Cybersecurity

Horizon3.ai Joins Anthropic’s Glasswing Vulnerability Hunt

mm
Add Unite.AI to your preferred sources on Google

Horizon3.ai has joined Anthropic’s Project Glasswing, the cyberdefense program that gives a vetted group of organizations access to Claude Mythos — a frontier model Anthropic keeps out of public release precisely because it is good at both finding and exploiting software vulnerabilities. The move, announced on July 15, 2026, adds an offensive-security specialist to a roster that until now leaned heavily on hyperscalers and large security vendors. Anthropic’s goal is to get its strongest vulnerability-hunting model into defenders’ hands before the same class of capability spreads to attackers.

Anthropic launched the program on April 7, 2026 with roughly 50 partners — among them Amazon (AMZN ) Web Services, Cisco, CrowdStrike (CRWD ), Google, JPMorganChase, Microsoft (MSFT ), Nvidia (NVDA ) and Palo Alto Networks (PANW ) — and later extended it to about 150 more organizations across more than 15 countries, reaching into power, water, healthcare and communications. Members use Mythos for defensive work: scanning their own code, writing patches, and vetting software before release. Anthropic has said it is committing up to $100 million in usage credits and $4 million in donations to open-source security groups to support the effort.

What Horizon3 actually brings

Horizon3.ai sells NodeZero, an autonomous penetration-testing product, and its argument for joining is the “attacker’s perspective” — that defenders learn most from people who understand how systems actually get broken into. That framing comes from a company promoting its own participation. But Horizon3’s recent record is verifiable in a way most vendor pitches are not.

This year its researchers surfaced two flaws that attackers went on to use against real targets. One was a remote-code-execution bug in Apache ActiveMQ (CVE-2026-34197), a widely deployed open-source message broker; the US cybersecurity agency CISA added it to its catalog of actively exploited vulnerabilities in April 2026 and gave federal agencies two weeks to patch. The other was a critical authentication bypass in SimpleHelp (CVE-2026-48558), a remote-management tool popular with managed-service providers, which Horizon3 says its autonomous vulnerability-research pipeline flagged within hours of ingesting the code. That flaw carried a maximum severity rating, was used to deploy credential-stealing malware, and reached CISA’s catalog in June 2026.

The bottleneck no one has cleared

Whether one more exploit-finding shop changes the picture depends on a problem Anthropic itself has flagged: discovery is no longer the constraint. Glasswing partners have reported more than 10,000 high- or critical-severity flaws since April, and Anthropic says the real bottleneck is now triaging, disclosing and patching them faster than attackers can weaponize them. Its own numbers show the scale of that problem: when Anthropic ran Mythos across more than 1,000 open-source projects, the model flagged over 23,000 potential vulnerabilities, and of a sample independently reviewed, more than 90% held up as valid. Independent researchers have described the same imbalance — AI is pushing the cost of finding and exploiting bugs down sharply while the human work of fixing them stays expensive.

That is where Horizon3’s angle is more than marketing. NodeZero is built around prioritization; the company’s premise is that most flaws are noise and the value lies in spotting the few attackers will actually use. A model that surfaces tens of thousands of candidate bugs makes that triage problem harder, not easier, unless someone can rank them by real-world exploitability.

The dual-use tension

There is an unresolved tension in giving a restricted, offense-capable model to a company whose business is offense. Anthropic keeps Mythos out of general release because, by its own account, the model can outperform all but the most skilled humans at finding and exploiting vulnerabilities, and it says new partners must meet unspecified security requirements before gaining access. Anthropic is not alone in turning offensive AI toward defense — OpenAI recently built an in-house AI attacker to harden its own models — but Mythos sits at the sharp end of that trend.

Horizon3’s chief attack engineer, Zach Hanley, said the firm had “already identified impactful vulnerabilities” in its first few days with Mythos — a claim it has not yet backed up, saying it intends to detail the findings publicly.

For now, the verifiable part of this story is Horizon3’s existing exploited-in-the-wild findings, not what Mythos will produce next. Chief executive Snehal Antani framed the stakes in terms that cut against the program’s own premise: the advantage, he said, “won’t be defined by who has access to the most powerful AI,” but by who can combine it with security expertise and operational discipline to reduce real-world risk. On the evidence so far, the harder half of that equation — turning a flood of AI-found bugs into deployed patches — is the one still waiting for a breakthrough.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.
With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.
Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.