
HackerOne is expanding its work with advanced artificial intelligence by joining Project Glasswing, Anthropic’s controlled-access initiative for Claude Mythos 5.
The company plans to use the model to strengthen its internal security while studying how frontier AI can support broader exposure management. HackerOne will share findings from that work to help advance cyber defense across the industry.
The research will examine how Mythos performs beyond vulnerability discovery. HackerOne will assess whether the model can help confirm exploitability, rank security findings according to business impact, and create fixes that developers can apply within existing engineering processes.
“Attackers are already using frontier AI to find and weaponise vulnerabilities faster than defenders can respond. The only viable answer is for defenders to operate on better models, faster. HackerOne’s mission is to empower the world to build a safer internet. Anthropic’s is safer software at scale. Same goal, different vantage point. Project Glasswing lets us put the most capable model available to work on our infrastructure and share what we learn across the full CTEM workflow,” said Kara Sprague, Chief Executive Officer, HackerOne.
HackerOne’s participation reflects growing interest in using AI throughout the security lifecycle. The company is exploring whether advanced models can help security teams move more quickly from identifying a weakness to understanding its significance and preparing a practical response.
“Building more resilient software requires continuous innovation in how we identify, understand, and remediate risk,” said Nidhi Aggarwal, Chief Product Officer, HackerOne. “We are excited to use Claude Mythos to strengthen the security of our internal systems, explore how frontier AI can strengthen every stage of the CTEM workflow from discovery to remediation, and contribute insights that help the security industry move toward continuous cyber defense.”
The work is limited to HackerOne’s own infrastructure and solutions. Claude Mythos 5 will not be used in customer programs or in external-facing agentic applications.
Â
Join our LinkedIn group Information Security Community!











