Project Glasswing is an Anthropic-led coalition (launched April 2026 alongside Claude Mythos, a frontier vulnerability-finding model Anthropic chose not to release publicly) that gives vetted organizations access to the model for defensive security work — finding and patching flaws in critical software before attackers can. Self-disclosed participants now span Oxide Computer (Mythos 5 pointed at its own firmware-to-network stack), Verizon and AT&T in telecom, TrendAI (Trend Micro), healthcare vendor Epic, and AWS, Apple, Nvidia and Google, with Anthropic committing up to $100M in usage credits and $4M to open-source security organizations; on Oct 6, 2026 Anthropic folded Glasswing members into an expanded three-tier Cyber Verification Program with open applications and reported ≥129K partner-found verified vulnerabilities for Apr–Jul 2026 — self-reported, explicitly unaudited, and met with community skepticism. The snippets are thin and partly conflicting on scope: one low-quality piece (placeholder citations) reframes Glasswing as securing AI datacenter infrastructure itself, while every first-party account consistently describes defensive vulnerability research on participants' own software. None of the supplied material shows the standards-for-securing-AI-agents or independent governance layer the hypothesis predicts — Glasswing is so far substantiated as a scaling, Anthropic-controlled model-access and verification regime, not a standards body.
| source | object | author | score | comments |
| 🟧 hn | Oxide Joins Anthropic's Project Glasswing | ErenayDev | 13 | 1 |
| 🟧 echo.blog | The original announcement is Oxide’s own post: “Today we’re joining Anthropic’s Project Glasswing… As part of this collaboration, Oxide is a | Oxide Computer Company | — | — |
| 🟧 hn | Oxide Joins Anthropic's Project Glasswing | lwhsiao | 16 | 4 |
| 🟧 hn | Oxide Joins Anthropic's Project Glasswing | tosh | 4 | 1 |
| 🟧 hn | Building standards for the next phase of AI | gmays | 6 | 2 |
| 🟠 reddit | NVIDIA shipped OpenShell, an open source sandbox that gives local and open agents real runtime limits instead of prompt rules. Over 100 firms joined the safety stack. OpenAI did not. LocalLLaMA | InternationalGap3698 | 810 | 161 |
| 🟠 reddit | Nvidia wants to put a watchdog chip next to every AI agent, and Anthropic and SpaceXAI are on board singularity | ross2000 | 202 | 82 |
| 🟠 reddit | The Internet Is Safer: Project Glasswing Found 135K Verified Vulnerabilities, With at Least 9,333 Already Patched singularity | ResultBackground2450 | 179 | 18 |
| 🟧 hn ⭐ | Expanding the Cyber Verification ProgramRetrieved article excerptOpen article · Retrieved 2026-10-06T20:42:30.249072+00:00 Announcements
# Expanding the Cyber Verification Program
Oct 6, 2026
Expanding the Cyber Verification Program
We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. Interested customers can [apply here](https://portal.anthropic.com/programs/cvp).
Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it. For this reason, our generally available models, such as [Claude Opus 5.5](https://www.anthropic.com/claude-opus-5-5), [Claude Fable 5.1](https://www.anthropic.com/claude-fable-and-mythos-5-1), and [Claude Sonnet 5.5](https://www.anthropic.com/claude-sonnet-5-5), have conservative cyber safeguards that block most cyber work. This is intended to limit the harmful activities malicious actors can carry out using our models, while we continue to work to reduce false positives for secure coding.
But defenders also need access to the best tools and most powerful capabilities to secure their systems. For the past six months, we’ve enabled trusted access through two programs: [Project Glasswing](https://www.anthropic.com/glasswing) and the [CVP](https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet). The former gave a group of organizations securing the most critical software access to Claude Mythos; the latter gave vetted security teams access to reduced safeguards on Claude Opus and Claude Sonnet models.
Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems.
### New access tiers
The updated access tiers make specific model capabilities available to security professionals based on the scope of their cyber work. Each has different verification requirements and security controls.
**Defense Access** is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Examples of qualifying organizations include security teams at companies, nonprofits, universities, and government bodies who are defending systems they own or maintain; operators of critical infrastructure of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities.
We expect many organizations conducting defensive cybersecurity work to qualify for this tier. We aim to respond to applications within a few days.
**Red Team Access** adds authorized penetration testing and red-teaming to the defensive uses above. Examples of qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Organizations in this tier can only perform adversarial testing against systems they are authorized to test, including IT systems in critical industries. Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems.
Given the increased eligibility requirements and security controls, we expect applications in this tier to take a few weeks to review. Qualifying organizations will be enrolled in the Defense Accesstier while we review their Red Team Access applications. Currently, this tier is for organizations only; individual researchers are not eligible.
**Specialized Access**, which has the fewest cyber blocks, is reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.
For this tier, we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transition to this tier and do not require reapproval for current models.
Our generally available models can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts.
Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse. Once [Enterprise Frontier Safeguards](https://www.anthropic.com/news/enterprise-frontier-safeguards) (EFS)—a new solution that combines the privacy of zero data retention with robust safeguards—is available later this fall, eligible organizations will be able to store data in cloud infrastructure they control. Until EFS is available, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention. To register interest in EFS, [fill out this form](https://claude.com/form/enterprise-frontier-safeguards).
Below, we share an overview of what’s available at each CVP access level, as well as requirements for security and privacy controls:
Overview of the Cyber Verification Program tiers.
### Testing the efficacy of our tiers
To assess the efficacy of our CVP protections, we ran Claude Opus 5.5 through CyScenarioBench—an evaluation that measures whether models can plan and execute multi-stage cyber operations under realistic constraints—with safeguards tuned for our different CVP tiers. Because this evaluation involves complex, interactive offensive scenarios, we would expect Claude to experience significant blocks both on the generally available model and in the Defense Access tier, while experiencing no blocks in the Red Team Access and Specialized Access tiers.
Across five attempts at each of the 10 CyScenarioBench challenges in each access tier, we found that:
- Without CVP access, every task was blocked on the first prompt;
- In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded; and
- In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks—effectively equivalent to the model’s 67.6% success rate on this evaluation with no safeguards applied (representative of Specialized Access).
These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing. We will continue to refine our tier-based classifiers over time.
On CyScenarioBench, our safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on Claude Opus 5.5 did not block any tasks, and completed 34 of 50—the same completion rate as when no safeguards are applied.
## Giving defenders the advantage
Through Project Glasswing, we found that Claude Mythos models significantly increased the rate at which organizations were able to identify vulnerabilities in their systems. Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. And through our own open-source scanning efforts, we found an additional 5,500 verified software vulnerabilities between April and October 2026. Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity. This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher.
When asked how long it would have taken them to find the same number of vulnerabilities without Claude Mythos models, several partners told us that the models had increased their rate of vulnerability finding by months or even years. Read more from our partners at [Booz Allen and Comcast](https://claude.com/blog/how-comcast-booz-allen-use-claude-mythos-to-secure-their-codebases) about their experience.
These results represent a lower bound on the program’s impact on third-party code, as they’re based on partial data from 33 partner reports and Anthropic’s open-source partnerships. Data limitations include that organizations took different approaches to triaging, and fewer than 50% of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.
The changes we’re making to our Cyber Verification Program today are intended to extend the impact of Project Glasswing to a much larger number of cyber defenders. We’re also continuing our efforts to help secure open-source software and critical infrastructure. In the coming weeks, we’ll share more about this work and what we’ve learned as we continue to work to give defenders a permanent advantage.
## Apply for access
Interested organizations can [apply to CVP here](https://portal.anthropic.com/programs/cvp). As part of the application process, we will verify all applicants and request proof of the required security controls for the relevant access tier. Existing CVP members will keep their current settings for previous models and will be automatically evaluated for access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 through the updated program. Admins will need to assign access to specific workspaces by following [these steps](https://support.claude.com/en/articles/16764810-assign-a-program-to-workspaces-in-claude-console).
CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. CVP is only available on Amazon Bedrock for customers eligible for [Enterprise Frontier Safeguards](https://www.anthropic.com/news/enterprise-frontier-safeguards).
If you’re blocked on work you think your tier should allow, you can [report it here](https://claude.com/form/cyber-block-false-positive-report-cvp-rejection-appeal). Full details on each tier can be found in our [Help Center](https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet).
## Related content
### Anthropic invests $100 million to train 10,000 engineers and tackle the enterprise AI talent gap
Anthropic is investing $100 million in Claude Frontier Academy to train 10,000 Frontier Deployed Engineers by the end of 2027, with cohorts from Accenture, Bain, CBA, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk already underway.
[Read more](https://www.anthropic.com/news/claude-frontier-academy)
### Barclays scales Claude to upgrade operations and improve client experience
Barclays, the British universal bank, is expanding its strategic collaboration with Anthropic to integrate secure, enterprise-grade AI systems across its global operations.
[Read more](https://www.anthropic.com/news/barclays-scales-claude)
### Claude discovers a novel enzyme system with CRISPR-like repeats
We’re announcing a new life sciences research group and laboratory at Anthropic. This post introduces the team behind this work and shares early results in which Claude discovered a novel enzyme system with properties reminiscent of CRISPR, with only high-level direction from our scientists.
[Read more](https://www.anthropic.com/news/claude-discovers-novel-enzyme-system) | surprisetalk | 4 | 2 |
| 🟧 hn | Expanding the Cyber Verification Program | soltanov | 4 | 0 |
| 🟧 hn | The Anthropic Cyber Mission | surprisetalk | 6 | 0 |
| 🟧 hn | Launching an opt-in vulnerability-finding service for open-source software | di | 4 | 1 |
| 🟧 hn | OSS Scanner by Anthropic | 0natcer | 3 | 1 |
| 🟧 hn | OSS Scanner | vinhnx | 5 | 0 |
2026-10-10T03:36:37Z
The infrastructure half of the hypothesis is now substantiated: three first-party Anthropic releases (Cyber Mission, opt-in OSS vulnerability service, OSS Scanner) plus Oxide's independent finding and the expanded three-tier CVP constitute a real, scaling security-infrastructure program. The standards-for-AI-agents and independent-governance half remains unfulfilled, pending Anthropic's promised 'coming weeks' report (~late Oct). Competitive tracks (NVIDIA OpenShell 100+ firms, OpenAI standards initiative) mean any consolidation is contested. Engagement on the case itself is flat (0 pts/h, 0 comments/h) though the topic neighbourhood is hot.
2026-10-09T19:58:37Z
evidence attached: hn.story.50021247 — shared external link with case evidence
2026-10-09T12:02:36Z
Three first-party Anthropic releases now attach — the Cyber Mission announcement, an opt-in vulnerability-finding service for OSS, and the OSS Scanner — concretely expanding the CVP/Glasswing security infrastructure. The hypothesis's 'standards for AI agents' and independent governance layer remain unfulfilled; the case now waits on Anthropic's promised 'coming weeks' report (~late Oct). Engagement stays quiet on HN (0–6 pts, 0–2 comments) despite magnitude-valve cross-platform spread from the September OpenShell wave.
2026-10-09T04:52:45Z
evidence attached: hn.story.50013453 — Anthropic's OSS Scanner release appears to be a component of the Project Glasswing security infrastructure effort.
2026-10-09T03:24:28Z
Two first-party Anthropic releases attached: the Cyber Mission announcement and an opt-in vulnerability-finding service for open-source software — concrete Glasswing-aligned security infrastructure expanding the CVP ecosystem. The hypothesis's 'standards for AI agents' and independent governance layer remain unfulfilled; the case now waits on Anthropic's promised 'coming weeks' report (~late Oct). Engagement stays quiet (1.2 pts/h, HN posts 0 comments) despite a velocity spike on the Reddit Glasswing thread (+7 pts, +4 comments).
2026-10-08T23:06:44Z
evidence attached: hn.story.50010549 — Anthropic's opt-in vulnerability-finding service for OSS is a concrete Glasswing-aligned security infrastructure release.
2026-10-08T23:06:44Z
evidence attached: hn.story.50010605 — Anthropic's first-party Cyber Mission announcement is a direct contribution to the cross-industry agent security effort.
2026-10-07T07:02:09Z
Consolidation, not development: the only attachment since the Oct 7 reprice is a duplicate HN repost of the same Anthropic CVP announcement (0 comments), the substantive_evidence flag was a repost, and every thread is cooling (5.7 pts/h vs 158 peak, momentum cooling). The case's meaning is unchanged — it now waits on Anthropic's promised 'coming weeks' report — so attention cools to low while the corroborated state holds; the magnitude-valve reading reflects the already-coasted September OpenShell wave, not expanding periphery.
2026-10-07T06:29:22Z
evidence attached: hn.story.49988768 — shared external link with case evidence
2026-10-07T00:52:04Z
grounded: converges/medium — Anthropic's Oct 6 tiered CVP operationalizes the evidence-gated access ladder Scott already codified in Earned Autonomy and the Gate Criteria Framework — and ha
2026-10-07T00:43:01Z
Glasswing crossed from promise to institution: Anthropic's Oct 6 expanded Cyber Verification Program quantifies partner output (129K+ verified vulns Apr–Jul, 33K+ critical/high, self-reported) and structurally absorbs Glasswing into a standing three-tier access program with open applications, so the case's meaning shifts from 'will it substantiate?' to 'how far does an Anthropic-controlled access program go toward the hypothesized independent standards body?'. State rises to corroborated (first-party artifact plus Oxide's independently demonstrated real findings); heat rises to medium on claim-owner movement, the 6.9x velocity spike, and the promised report window now opening — not high, since the new spread is a modest Anthropic news cycle (HN 3 pts, Reddit 93 pts) and the magnitude-valve reading reflects the already-coasted September OpenShell wave.
2026-10-06T21:54:56Z
anchor promoted to claim owner's artifact: echo.blog.2d5428b336 -> hn.story.49982574 — The expanded tiered Cyber Verification Program is Anthropic's own artifact updating the same Glasswing program line (Glasswing members transition into Specialized Access), so it belongs on the existing case and should anchor it.
2026-10-06T21:54:56Z
evidence attached: hn.story.49982574 — The expanded tiered Cyber Verification Program is Anthropic's own artifact updating the same Glasswing program line (Glasswing members transition into Specialized Access), so it belongs on the existing case and should anchor it.
2026-10-06T20:42:17Z
evidence attached: reddit.post.1wzbacf — Reported outcome numbers — 135K verified vulnerabilities found, 9,333+ patched — are concrete progress evidence that Glasswing is becoming a substantive security-infrastructure effort, with skeptical community context attached.
2026-09-30T10:53:25Z
Third look of pure amplification, and now visibly the spike's tail: the OpenShell thread crept 736→761 pts over ~24h (~1 pt/h vs a 115 peak) and the watchdog echo is static, so the three velocity-spike firings were sensor noise on a coasting thread, not new spread. With no new venues, implementations, or corroboration, the periphery has stopped expanding — heat cools to low and the case idles on the ~late-Oct Glasswing report, the unchanged decisive checkpoint.
2026-09-29T09:57:27Z
This look is engagement amplification, not new signal: the OpenShell Reddit thread quintupled (153→736 pts) in a day while Glasswing itself stayed silent, the watchdog-chip echo gained comments but no corroboration, and no new venues, implementations, or communities appeared — so the competitiveness framing, watching state, and medium heat all stand, with high still gated on a corroborated watchdog claim, an OpenShell implementation wave, or any Glasswing movement before the ~late-Oct report.
2026-09-28T12:28:36Z
The competitiveness framing set earlier today holds: this look's meaning change is confirmation that the live center of gravity of the agent-security-infrastructure story sits on NVIDIA's rival track (OpenShell thread doubled again to top-decile, magnitude valve fired across platforms) while Glasswing itself has emitted nothing in two months; relevance rises to medium because OpenShell is a shipped, installable sandbox squarely in Scott's coding-agent sandboxing/harness territory. Heat stays medium rather than high: the spread is one fast Reddit thread plus a faint second-subreddit echo, not a derivative wave, momentum is steady not accelerating, and the decisive ~late-Oct report checkpoint is unchanged — high awaits a corroborated watchdog-chip claim, an OpenShell implementation wave, or any Glasswing movement.
2026-09-28T11:28:21Z
evidence attached: reddit.post.1wsbgsq — Single uncorroborated blog claim of a Nvidia agent-watchdog platform with Anthropic aboard — material context for the agent-security-infrastructure case if verified, but treat weight accordingly.
2026-09-28T10:27:29Z
NVIDIA's shipped OpenShell sandbox — 100+ firms in its safety stack, OpenAI abstaining, installable from GitHub today — is the first proof that practical cross-industry agent-security infrastructure can exist and win adoption, but it materialized on a rival track, not through Glasswing. The hypothesis is now a competitiveness question, not merely a delivery question: Glasswing's ~late-October report must show it can be the consolidating vehicle against NVIDIA's stack and OpenAI's rival standards bid, or the theme succeeds while this case's subject fails.
2026-09-28T10:25:09Z
evidence attached: reddit.post.1ws9ydg — NVIDIA's OpenShell sandbox with 100+ firms joining a safety stack and OpenAI abstaining is direct evidence on whether cross-industry agent security infrastructure becomes substantive.
2026-09-24T05:17:16Z
OpenAI's first-party standards initiative is the first genuinely new signal since launch: it confirms AI standards are contested ground among frontier labs, validating the space Glasswing targets while introducing fragmentation risk — but it evidences nothing about Glasswing's own progress toward cross-industry agent-security standards. The case stays in watching pending the promised ~90-day report (due ~late October), now against a multi-lab standards backdrop rather than an Anthropic-only bid.
2026-09-22T16:23:55Z
evidence attached: hn.story.49802825 — OpenAI's first-party standards initiative independently bears on the developing push for practical cross-industry AI-agent security standards.
2026-09-10T02:31:53Z
No substantive delta changes the interpretation: reconstructed testimony supports Oxide’s AI-assisted vulnerability work, not yet infrastructure or standards for securing agents. Retain the case for the expected report or concrete standards work; silence does not disprove the thesis, and another short-cadence review adds little.
2026-09-08T02:25:41Z
No substantive delta changes the case: reconstructed testimony about Oxide’s defensive deployment supports AI-assisted software security, not yet infrastructure or standards for securing agents. The expected report remains a reason to retain the case, but silence neither disproves the hypothesis nor justifies repeated short-cadence reviews.
2026-09-06T02:22:07Z
No substantive delta changes the interpretation: Oxide’s reported defensive use supports AI-assisted software security, not yet infrastructure or standards for securing agents. The expected report remains a reason to keep the case open, but duplicate coverage and silence warrant neither promotion nor disproof.
2026-09-04T01:25:09Z
No new evidence accompanied the staleness trigger, so Glasswing still supports only Oxide’s concrete AI-assisted software-security deployment rather than the hypothesized cross-industry agent-security infrastructure or standards effort. Keep monitoring event-first until the promised report window closes.
2026-09-02T00:32:37Z
Minor engagement adds no implementation, participant, report, or standards work; the evidence still supports only Oxide’s deployment rather than the hypothesized cross-industry agent-security effort. Keep monitoring event-first for the promised report or another concrete deliverable.
2026-08-30T23:31:32Z
No substantive evidence has arrived; repeated staleness checks reinforce that Glasswing currently amounts to Oxide’s concrete AI-assisted software-security deployment, not the hypothesized cross-industry agent-security standards effort. Keep it open only through the promised report window or for a new implementation or standards deliverable.
2026-08-28T23:23:05Z
This staleness check adds no case-specific progress; evidence still supports only Oxide’s AI-assisted software-security deployment, not the hypothesized cross-industry agent-security infrastructure or standards effort. Keep the case event-driven while the promised 90-day report window remains open.
2026-08-26T22:37:27Z
Continued silence makes the broader cross-industry agent-security standards thesis increasingly speculative; current evidence still establishes only Oxide’s concrete AI-assisted software-security deployment. The promised initial-report window remains open, so retain event-driven monitoring rather than closing the case.
2026-08-24T21:32:53Z
Another staleness check adds no evidence that Glasswing is expanding beyond Oxide’s known AI-assisted software-security deployment. Preserve the case only for the promised initial report, an independent implementation, or a concrete standards deliverable, with event-driven monitoring until the report window closes.
2026-08-22T21:31:27Z
The staleness trigger adds no substantive evidence, and repeated checks now confirm that current support stops at Oxide’s concrete AI-assisted software-security deployment. Keep the broader cross-industry agent-security standards thesis open only through the promised report window or until an independent implementation or standards deliverable appears.
2026-08-20T20:33:43Z
This staleness check adds nothing beyond the known Oxide deployment, so Glasswing still does not substantiate a cross-industry agent-security infrastructure or standards effort. Leave it open for the promised report, an independent implementation, or concrete standards activity, but monitor event-first rather than on a short cadence.
2026-08-18T19:39:15Z
No new evidence has appeared beyond minor engagement with duplicate coverage, so the broader agent-security infrastructure and standards thesis remains uncorroborated. Shift to event-driven monitoring for the promised report, an independent implementation, or concrete standards activity rather than further staleness checks.
2026-08-16T19:32:25Z
Another staleness check adds nothing beyond Oxide’s known deployment, so Glasswing still does not support the broader cross-industry agent-security standards thesis. Keep it open only for the promised initial report, another independent implementation, or concrete standards activity.
2026-08-14T18:36:35Z
Continued silence and unchanged duplicate coverage further weaken the interpretation of Glasswing as an emerging agent-security standards effort; current evidence still supports only a concrete AI-assisted software-security deployment. Keep the case open for the promised initial report or another independent implementation, but review far less frequently.
2026-08-12T17:38:34Z
The latest check adds only trivial engagement to duplicate coverage, with no new implementation, participant, report, or standards activity. Glasswing remains a concrete Oxide security deployment, but the broader cross-industry agent-security thesis still lacks corroboration.
2026-08-10T16:45:19Z
No new evidence has appeared, and topic heat or Anthropic’s standing does not substitute for progress by Glasswing itself. Keep the case open for the promised report or another concrete implementation, but stop frequent staleness reviews.
2026-08-08T16:29:32Z
The staleness check adds no evidence beyond Oxide’s known defensive deployment, so the hypothesized cross-industry agent-security infrastructure and standards effort remains uncorroborated. The promised initial report is still a plausible future checkpoint, but repeated duplicate coverage no longer merits frequent review.
2026-08-06T15:26:28Z
The newly attached item is another low-engagement duplicate of Oxide’s announcement, adding neither an independent implementation nor standards activity. Glasswing remains a concrete AI-assisted software-security collaboration, but the broader cross-industry agent-security infrastructure thesis is still uncorroborated.
2026-08-06T15:21:43Z
evidence attached: hn.story.49197627 — shared external link with case evidence
2026-08-02T03:21:00Z
No new evidence arrived during the staleness interval, and repeated engagement remains amplification of Oxide’s known deployment. Keep watching for the promised report, additional implementations, or standards activity; the broader agent-security thesis remains uncorroborated.
2026-07-29T13:28:53Z
The duplicate HN story accumulated a few comments but no independent evidence or new participants. Glasswing remains a concrete AI-assisted software-security deployment by Oxide; the broader hypothesis about cross-industry agent-security infrastructure and standards remains uncorroborated and unchanged.
2026-07-29T07:27:16Z
The attachment adds no discernible independent evidence or implementation beyond Oxide’s already-known first-party deployment. The concrete software-security work remains worth watching, but the broader agent-security infrastructure and standards thesis is still uncorroborated.
2026-07-29T02:27:26Z
The latest activity adds no independent evidence beyond Oxide’s existing first-party deployment account, so it is repetitive amplification rather than corroboration. Glasswing remains concrete as AI-assisted software security, but its development into agent-security infrastructure or standards is still unproven.
2026-07-28T23:25:38Z
The newly attached item is a duplicate link with no discussion or independent reporting, so it adds no corroboration. Glasswing remains a concrete AI-assisted software-security deployment, while the broader agent-security infrastructure and standards thesis is still unproven.
2026-07-28T23:21:11Z
evidence attached: hn.story.49091206 — shared external link with case evidence
2026-07-28T17:24:26Z
Oxide’s first-party account turns Glasswing into a concrete defensive deployment against vulnerabilities across a real hardware/software stack, not merely a partner announcement. It still supports AI-assisted software security more strongly than the hypothesized infrastructure or standards for securing AI agents, so the broader thesis remains uncorroborated.
2026-07-28T13:26:15Z
grounded: novel/low — No intersection was found in Scott’s wikis, and the radar does not already track this initiative or its actors. Agent security and harnesses are broadly within
2026-07-28T13:25:14Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49082926 -> echo.blog.2d5428b336 by Oxide Computer Company
2026-07-28T13:24:21Z
case created — A named cross-company initiative in the hot agentic-security space with a concrete first partner joining, worth tracking as it develops.