Stock Markets May 18, 2026 06:30 PM

Anthropic Permits Broader Sharing of Mythos Cybersecurity Findings

Company adjusts terms for Project Glasswing partners to allow dissemination of vulnerability information to other stakeholders

By Ajmal Hussain AMZN MSFT NVDA AAPL

Anthropic has updated its approach to information sharing for Mythos, the defensive cybersecurity model deployed under its restricted Project Glasswing initiative. Partners now have clear permission to share findings, tools, and code produced through the program with other organizations and the public, subject to responsible-disclosure norms. The move follows partner requests for initial confidentiality protections and comes as agencies such as the Pentagon use Mythos to hunt and patch software vulnerabilities.

Anthropic Permits Broader Sharing of Mythos Cybersecurity Findings
AMZN MSFT NVDA AAPL

Key Points

  • Anthropic revised its policy to allow Project Glasswing partners to share Mythos-derived vulnerability findings with other organizations, subject to responsible-disclosure norms.
  • Mythos, announced April 7 and deployed via Project Glasswing, is accessible to select partners including Amazon, Microsoft, Nvidia and Apple for defensive cybersecurity purposes.
  • The Pentagon is deploying Mythos to scan and patch software vulnerabilities across the U.S. government, even as it completes a transition away from the company.

Anthropic said on Monday that it has relaxed earlier limits on how partners using its Mythos cybersecurity model may share information about cyber threats. The revision permits organizations participating in its controlled Project Glasswing effort to disclose findings about vulnerabilities to other parties who might face similar exposures.

Mythos, which Anthropic announced on April 7, is being made available to a select set of organizations under Project Glasswing. The initiative allows chosen partners - including major technology firms such as Amazon, Microsoft, Nvidia and Apple - to access the unreleased Claude Mythos Preview model specifically for defensive cybersecurity work.

Experts have noted that Mythos' advanced high-level coding capabilities give it an unusual capacity to both identify security weaknesses and articulate potential exploitation techniques. That capability prompted initially cautious handling of outputs from the model.

Last week, Anthropic began informing partners that they generally may disclose their participation in Glasswing and, at their discretion, share the findings, tools, best practices or code that they develop while working with the model. In a statement, an Anthropic spokesperson said: "We fully support our partners sharing findings with each other and companies outside of Glasswing to triage vulnerabilities."

The spokesperson noted that while there was never a specific Glasswing non-disclosure agreement, confidentiality protections were requested by partners at the outset and were incorporated into the contracts those partners signed. Those protections were put in place after participants sought assurances before revealing sensitive results and voiced concerns about becoming targets for attackers.

As the program has evolved, Anthropic said it has adjusted the protections to allow key information to be shared more broadly - including beyond the confines of the program - to maximize defensive benefits.

Under the updated guidance, partners may share information with security teams at other companies, with industry bodies, regulators and government agencies, with open-source maintainers, and with the media or the public, provided such disclosures follow responsible-disclosure norms. Those norms are intended to balance the need for rapid defensive action with caution around exposing technical details that could aid attackers.

The company also confirmed that the Pentagon is using Mythos to identify and remediate software vulnerabilities across the U.S. government, even as it works to complete a transition away from the AI company, according to the Defense Department's top technology official.


Contextual note: The changes reflect an adjustment from initial partner-requested confidentiality toward broader information circulation to enhance collective defense, while still emphasizing responsible disclosure practices.

Risks

  • Mythos' advanced coding capabilities create a heightened risk that discovered vulnerabilities and potential exploitation techniques could be sensitive if not handled under responsible-disclosure norms - affecting cybersecurity teams and software vendors.
  • Early confidentiality protections in partner agreements reflect concern that participants might be targeted after sharing sensitive findings, indicating ongoing operational security risks for companies and government entities involved.
  • The Pentagon's continued use of Mythos while completing a transition away from the company introduces uncertainty around continuity of access and support for government cybersecurity operations.

More from Stock Markets

Toronto market ends at fresh record as healthcare, financials and materials lead gains Jun 4, 2026 After-Hours Movers: Lululemon Dips on Guidance as Software and Data Names Show Mixed Reactions Jun 4, 2026 Lululemon Lowers Fiscal 2026 Revenue and EPS Guidance as U.S. Demand Softens Jun 4, 2026 Anthropic Places Engineers Inside NSA to Support Mythos AI for Offensive Cyber Tasks Jun 4, 2026 Trump Directs $700M Toward Coal Industry, Lifting Peabody Shares Jun 4, 2026