It seems hard to believe now, but it wasn’t that long ago that finding and exploiting software vulnerabilities took a skilled threat actor weeks. With the rapid development of frontier AI models and agentic AI capabilities, it now takes hours. The good news is that the fundamentals of defending against these types of attacks, and the tradecraft itself, have not changed. But it’s critical that the defenders have the capabilities and tools required to outpace attackers in this rapidly evolving AI era.
That is why Sophos is proud to join Anthropic’s Project Glasswing.
What is Project Glasswing?
Anthropic, the lab behind Claude, started Project Glasswing to help secure the world's most critical software for this AI era. Members get access to Claude Mythos 5, the frontier model that follows Claude Mythos Preview and isn't available to the public. Anthropic's own published research says Mythos can find and help fix vulnerabilities at a depth that beats even the best human researchers. It has already turned up thousands of serious flaws across every major operating system and browser. We're putting it to work on our own code and on the open-source components our customers depend on.
Sophos commitment to frontier defense
Project Glasswing is one of several frontier lab partnerships Sophos has joined this year. Most recently in June, Sophos joined OpenAI's Daybreak Cyber Partner Program, bringing OpenAI's cyber capabilities into defensive workflows such as MDR threat investigation, advisory assessments, and exposure remediation, with Sophos analysts and controls in the loop.
What Sophos brings to Project Glasswing
Sophos defends more than 625,000 organizations worldwide, with 40,000 managed detection and response (MDR) customers spanning every segment of the market: global enterprises, mid-market and commercial businesses, the suppliers and partners they depend on, and the public-sector organizations that serve their communities. We are a critical part of the core cybersecurity fabric that protects business of all sizes. That scale allows Sophos to amplify the impact of Glasswing findings and to broaden the reach of the program.
How this benefits our customers and partners
The defensive AI capabilities that frontier labs have developed is now being applied directly to our internal system.
That means:
- Stronger software, before attackers find the weaknesses. Mythos 5 is being pointed at Sophos’s own code and the open-source components our customers depend on. Vulnerabilities get found and fixed faster, before attackers can exploit them.
- Findings that strengthen the broader ecosystem. Project Glasswing is structured so that participants share what they learn back with Anthropic. At Sophos, we believe transparency is critical for defense that scales, and we commit to publishing insights where valuable for the broader cybersecurity community to benefit.
- A more level playing field. Attackers are using AI to find and exploit vulnerabilities faster than ever. Project Glasswing ensures that defenders of critical infrastructure and software have the most capable defensive AI systems in the world working on the other side of that equation.
What changes, and what doesn't.
Sophos has been on record about what Mythos changes and what it does not.
AI is capable of finding vulnerabilities at scale. Exploiting them is now easier than it’s ever been. Patching them in time to matter is increasingly challenging. Exploiting vulnerabilities is one of several paths attackers take to compromise businesses, alongside phishing, stolen credentials, supply-chain compromise, and insider threats. None of that is solved by a single model, however capable.
What Glasswing changes is the speed at which defenders can close that gap. Findings ship into our products and services. The patch cycle compresses. The Sophos customers who rely on our Defense System see the result: software that is harder to break, with more of the work done before an attacker ever shows up.
That is the promise Glasswing makes with the cybersecurity industry, and it is the promise Sophos makes with its customers and partners. We will be transparent about what this work produces and what we do with it. And we will share what we learn, because that is the best way to strengthen the cybersecurity community and protect our customers.
Learn more
Later this week, we're publishing our inaugural AI Security Report where we share our assessment of the AI landscape in cybersecurity, built on our own MDR casework, Sophos X-Ops analysis, and Counter Threat Unit (CTU) intelligence. Stay tuned for more on Sophos.com.
Sophos also recently hosted Part 2 of our “Mythos Webinar” series on Sophos’ capabilities in the AI era, offering security leaders practical guidance in leveraging endpoint, firewall, and other solutions as the AI landscape rapidly evolves. Watch on demand here.
