BREAKING
🔥 Microsoft cuts 3,200 Xbox jobs, divests four studios in historic reset  |  Anthropic in early talks with Samsung to build custom 2nm AI chip  |  SpaceX joins Nasdaq-100 on July 7, unlocking wave of passive money  |  Qualcomm's Dragonfly C1000 lands Meta data center deal for 2028  |  Samsung rolls out ChatGPT Enterprise & Codex to workers worldwide  |  Meta bets ~$900M on Cred, Kunal Shah to lead WhatsApp globally  |  OpenAI latest model GPT-5.5  |  Starlink hits 10-Gigabit speeds in global beta  |  Nvidia's 'Rubin' GPUs Promise 4x Efficiency Jump  |  Generative UI frameworks end static web design  |  Hackers manipulate chatbot to steal 20,000 Instagram accounts  |  McDonald's tests Google-backed AI drive-thrus
Anthropic Hits $965B Valuation as Its Project Glasswing Finds Over 10,000 Vulnerabilities Cybersecurity
May 30, 2026 6 min read

Anthropic Hits $965B Valuation as Its Project Glasswing Finds Over 10,000 Vulnerabilities

N
Nexalytics Tech Editorial Team Reporting & analysis by our staff

Anthropic announced on May 28, 2026, that it had raised $65 billion in Series H funding, valuing the company at $965 billion post-money. The round was led by Altimeter Capital, Dragoneer, Greenoaks, and Sequoia Capital, and co-led by Capital Group, Coatue, D1 Capital Partners, GIC, ICONIQ, and XN, according to Anthropic's own announcement. The company said its run-rate revenue crossed $47 billion earlier that month, up from $14 billion when it closed its previous funding round (Series G) in February 2026 — a pace of growth that has made Anthropic, maker of the Claude AI models, one of the most highly valued private companies in the world.

What Project Glasswing actually is

Four days before the funding announcement, on May 22, 2026, Anthropic published its first progress update on Project Glasswing, a collaborative cybersecurity initiative it launched about a month earlier. The idea: give roughly 50 partner organizations — including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, and the Linux Foundation — access to a specialized, security-focused version of Claude called Mythos Preview, so defenders can find and patch vulnerabilities in critical software before less carefully safeguarded AI models can be used to find and exploit the same flaws first.

According to Anthropic's own account, Project Glasswing partners collectively found more than 10,000 high- or critical-severity vulnerabilities in the roughly one month since launch, with several partners reporting their rate of bug discovery increased more than tenfold. Cloudflare, one of the named partners, reported finding 2,000 bugs across its critical-path systems, 400 of them high- or critical-severity, using access granted through Glasswing. Mozilla reported it found and fixed 271 vulnerabilities in Firefox while testing Mythos Preview — more than ten times what it found in the previous Firefox release using Claude Opus 4.6. Separately, Anthropic has used Mythos Preview to scan more than 1,000 open-source projects on its own initiative, estimating it found 6,202 high- or critical-severity vulnerabilities among 23,019 total issues; of those it has had independently verified so far, roughly 90% proved to be genuine, and 62% were confirmed high- or critical-severity.

The vulnerabilities that got public attention

Anthropic's own Project Glasswing page details three specific findings it says Mythos Preview identified largely autonomously. It found a 27-year-old vulnerability in OpenBSD — an operating system with a reputation as one of the most security-hardened in the world, commonly used to run firewalls — that allowed an attacker to remotely crash any machine running it just by connecting. It also found a 16-year-old vulnerability in FFmpeg, the widely used video encoding and decoding library, sitting in a line of code that automated testing tools had reportedly executed roughly five million times without ever catching the flaw. And it autonomously chained together several Linux kernel vulnerabilities to escalate from ordinary user access to full control of a machine. Anthropic says all three have since been reported to the relevant maintainers and patched. Separately, security-tracking site VulnCheck has catalogued at least 40 CVEs (published vulnerability records) directly credited to Anthropic researchers and Claude in 2026, spanning Mozilla Firefox, FreeBSD, wolfSSL, F5's NGINX Plus, and the Bouncy Castle cryptography library.

The bottleneck has moved from finding bugs to fixing them

Anthropic's own framing of the update is the most important part: for years, cybersecurity progress was limited mainly by how fast defenders could find vulnerabilities. Now, the company argues, the constraint has shifted to how fast humans can verify, disclose, and patch the volume of vulnerabilities that AI models can surface. Anthropic said a typical high- or critical-severity bug found by Mythos Preview takes about two weeks to patch, and that several open-source maintainers have actually asked Anthropic to slow its disclosure pace because they lack the capacity to handle the incoming reports — on top of an existing flood of low-quality, AI-generated bug submissions unrelated to Glasswing. As one concrete example, Anthropic says Mythos Preview helped one partner bank detect and stop a fraudulent $1.5 million wire transfer tied to a compromised customer account.

Mythos Preview itself has not been released publicly. Anthropic has said it is withholding general release until it develops stronger safeguards, since the same capabilities that let Mythos Preview find zero-days for defenders could, in the wrong hands or without those safeguards, make it dramatically easier for attackers to do the same thing at scale.

  • $65B Series H round, $965B post-money valuation, announced May 28, 2026
  • Run-rate revenue crossed $47B in May 2026, up from $14B in February 2026
  • Project Glasswing: ~50 partners, 10,000+ high/critical vulnerabilities found in ~1 month
  • Cloudflare: 2,000 bugs found (400 high/critical); Mozilla: 271 Firefox vulnerabilities fixed
  • Mythos Preview remains unreleased publicly, pending stronger misuse safeguards

Our take

The eye-catching valuation number and the vulnerability-discovery numbers are two separate stories that happened to land in the same week, and Anthropic's own materials back up both. The more consequential one for anyone running software is the patching bottleneck: an AI model that can find thousands of critical bugs a month is only a net security win if the people responsible for shipping fixes can keep pace, and Anthropic's own data shows that gap is real and, for now, widening.

What to watch next

Watch Anthropic's ongoing Glasswing disclosure dashboard for how many of the reported vulnerabilities actually get patched over the following months, whether other AI labs follow with similar security-research access programs of their own, and whether Anthropic or a competitor moves to release a Mythos-class model publicly once new safeguards are in place — a step Anthropic has said it intends to take but has not yet scheduled.

Share: