What’s the buzz?
Anthropic just announced that its new AI‑assistant, Claude Mythos Preview, has been used to discover over 10,000 high‑ or critical‑severity vulnerabilities since the launch of Project Glasswing. That’s a massive number for a tool that’s still in preview mode.
How does it work?
Claude Mythos is a specialised version of Anthropic’s Claude LLM, fine‑tuned to read code, spot insecure patterns and even suggest patches. Project Glasswing feeds the model with real‑world codebases – open‑source projects, bug‑bounty submissions and even internal code from partner firms. The AI then runs a series of static‑analysis prompts, looking for things like hard‑coded API keys, insecure deserialization, or missing authentication checks.
Numbers that matter
- 10,000+ high/critical bugs found in the first 6 months.
- Average time to flag a vulnerability: 2‑3 seconds per file.
- 90% of flagged issues were previously missed by traditional scanners.
Why Indian users should care
India’s tech ecosystem runs on a massive amount of open‑source code – from the back‑end of Paytm to the micro‑services that power Swiggy. Most mid‑size firms still rely on free scanners like OWASP‑ZAP or Snyk’s community tier, which can miss nuanced logic errors. Claude Mythos can plug that gap.
Think about a typical Indian e‑commerce startup. A single insecure endpoint can expose customer PII, leading to a UPI‑fraud nightmare. With Claude Mythos, the dev team gets instant feedback: “Hey, you’re exposing client_secret in a GET request – fix it now.” That kind of real‑time guardrail can save lakhs in breach remediation.
Getting your hands on it
Anthropic is currently offering the preview to selected partners via an API key. The pricing model is still under wraps, but early‑access users get a generous quota – 5 million tokens per month, which translates to roughly 1 GB of code analysis.
For Indian developers, the practical steps are:
- Visit the Anthropic website and request access to Project Glasswing.
- Integrate the Claude MySQL endpoint into your CI/CD pipeline (e.g., GitHub Actions).
- Set up a nightly job that sends new pull‑requests to the API and fails the build if a critical issue is reported.
What TamilTech thinks
We’re excited because this is the first time an LLM is being used at scale for pure vulnerability hunting. It’s not a silver bullet – you still need human review – but the speed is unprecedented. In Tamil Nadu’s startup scene, where budgets are tight, a tool that can catch 90% of missed bugs without buying an enterprise license is a game‑changer.
However, a word of caution: the model is only as good as the data it’s trained on. If you feed it proprietary code without proper licensing, you might run into IP issues. Also, the API calls are billed per token, so a huge monorepo could rack up costs quickly.
Looking ahead
Anthropic says Project Glasswing will soon support automated patch generation – the AI will not only point out the flaw but also write a PR with the fix. If that lands, we could see a future where the majority of low‑level security bugs are auto‑remediated.
For now, Indian security teams should start experimenting, share feedback with Anthropic, and prepare their CI pipelines to accept AI‑generated findings. The era of “human‑only code review” is fading, and Claude Mythos is leading the charge.




Comments (0)
Be the first to comment!