Picture a security guard who can scan millions of lines of code in a matter of weeks, catching every unlocked door and every crack in a digital wall. That’s essentially what Anthropic built with Project Glasswing: an initiative where its Claude Mythos Preview model combed through more than 1,000 open source projects used daily by businesses around the world, including several that your SMB is probably running right now.
In under a month, the project flagged more than 10,000 high or critical severity vulnerabilities in software that runs critical systems globally. Behind that striking number is a very real story for SMBs in Trois-Rivières, the Mauricie region, and across Quebec: the digital tools that keep your operations running carry risks that are often invisible, and AI is now changing how those risks get found and fixed.
Quick answer: Anthropic and about fifty partners (including Microsoft, Google, Apple, Cisco, and AWS) used Claude Mythos to find more than 10,000 critical security flaws in widely used open source software. Hundreds of these flaws are already being fixed, directly reducing risk for the businesses and organizations that rely on this software, including many Quebec SMBs.
1. What is Project Glasswing?
Project Glasswing is an Anthropic initiative with a clear goal: secure the world’s most critical software before bad actors can use AI to attack it. The name references the glasswing butterfly (Greta oto), whose transparent wings capture the kind of visibility AI can bring to environments that were once opaque to human security teams.
The program brings together about fifty major partners, including Amazon Web Services (AWS), Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Together, these organizations gave Claude Mythos Preview access to more than 1,000 open source projects to scan for security flaws. Work that would have taken teams of human specialists years was done in a matter of weeks.
The name isn’t a coincidence: the glasswing butterfly (Greta oto) has nearly transparent wings, making it hard for predators to spot. Anthropic drew on that image to describe AI’s ability to reveal what was previously hidden across millions of lines of code.

2. What the AI actually found
The data Anthropic published in its initial project update is striking. Claude Mythos Preview analyzed more than 1,000 open source projects and flagged 6,202 candidate vulnerabilities of high or critical severity in the first month. After review by human experts, 1,726 turned out to be genuine, exploitable flaws, with 1,094 confirmed as high or critical severity.
Counting subsequent updates, the project has surpassed 10,000 high or critical severity vulnerabilities found. For context: a single unpatched critical vulnerability can be enough for an attacker to take over a server, steal confidential data, or launch a ransomware attack against an entire organization.
Here’s where things stand on fixing these flaws, according to Anthropic’s official figures:
- More than 530 high or critical severity flaws have been disclosed to the maintainers of the affected software
- 75 have been fixed and made public
- 65 public security advisories have been issued
Anthropic’s own assessment is candid: the bottleneck is no longer detection, it’s the human capacity to process, verify, and fix these flaws. AI solved one problem and created another, pushing security teams to rethink how they work from the ground up.
3. Why open source software matters to your SMB
If “open source” sounds like something far removed from your day-to-day as an SMB, think again. A significant share of the digital tools you use every day rely on open source components, even if you don’t realize it:
- Your website (WordPress runs heavily on open source components, as do the underlying Apache or Nginx servers)
- The databases storing your customer and financial data (MySQL, PostgreSQL)
- The email and file-processing libraries built into commercial software
- The collaboration and management tools your team uses daily
- Components used by popular platforms like Microsoft 365 or Salesforce
One example is still fresh in the minds of IT teams: the Log4Shell flaw from December 2021, a vulnerability in an open source Java library used by millions of systems worldwide. Thousands of organizations, including Quebec SMBs, found themselves exposed overnight through no fault of their own. Project Glasswing is precisely aimed at avoiding that kind of scenario, by finding these flaws before attackers do.

4. AI is shifting the balance of power in cybersecurity
For years, cybercriminals held a structural advantage: they only needed to find one flaw to get in, while defenders had to watch an entire perimeter. AI is now rebalancing that dynamic, at least in part.
Claude Mythos Preview didn’t just find flaws, it automated a chunk of the verification work that used to be entirely manual, freeing up human experts to focus on fixing issues rather than hunting for them. That’s the shift the industry has been waiting for from generative AI applied to cybersecurity.
For Quebec SMBs, the benefits are tangible:
- The updates you install become more reliable: flaws identified through Glasswing end up in the patches you apply
- The overall attack surface shrinks: fewer known, unpatched vulnerabilities in the software you use every day
- The risk window narrows: what used to take years to detect can now be handled in weeks
- Industry collaboration deepens: when Microsoft, Google, and Apple work together on securing shared software, everyone benefits
That said, this progress doesn’t replace vigilance at the individual business level. Misconfigurations, weak passwords, uncontrolled access, and gaps in employee training remain major attack vectors for SMBs, regardless of how secure the underlying software is.

5. What your SMB should do right now
The good news is that SMBs don’t need to understand the technical details of Project Glasswing to benefit from it. A few practical habits, though, will help you get the most protection:
- Keep your software up to date: patches coming out of projects like Glasswing arrive through normal updates. Applying them quickly is your first line of defense.
- Take stock of your tools: do you know exactly what software is running on your servers and workstations? An IT partner can help you map your environment and spot components that haven’t been updated.
- Don’t underestimate your open source components: if your website or applications run on WordPress or other open source components, make sure they’re updated regularly, plugins included.
- Take a proactive approach: waiting for a cyberattack to happen always costs more than preventing one. A periodic security audit helps catch blind spots before they get exploited.
For SMBs in Trois-Rivières and the Mauricie region without an in-house IT department, a trusted partner can handle these updates and ongoing monitoring for you. That’s what’s known as proactive systems management, and it’s exactly what’s covered by OKTO Solutions’ IT services, built around the realities and budgets of regional SMBs.
Frequently Asked Questions
What is a critical severity software vulnerability?
A critical vulnerability is a flaw that lets an attacker execute code remotely, bypass authentication, or compromise a system without any user interaction. These flaws are the most dangerous because bots can exploit them automatically, often before an administrator even knows they exist. That’s why how fast a flaw gets fixed matters just as much as finding it in the first place.
Microsoft is one of the partners: does that protect Microsoft 365 users?
Indirectly, yes. Microsoft contributes to Project Glasswing and regularly releases security updates for its products, some of which fix vulnerabilities in open source components built into its software. Applying Windows and Microsoft 365 updates as soon as they’re released is still the best way to actually benefit from this work.
Can AI also be used by cybercriminals to find flaws?
Yes, and experts are open about that reality. AI tools are available to bad actors looking to automate vulnerability hunting too. That’s actually one of the motivations behind Glasswing: fix known flaws before attackers equipped with AI can exploit them at scale. SMBs benefit from working with IT partners who track these developments closely and adjust their security posture accordingly.
A step toward safer digital infrastructure for every business
Project Glasswing marks a turning point in global cybersecurity: for the first time, AI is being deployed at scale to proactively secure the software our digital economy runs on. SMBs in Trois-Rivières, the Mauricie region, and across Quebec don’t have to navigate this constantly shifting landscape alone. If you want a real assessment of your security posture, or simply want to know how to keep your systems up to date effectively, the OKTO Solutions team is available through our services page or directly through our contact form to help you build an approach that fits your reality.