Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Project Glasswing: AI Found 10,000 Critical Flaws in the Software You Use Daily

Portrait of Antonio Pazzi, president of OKTO Solutions

By ·

President of OKTO Solutions · 7 minute read

Picture a security guard able to read millions of lines of code in a few weeks and spot every badly locked door, every crack in a digital wall. That is exactly what Anthropic set up with Project Glasswing: an unprecedented initiative in which its AI model Claude Mythos Preview combed through more than 1,000 open source software projects used every day by companies around the world, several of which your business is very likely running right now.

In less than a month, the project turned up more than 10,000 high or critical severity vulnerabilities in software that matters on a global scale. Behind that striking number sits a concrete reality for small businesses in Trois-Rivières, the Mauricie and the rest of Quebec: the digital tools that keep your operations running are exposed to risks that are often invisible, and AI is now changing how those risks get found and fixed.

Quick answer: Anthropic and roughly fifty partners (Microsoft, Google, Apple, Cisco and AWS, among others) used Claude Mythos to find more than 10,000 critical security flaws in widely deployed open source software. Hundreds of those flaws are being fixed, which directly lowers the risk for the companies and organizations that use this software, including many Quebec small businesses.

1. What is Project Glasswing?

Project Glasswing is an initiative launched by Anthropic with a clear goal: secure the planet’s most critical software before malicious actors can use AI to attack it. The name refers to the Greta oto butterfly, whose transparent wings stand in for the visibility AI can bring to environments that were opaque to human security teams until now.

The program brings together some fifty leading partners, including Amazon Web Services (AWS), Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. Together, these organizations gave Claude Mythos Preview access to more than 1,000 open source projects to analyze them for security flaws. What would have taken teams of human specialists years was done in a few weeks.

The name was not chosen at random: the glasswing butterfly (Greta oto) has nearly transparent wings, which makes it hard for predators to spot. Anthropic borrows the image to describe the AI’s ability to make visible what used to be hidden inside millions of lines of code.

2. What the AI actually found

The data Anthropic published in the project’s initial update is striking. Claude Mythos Preview analyzed more than 1,000 open source projects and flagged 6,202 vulnerability candidates of high or critical severity in the first month. After validation by human experts, 1,726 turned out to be real exploitable flaws, of which 1,094 were confirmed as high or critical severity.

Counting the later updates, the project passed 10,000 vulnerabilities of high or critical severity found. For context: a single unpatched critical vulnerability can be enough to let an attacker take control of a server, steal confidential data or launch a ransomware attack against an entire organization.

Here is where the remediation of those flaws stands, according to Anthropic’s official figures:

  • More than 530 high or critical severity flaws have been disclosed to the maintainers of the software concerned
  • 75 have been fixed and made public
  • 65 public security advisories have been issued

Anthropic’s read on this is clear-eyed: the bottleneck is no longer detection, it is human capacity to triage, verify and fix these flaws. The AI created a new problem by solving the old one, which is pushing security teams to rethink the way they work from top to bottom.

3. Why open source software concerns your business

If the term "open source" sounds far removed from your reality as a small business, think again. A sizeable share of the digital tools used every day rests on open source components, even if you do not know it:

  • Your website (WordPress leans heavily on open source components, as do the underlying Apache or Nginx servers)
  • The databases that store your client and financial information (MySQL, PostgreSQL)
  • The email and file handling libraries built into commercial software
  • The collaboration and management tools your teams use daily
  • Components used by popular platforms such as Microsoft 365 or Salesforce

One example is still fresh in the memory of IT teams: the Log4Shell flaw of December 2021, a vulnerability in an open source Java library used by millions of systems worldwide. Thousands of organizations, Quebec small businesses among them, found themselves exposed overnight without having done anything wrong. Project Glasswing exists precisely to avoid that kind of scenario, by finding these flaws before the attackers do.

IT threat monitoring, OKTO Solutions Trois-Rivières

4. AI is shifting the balance of power in cybersecurity

For years, cybercriminals held a structural advantage: they only had to find one flaw to get in, while defence teams had to watch the whole perimeter. AI is starting to even out that dynamic, at least in part.

Claude Mythos Preview did not only find flaws: it automated part of the verification work that used to be entirely manual, freeing human experts to focus on fixing rather than finding. That is the shift the industry had been waiting for from generative AI applied to IT security.

For Quebec small businesses, the benefits are concrete:

  • The updates you apply become more reliable: the flaws Glasswing identifies end up in the patches you install
  • The overall attack surface shrinks: fewer known and unpatched vulnerabilities in everyday software
  • The window of risk narrows: what used to take years to detect can now be handled in weeks
  • Industry collaboration deepens: when Microsoft, Google and Apple work together on the security of shared software, everybody gains

That said, this improvement does not replace vigilance inside each company. Bad configurations, weak passwords, uncontrolled access and a lack of employee training remain major attack routes for small businesses, no matter what state the underlying software is in.

Building a strategic IT security plan for a small business in Quebec

5. What your business should do right now

The good news is that small businesses do not need to understand the technical details of Project Glasswing to benefit from it. A few concrete practices will get you the most protection:

  • Keep your software up to date: the fixes that come out of projects like Glasswing arrive through normal updates. Applying them quickly is your first line of defence.
  • Take an inventory of your tools: do you know exactly which software runs on your servers and workstations? An IT partner can help you map your environment and spot the components that are not being updated.
  • Do not underestimate your open source components: if your website or your applications rest on WordPress or other open source components, make sure they are updated regularly, plugins included.
  • Take a proactive approach: waiting for a cyberattack to happen always costs more than preventing one. A periodic security audit lets you find the blind spots before they are exploited.

For small businesses in Trois-Rivières and the Mauricie that have no in-house IT department, a trusted partner can handle these updates and this monitoring on an ongoing basis. That is what proactive systems management means, and it is exactly what the IT services from OKTO Solutions cover, sized for the realities and budgets of regional businesses.

Frequently asked questions

What is a critical severity vulnerability in software?

A critical vulnerability is a flaw that lets an attacker run code remotely, bypass authentication or compromise a system with no user interaction. These flaws are the most dangerous because bots can exploit them automatically before an administrator even knows they exist. That is why the time it takes to fix them counts as much as finding them.

Microsoft is one of the partners: does that protect Microsoft 365 users?

Indirectly, yes. Microsoft contributes to Project Glasswing and regularly publishes security updates for its products, some of which fix vulnerabilities in open source components built into its software. Applying Windows and Microsoft 365 updates as soon as they are released remains the best way to benefit from this work in practice.

Can cybercriminals also use AI to find flaws?

Yes, and experts acknowledge it openly. AI tools are available to malicious actors for automating the hunt for vulnerabilities. That is one of the reasons behind Glasswing: fix the known flaws before AI-equipped attackers exploit them at scale. Small businesses have every interest in working with IT partners who follow these developments closely and adjust their security posture accordingly.

A step toward safer digital infrastructure for every business

Project Glasswing marks a turning point in global cybersecurity: for the first time, AI is being deployed at scale to proactively secure the software our digital economy rests on. Small businesses in Trois-Rivières, the Mauricie and across Quebec do not have to find their way through this fast-moving environment alone. If you want a concrete read on your security posture, or simply want to know how to keep your systems up to date efficiently, the OKTO Solutions team is available through our services page or directly through our contact form to help you build an approach that fits your reality.

Reading about AI is one thing. Connecting it to your own data is another: artificial intelligence in business, custom AI application development and our IT services in Quebec City.

A question on this subject, for your own company?

An article explains the principle. A twenty minute call tells you what it changes at your place, with your systems and your constraints.