SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Checkmarx joins Anthropic's Project Glasswing on defence

Checkmarx joins Anthropic's Project Glasswing on defence

Mon, 7th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Checkmarx has joined Anthropic's Project Glasswing, a programme that gives selected security organisations access to Mythos for defensive cybersecurity work.

Under the arrangement, Checkmarx will use Claude Mythos 5 to strengthen its internal vulnerability detection and plans to share its findings with the wider security community. As part of the initiative, it will focus on securing its own code and systems.

The move places Checkmarx among a limited group of security companies working with Anthropic's model in a defensive setting. It reflects growing interest in how advanced AI systems can help identify software risks before attackers exploit them.

Research cited by Checkmarx points to mounting pressure on software security teams. A J.P. Morgan analysis found that about 80% of exploitations now happen on or before the day a vulnerability becomes public, highlighting the shrinking window for defenders to respond.

Frontier AI models are beginning to uncover categories of risk that have remained hidden in code bases for years, according to Checkmarx. That could mark a shift for application security teams, which have often relied on scanning cycles and remediation processes that struggle to keep pace with modern software development.

Closing the gap

Through Project Glasswing, Checkmarx aims to help close that gap by finding and fixing risks before exploitation. It also plans to share with the broader industry what that process requires.

For Checkmarx, the effort builds on its existing application security business and its research division, Checkmarx Zero. The unit has focused on threat intelligence alongside product development to reduce cyber risk.

Sandeep Johri, Chief Executive Officer of Checkmarx, described the project as part of a wider effort to adapt to the speed and scale of the threat environment.

"We've watched frontier models surface risk that's gone undetected for years, faster than most organizations can keep up. Project Glasswing is one part of how we're working to close that gap and a chance to share what we learn so the rest of the industry can close it too," Johri said.

He also outlined how Checkmarx sees the role of AI in its defensive work.

"We're proud to bring our expertise to the effort and to put frontier AI to work defending the software the world runs on," Johri said.

Industry pressure

The announcement comes as software developers and security teams face pressure from both faster release cycles and the spread of AI-generated code. Those trends have increased the volume of code organisations must review, while also raising concerns that weaknesses can persist unnoticed until public disclosure or active exploitation.

Application security providers have been trying to adapt by combining automation, threat intelligence and more targeted remediation workflows. Access to large AI models designed for defensive use may give some vendors another way to detect patterns and flaws that are difficult to spot through conventional tools alone.

Checkmarx intends to publish findings and best practices from the work, including how AI is affecting application security workflows, triage and disclosure. That suggests it is positioning the Glasswing project not only as an internal security exercise, but also as a contribution to the broader industry discussion about how AI should be applied in software defence.

Checkmarx scans trillions of lines of code each year, giving it a large base of software data and customer exposure from which to observe vulnerability patterns and remediation practices.

As security groups test advanced AI in defensive environments, a central question will be whether such systems can consistently reduce the time needed to identify meaningful risks without flooding engineers with noise. Checkmarx said its work in Project Glasswing will focus on that challenge by detecting vulnerabilities in its own environment and publishing findings and best practices for the security community.