Deep|Glasswing/Mythos: AI-Native Cyber Capability Drives a Reshaping of the Cybersecurity Value Chain and Sector Divergence
Executive Summary
On June 2, Anthropic expanded Project Glasswing to nearly 200 partners. We do not view this as a simple expansion of a frontier-model pilot. Rather, we see it as an important signal that AI-native cyber capability is beginning to enter real-world enterprise and critical-infrastructure security workflows.
In industry terms, models such as Claude Mythos Preview are likely to push the marginal cost of vulnerability discovery another step lower, while shifting the center of gravity in cybersecurity from “finding vulnerabilities” toward later-stage, more closed-loop workflows such as validation, prioritization, remediation, response, and governance.
We expect this to drive more pronounced dispersion within the cybersecurity group. Vendors with platform breadth, cross-domain telemetry, enterprise workflows, remediation loops, and security-operations control points should be better positioned to capture the incremental value created by this technology shift. By contrast, companies whose business models still depend on traditional vulnerability scanning, low-end SAST, point AppSec scanners, or commoditized SOAR automation could face the dual pressure of functional commoditization and multiple compression.
At the public company level, we are more constructive on platform vendors capable of supporting an end-to-end security loop, including PANW, MSFT, CRWD, GOOGL, and CYBR. Conversely, QLYS, TENB, RPD, and parts of the lower-end AppSec / SAST tooling market should be viewed with caution, as their medium-term narratives could come under pressure.
I. Event Background: Glasswing Is Moving From Capability Validation to Controlled Scaled Deployment
Project Glasswing was launched by Anthropic in April 2026. Initially, Claude Mythos Preview access was offered only to roughly 50 highly trusted partners, primarily for vulnerability discovery and remediation in real codebases and critical systems. Anthropic later added roughly 150 partners, bringing the overall partner base close to 200 organizations across more than 15 countries. Newly covered sectors include power, water, healthcare, communications, hardware, and other critical infrastructure domains.
We believe this expansion is worth highlighting for three reasons.
First, the project has shifted from model capability validation to controlled real-world deployment. The initial group of roughly 50 partners was mainly meant to answer whether Mythos could work in complex codebases. With the partner base now approaching 200 organizations, the focus is no longer simply on proving that the model works; it is on releasing defensive value across a broader set of critical systems in advance. In a sense, this also suggests that the technical barriers to a broader Mythos rollout are declining.
Second, it reflects Anthropic’s proactive management of dual-use cyber risk. Mythos can both discover and validate vulnerabilities. In the hands of defenders, this capability is a force multiplier; in the hands of attackers, it can also lower the bar for offensive activity. As a result, Anthropic has not chosen to release a public GA model but instead is releasing the capability through a vetted partner network.
Third, Glasswing is effectively a governance and productization rehearsal for Mythos-class models ahead of commercialization. On one hand, Anthropic is keeping tight control over Mythos Preview access. On the other hand, it is using real customers and critical-infrastructure environments to test the security boundaries, delivery mechanisms, workflow interfaces, and regulatory frameworks that future AI cyber products will require.
II. Mythos’ Core Capabilities: From Code Scanning to an AI Security Researcher
Mythos is not merely a step-function improvement in coding capability. More importantly, its cyber workflow is beginning to resemble that of an AI security researcher. Compared with traditional scanners, Mythos-class models differ across five main areas.
1. Vulnerability Discovery: Expanding the Coverage of Vulnerability Identification
Mythos can identify potential security defects in large-scale codebases, making it particularly well-suited for open-source projects, browsers, cloud platforms, operating systems, networking equipment, industrial software, and complex legacy systems.
Historically, code auditing has relied on either security researchers or rule-based scanners, both of which are constrained by headcount and coverage. Mythos’ incremental value lies in stronger contextual understanding and cross-file reasoning, allowing it to broaden audit coverage and surface vulnerabilities that traditional tools may miss.
Channel feedback suggests that Mythos is essentially a test tool capable of surfacing “vulnerabilities that traditional tools have failed to find for years.” The vendors most directly exposed to substitution risk may be DAST / SAST-centric players such as Veracode and Snyk [S6].
2. Exploitability Analysis: From Findings to Risk Validation
The pain point for enterprise security teams is not a lack of findings; it is the lack of high-quality judgment. Which vulnerabilities are real? Which can be externally triggered? Which are actually exploitable? Which must be remediated immediately?
The value of Mythos-class capability lies in its ability to perform deeper contextual analysis of a vulnerability and to partially take over exploitability assessment and prioritization. This implies that the center of gravity in vulnerability management will gradually move from “listing CVEs / findings” to “identifying real attack risk.”
3. Exploit Chain Construction: From Point Vulnerabilities to Attack Paths
Based on public testing feedback, one of Mythos’ key breakthroughs is its ability to chain multiple issues that may not appear severe in isolation into a high-risk exploit chain. This has direct implications for existing enterprise security processes.
In traditional vulnerability management, low-severity findings often remain in the backlog for extended periods. However, once AI can demonstrate that multiple low-risk issues can be combined into a viable attack path, enterprises will need to reassess their remediation priorities, risk measurement frameworks, and broader exposure-management logic.
Channel feedback suggests that Mythos-like models will meaningfully accelerate the speed at which attackers identify and weaponize vulnerabilities. Enterprises, therefore, need to move from asking, “Do I have this vulnerability?” to asking, “Can an adversary weaponize this vulnerability?” In the future, security operations will need to move toward always-on internal red teaming and automated patching. Some channel contacts even believe that SIEM and MDR, as traditionally understood, could be materially disrupted within 12-18 months by agentic SOC tools such as 7AI and Dropzone AI.
Along this line of reasoning, the importance of capabilities such as attack graphs, exposure management, CNAPP, and XDR / SOC correlation should continue to rise.
4. Proof Generation: Reducing Triage and Engineering Handoff Costs
Mythos not only flags vulnerabilities; it can also generate evidence to validate them, thereby reducing the triage burden for security teams.
This is important for enterprise users. Historically, a large volume of scanner findings has failed to enter the remediation loop due to high false-positive rates, difficulty reproducing, and limited buy-in from engineering teams. If AI can deliver the root cause, trigger path, impact scope, and validation materials together, handoff efficiency between security and engineering teams should improve meaningfully.
5. Remediation / Patch Suggestion: Extending Into the Remediation Loop
Anthropic has already released Claude Security in public beta for codebase scanning and remediation suggestions. At a minimum, this indicates that Mythos / Glasswing is not stopping at vulnerability discovery, but is extending further into remediation workflows.
We view this as the most important part of the industry impact. Once vulnerability discovery becomes increasingly automated, the scarce capabilities will sit further downstream: automatically generating patches, integrating with CI/CD, completing Jira / GitHub workflows, validating fixes after remediation, and preserving compliance and audit records. This is also the direction in which vendors such as Tenable, Qualys, and Rapid7 are accelerating their own pivots.

