure the world’s most critical software using an unreleased AI model called Claude Mythos Preview.
On the surface, it is a noble coalition. But looked at from another angle, it is a cartel of the most powerful technology companies on earth jointly deciding who gets access to the most capable cyber tools ever built.
Mythos Preview, Anthropic’s new frontier model, has demonstrated an ability to find and exploit vulnerabilities hidden for decades in software that powers everything from operating systems to web browsers to the open-source code underpinning much of the internet.
To understand why this matters, a brief explanation of the terminology is useful. A “zero-day vulnerability” is a flaw in software that nobody knew existed until someone spots it, and so developers have zero days to fix it. An “exploit” is the actual weapon built from that flaw, a piece of code that lets an attacker break into a system, steal data, or crash critical services.
Previously, finding zero-days and turning them into working exploits required expert human researchers working for days or weeks. Mythos Preview, according to Anthropic’s own technical documentation, can do both autonomously, overnight, and at a fraction of the cost.
Anthropic claims the model identified a 27-year-old flaw in OpenBSD, an operating system specifically built with security as its primary design principle. It found a 16-year-old bug in FFmpeg, a video processing library so widely used and so thoroughly tested that research papers have been dedicated to how best to audit it. In one case, automated testing tools analysed a vulnerable line of code five million times over the years and missed it entirely. But Mythos Preview spotted it.
Anthropic says its model has already surfaced thousands of critical vulnerabilities and is still working through an extensive list of open-source codebases.
The stated mission of Project Glasswing is defensive: find bugs before bad actors do, notify developers, and fund open-source maintainers, who are usually independent programmers who need time and resources to fix flaws in the software.
Anthropic has committed $2.5 million to the Open Source Security Foundation and Alpha-Omega, and $1.5 million to the Apache Software Foundation. Free access to Claude subscriptions is being offered to verified open-source developers.
While these are meaningful gestures, the structure of the initiative raises a pertinent question on why Anthropic has decided, unilaterally, that Mythos Preview will not be made generally available. The most powerful bug-finding tool in existence is being distributed exclusively through a coalition that Anthropic convened and controls. And the companies gathered under Project Glasswing are also the ones best positioned to profit from a software breakdown.

This initiative comes less than a month after Google completed its acquisition of Wiz, Israeli cybersecurity firm, in $32 billion deal, marking the largest acquisition in the company’s history. Wiz built its reputation by offering a platform that scans cloud environments for vulnerabilities and misconfigurations.
Together, Google Cloud and Wiz will now offer what they describe as an AI-powered cybersecurity platform combining Google’s Threat Intelligence and Security Operations with Wiz’s Cloud Security Platform, designed to detect, prevent, and respond to threats across all environments. The deal positions Google not merely as a cloud provider that happens to offer security tools, but as a vertically integrated security company with the AI backbone to run it.
For Google, the move is widely seen as a way to differentiate its offering through a security-first cloud strategy. In other words, cybersecurity is no longer a feature Google offers alongside its cloud services; it is the competitive differentiator. Microsoft made a similar bet years ago, quietly building its security division into a business that now generates over $20 billion in annual revenue. Vertically integrating cybersecurity into cloud services provides hyperscalers a new category of enterprise power.
While Google, which offers its own rival model Gemini, is a part of Project Glasswing, OpenAI is conspicuously absent in the partner list. The company whose name is most synonymous with the public face of the AI revolution was not invited to Anthropic’s table.
But the ChatGPT-maker has moved quickly. Just a week after Glasswing was announced, the company expanded its own Trusted Access for Cyber (TAC) programme and released GPT-5.4-Cyber, a version of its latest model purpose-built for defensive security work with fewer restrictions for verified users.
The launch directly responds to Anthropic’s Project Glasswing, with OpenAI’s benchmark data showing just how fast these capabilities are advancing: its models went from scoring 27% on capture-the-flag security challenges in August 2025 to 76% just three months later.
But the more structurally interesting question about OpenAI is not its cybersecurity product roadmap. It is the nature of the company’s infrastructure bets and what they mean for its ability to compete in a field increasingly defined by the integration of AI, cloud, and security.
Its Stargate infrastructure project gives it unparalleled scale for model development, and its partnership with Microsoft provides some enterprise security reach. But it lacks a platform like Wiz that sits inside enterprise cloud environments, watching for threats in real time. In cybersecurity, that kind of embedded presence is enormously difficult to replicate through model releases alone.
Anthropic has made the first move and formed a solid alliance with the most important names in the world of tech. That leaves OpenAI with fewer options. It could possibly attempt an acquisition of its own in the security space or deepen its relationship with Microsoft to the point where its models become the intelligence layer beneath Microsoft’s security stack.
But OpenAI has said it does not think it is “practical or appropriate to centrally decide who gets to defend themselves,” positioning its approach as broader and more democratised than Glasswing’s curated coalition.
So, with Anthropic’s Project Glasswing a system is emerging where the same firms that develop the AI models capable of finding vulnerabilities at unprecedented scale will also be the firms selling the platforms that protect against those vulnerabilities.
They convene the coalitions that decide who gets access to the most advanced tools. They fund the foundations that maintain the open-source software those tools scan. And they do all of this while their models grow more capable by the month.
While their goal is rational and, in isolation, defensible, the aggregate effect will lead to a concentration of cybersecurity power in a handful of firms that is difficult to overstate.
This could possibly lead to a cartel-like behaviour sans price fixing as these firms will become companies whose structural position means that the rest of the world’s ability to secure its digital infrastructure increasingly runs through their products, their platforms, and their decisions about who gets access to what.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。