Skip to content

Project Glasswing and Mythos Preview

By Nick Charles | Head of Professional Services at TEAM Cloud

 

4 Mins Read

Something significant happened that every organisation running workloads in the cloud should know about.

Anthropic launched Project Glasswing, a controlled initiative giving a select group of critical infrastructure organisations exclusive access to Claude Mythos Preview, a frontier AI model Anthropic considers too capable to release publicly. Since launch, Anthropic and its approximately 50 partners have used Claude Mythos Preview to find more than ten thousand high or critical severity vulnerabilities across the most systemically important software in the world. Several partners have reported that their rate of bug finding has increased by more than a factor of ten.

TEAM Cloud_Blog Images_Mythos & Glasswing_2.0

 

Oracle is one of those organisations.

Oracle has access to leading frontier AI models, including Anthropic's Claude Mythos Preview, and is extending its capabilities with these models to improve how quickly and effectively vulnerabilities are identified. This is applied across Oracle-developed software and services and the open-source components built into Oracle products. Oracle's own Integrated Cyber Centre blog notes that the result is stronger code, earlier identification of risk and mitigations, and better protection for Oracle and its customers.

The scale of the improvement is striking. Oracle is finding and fixing vulnerabilities across its products and cloud multiple times faster than before. Oracle's Field CISO has written publicly about what this shift means, noting that AI systems that can reason across large codebases, identify subtle weaknesses, validate exploitability, and chain multiple vulnerabilities into working attack paths completely change the game for security teams. 

What does this mean for TEAM Cloud customers?

TEAM Cloud operates the Dedicated Realm on Oracle Cloud Infrastructure. As a Dedicated Realm, TEAM Cloud inherits Oracle's core OCI security posture - the same underlying platform, the same security engineering, and critically, the same patch pipelines as Oracle's commercial OCI regions.

That matters right now more than ever.

Oracle released its April 2026 Critical Patch Update - the second quarterly update of 2026, containing fixes for 241 unique CVEs across 481 security updates spanning 28 Oracle product families. But the bigger news is what came immediately after. Oracle has introduced a new Critical Security Patch Update programme, providing targeted, high-priority security fixes in a smaller, more focused format on a monthly cadence, complementing the existing quarterly CPUs.

This is a direct consequence of the AI-driven vulnerability discovery era Glasswing represents. Progress on software security used to be limited by how quickly vulnerabilities could be found. Now it's limited by how quickly they can be verified, disclosed, and patched. Oracle has responded to this new reality by moving to a higher-frequency patching model and as an OCI Dedicated Realm, TEAM Cloud customers benefit from that improved cadence automatically.

For Oracle managed cloud services, vulnerabilities are identified and addressed continuously Oracle monitors its infrastructure, platform services, and SaaS applications and applies fixes as they become available, reducing operational burden and helping keep systems up to date.

The bottom line for our customers and partners:

  • Oracle is an active Project Glasswing participant, using the world's most capable security AI to harden the OCI platform

  • TEAM Cloud's Dedicated Realm inherits OCI's security posture and patch pipelines

  • Oracle now ships security fixes monthly (not just quarterly), meaning vulnerabilities are remediated faster than ever before

  • Anthropic has committed up to $100M in usage credits and will share what Glasswing partners learn so the whole industry benefits

For organisations choosing a sovereign cloud in New Zealand, this is a meaningful differentiator. The security rigour being applied to OCI at the global level flows directly into the infrastructure your workloads run on.

A note on Mythos Preview vs. Mythos 5

You may have seen recent news about Anthropic's newer Mythos 5 model being suspended. It's worth clarifying that this is a separate and distinct model from the Mythos Preview used in Project Glasswing. On 12 June 2026, the US government issued an export control directive suspending all access to Fable 5 and Mythos 5 for any foreign national - the net effect being that access was disabled for all customers to ensure compliance. Access to all other Anthropic models is not affected. The Glasswing programme and Oracle's participation in it are based on Mythos Preview, which is unaffected. We'll continue to monitor any downstream implications for the Glasswing initiative.

References