← Back to all entries
2026-05-25 🧭 Daily News

Project Glasswing Finds 10,000+ Critical Bugs, Compliance API Ecosystem Launches & Anthropic's 2028 AI Scenarios

Project Glasswing Finds 10,000+ Critical Bugs, Compliance API Ecosystem Launches & Anthropic's 2028 AI Scenarios — visual for 2026-05-25

🧭 Project Glasswing: Claude Mythos Preview Uncovers 10,000+ Critical Vulnerabilities in One Month

One month after Claude Security entered public beta, Anthropic has published the first results from Project Glasswing — its initiative to use Claude Mythos Preview, an unreleased frontier model optimised for vulnerability discovery, to scan critical software infrastructure. The headline figure: more than 10,000 high-or-critical-severity vulnerabilities identified across partner systems in the first month alone. That total includes both enterprise partner codebases and a sweep of over 1,000 open-source projects.

Partner-by-partner highlights

Open-source sweep: 6,200 valid high/critical findings

The open-source component scanned more than 1,000 projects and identified approximately 6,200 estimated high-or-critical-severity vulnerabilities. Of the subset assessed by independent security firms, 90.6% proved to be valid findings, with 62% confirmed at high or critical severity — a significantly lower false-positive rate than most automated scanning tools achieve.

The new bottleneck: patching, not discovery

The most consequential observation in the update is structural: the bottleneck in software security has shifted. AI dramatically accelerates vulnerability discovery, but human-dependent triage, disclosure coordination, and patching pipelines remain slow — averaging roughly two weeks per critical bug. Anthropic is working with partners to develop AI-assisted patch drafting workflows to close that gap.

What this means if you operate Claude-integrated software

Project Glasswing is currently a curated partner programme — not a self-serve product — but it signals the direction of travel for Claude Security (already in public beta for Enterprise customers). If your engineering team uses Claude Code's /security-scan workflow or Claude Security's codebase scanning, expect the underlying model capability to improve substantially as Glasswing findings feed back into Mythos training data. Operators building in regulated sectors (fintech, healthcare, defence supply chain) should monitor Anthropic's partner expansion announcements, as priority access to Glasswing scans will likely be negotiated through enterprise agreements.

⭐⭐⭐ anthropic.com
Project Glasswing Claude Mythos vulnerability scanning cybersecurity open-source security Cloudflare Mozilla

🧭 Five Enterprise Security Vendors Launch Claude Compliance API Integrations on the Same Day

On May 21, 2026, five major enterprise security and governance vendors simultaneously announced integrations with Anthropic's Claude Compliance API — the REST endpoint that gives Enterprise plan administrators programmatic access to Claude activity data for continuous monitoring and policy enforcement. The coordinated launch signals that Anthropic is treating the Compliance API as a cornerstone of its enterprise go-to-market strategy, with a growing ecosystem of SIEM, DLP, CASB, and identity-governance tools plugging directly into Claude activity streams.

The five integrations at launch

What the Compliance API exposes

The API provides security visibility into prompts, responses, uploaded files, Projects, and administrative actions — everything that flows through Claude Enterprise and Claude Platform. Data is streamed in near-real-time to connected tools, with a 90-day history available for forensic investigation and audit trails.

Practical guidance for enterprise Claude admins

If your organisation already runs Netskope One, Cloudflare One, or a SailPoint/Saviynt identity platform, you can likely activate the Claude Compliance API integration through your existing vendor relationship — no new contracts required. The most immediately valuable use case is DLP policy unification: your existing rules for data classification (e.g., PII handling, MNPI controls for financial firms) now apply automatically to Claude-generated content, removing the need to build separate Claude-specific data-handling policies from scratch. Check your vendor's documentation portal for the activation steps, as each integration varies in setup complexity.

Compliance API enterprise security DLP CASB governance Netskope SailPoint Cloudflare

🧭 Anthropic Publishes "2028: Two Scenarios for Global AI Leadership" — What It Signals for the AI Development Ecosystem

On May 14, Anthropic published a policy research essay titled 2028: Two Scenarios for Global AI Leadership, arguing that the decisions made in 2026 will substantially determine which actors shape global AI governance norms by 2028. The paper is notable less for its geopolitical argument than for what it reveals about Anthropic's strategic assumptions — assumptions that directly affect what frontier models get built, when they ship, and how they are distributed.

The two scenarios in brief

The key technical argument: distillation attacks

One of the more technically substantive claims in the paper is that "distillation attacks" — training a new model by having it predict the outputs of an existing frontier model at scale — represent a meaningful transfer of capability that current export control regimes do not adequately address. Anthropic recommends that this be legally clarified as a form of IP theft and treated accordingly under existing or new legislation.

Why this matters for developers building on Claude today

This paper is Anthropic's public statement of intent about what kind of company it plans to be in a contested AI landscape. For developers and operators, the practical read-through is: Anthropic is unlikely to loosen safety guardrails in response to competitive pressure, and may tighten them if it believes capability leakage is occurring. If your use case involves fine-tuning on Claude outputs at scale, or building tools that systematically extract and re-train on model responses, expect increasing scrutiny under both the API usage policy and potentially broader regulatory frameworks. The paper also signals that Anthropic will actively lobby for policies that could affect model availability in specific jurisdictions — relevant context if you are building globally distributed products.

⭐⭐⭐ anthropic.com
AI policy 2028 scenarios compute export controls distillation attacks AI governance safety
Source trust ratings ⭐⭐⭐ Official Anthropic  ·  ⭐⭐ Established press  ·  Community / research