With AI, Cybersecurity Focus Shifts from Finding Flaws to Fixing Them

One of cybersecurity's biggest challenges has always been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

At the center of that shift is Anthropic's Project Glasswing, a cybersecurity initiative that provides selected organizations with access to Claude Mythos Preview, an advanced AI model designed to identify software vulnerabilities and potential attack paths.

According to Anthropic, Project Glasswing has expanded to more than 150 organizations across more than 15 countries and has helped identify more than 10,000 high- or critical-severity vulnerabilities in participating organizations and software projects. The figures were disclosed by the company in materials describing the initiative.

The program gained additional attention recently when BT Group became the first U.K. company to publicly join the initiative. According to BT and reporting by TechRadar, the telecommunications company plans to use the technology to strengthen defenses across its networks and customer systems. BT said it currently blocks approximately 4 million cyber attacks each day.

The development reflects a broader trend in which AI companies are positioning advanced models as cybersecurity tools for governments, critical infrastructure operators, and large enterprises.

According to Anthropic, Project Glasswing participants include organizations from sectors such as telecommunications, healthcare, energy, and government. The company also lists major technology and financial firms, including Microsoft, Google, Apple, Nvidia, Amazon Web Services, CrowdStrike, Cisco, and JPMorgan Chase as participants or collaborators in cybersecurity-related efforts.

Security experts say one of AI's most significant advantages is its ability to analyze large code bases rapidly and identify relationships among vulnerabilities that may be difficult for human analysts to recognize.

According to reporting by The Wall Street Journal, executives at Visa involved with the initiative said the Claude Mythos Preview model can connect multiple lower-severity vulnerabilities into realistic attack chains, helping defenders identify risks that might otherwise go unnoticed.

The promise of the technology, however, is accompanied by concerns about misuse.

Anthropic has stated that Claude Mythos Preview is not broadly available because the same capabilities that can help defenders identify vulnerabilities could potentially assist attackers in locating weaknesses more efficiently. The company has said access is restricted to vetted organizations because of concerns that advanced cybersecurity models could be used for offensive purposes if released widely.

Those concerns have become increasingly prominent as governments and regulators examine the security implications of frontier AI systems. Anthropic has positioned Project Glasswing as a defensive cybersecurity initiative while maintaining restrictions on public access to the underlying model.

The result is a growing debate over whether AI's greatest impact on cybersecurity will come from strengthening defenses, making attacks more sophisticated, or both.

For now, supporters of the technology argue that AI is helping organizations address a longstanding problem: the inability to identify and remediate vulnerabilities fast enough. If the technology continues to improve, cybersecurity professionals say the bottleneck may no longer be finding flaws, but determining which ones to fix first.

Updates on Project Glasswing can be found here on the Anthropic site.

About the Author

John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS.  He can be reached at [email protected].

Featured

  • digital graph

    Building Genuinely Data-Informed School Districts

    Schools today generate enormous amounts of data. The difference between collecting it and using it effectively often comes down to quality, access, and context.

  • Neon blue security locks with a single red highlight

    With AI, Cybersecurity Focus Shifts from Finding Flaws to Fixing Them

    For decades, one of cybersecurity's biggest challenges has been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

  • Top View Shot in Elementary School Computer Science Classroom

    Education's Top 5 Technology Priorities and the Challenges Standing in the Way

    Cybersecurity ranks as the No. 1 priority for education technology leaders in the United States, according to the latest State of Ed Tech report from CoSN, yet insufficient cybersecurity staffing and the lack of a dedicated budget are key barriers.

  • Engineering team implements digital guardrails on AI

    3 Starting Points for Integrating AI Guardrails in K-12 Districts

    As education leaders start to craft an AI policy that is both practical and flexible enough to evolve with this fast-changing technology, there is at least one principle that should be foundational: AI should serve to augment human critical thinking and creativity but never replace human interaction and decision-making.