**Nozomi Networks Joins Anthropic’s Project Glasswing to Enhance AI-Driven Vulnerability Detection in Critical Infrastructure**
Nozomi Networks has become a key participant in Anthropic’s *Project Glasswing*, an ambitious initiative that leverages artificial intelligence to identify software vulnerabilities in critical infrastructure and connected systems. By contributing its expertise in operational technology (OT), the Internet of Things (IoT), and cyber-physical systems (CPS), Nozomi is helping to push the boundaries of AI-driven cybersecurity.
The company plans to integrate advanced AI models into its platform to discover vulnerabilities, contribute findings to Anthropic’s research, and share relevant results with the broader cybersecurity community. This collaboration underscores the growing role of AI in protecting essential industrial systems.
**Project Overview and Goals**
Project Glasswing brings together software companies, infrastructure providers, and security specialists to collectively improve the security of critical systems. Participating organizations are granted access to *Claude Mythos Preview*, a tool designed to examine software for vulnerabilities and assess how frontier AI models perform against real-world infrastructure challenges.
According to Anthropic, organizations involved in the project have already used the model to scan their codebases, with Claude Mythos Preview identifying more than 10,000 potential findings rated as high or critical severity across participating organizations.
Earlier versions of Claude Mythos Preview were also used to examine open-source software, with external security researchers helping triage and validate results before findings were responsibly disclosed to software maintainers.
**Extending Research to Industrial and Connected Environments**
Nozomi’s involvement extends this research into industrial and connected-device environments—systems that link enterprise applications, remote-access services, cloud platforms, sensors, controllers, and physical equipment. These connections enable data and access to flow between IT and OT systems, creating complex security challenges.
In such environments, vulnerabilities can affect not only digital systems but also physical operations, including production, control, and safety functions. This means that security teams must carefully consider the operational role of affected assets when assessing risk.
**Operational Context Shapes Vulnerability Priorities**
Unlike traditional IT systems, OT environments often include equipment with long lifecycles, limited maintenance windows, and systems that cannot be patched using standard processes. Cyber incidents in these settings can directly impact physical equipment, production processes, and safety systems.
NIST defines OT as programmable systems and devices that interact with the physical environment or manage devices that do so. Its guidance emphasizes that OT cybersecurity controls must account for performance, reliability, and safety—not just technical severity.
As a result, a vulnerability’s technical severity rating is only part of the prioritization process. Operators must also consider:
– Where the affected software is deployed
– Which process it supports
– How it is connected
– The potential impact of asset failure or downtime
CISA guidance similarly stresses the importance of asset visibility and categorization in vulnerability management, reinforcing the need to understand system function before determining response priorities.
Project Glasswing’s findings highlight the growing challenge of managing model-generated results at scale, making human validation and operational prioritization more important than ever. Nozomi and Anthropic have not yet disclosed how they plan to measure false positives or assign process-level risk to model-generated findings.
Nozomi already uses AI and machine learning within its platform to analyze industrial network communications, process variables, assets, and network relationships. The company specializes in cybersecurity for OT, IoT, and critical infrastructure environments.
Through Project Glasswing, Nozomi will apply these models within its own platform to enhance vulnerability detection and research. While the initiative focuses on vendor-controlled software and testing in controlled environments, it does not currently indicate direct testing on live customer equipment or production networks.
Other industrial cybersecurity companies, such as Dragos, have also joined Project Glasswing, using Claude Mythos Preview to examine their own products for previously undetected vulnerabilities. These efforts aim to strengthen software security and provide insights into AI model performance in OT environments, with findings shared with the broader security community.
**Testing Without Disrupting Operations**
NIST advises organizations to carefully evaluate how vulnerability-scanning tools might affect OT components and communications. Recommendations include testing scanning tools in offline environments before deploying them in production.
Active testing can generate traffic and queries that disrupt timing-sensitive or resource-constrained OT components. Interrupted connections or unstable devices can affect physical processes, especially when those components support production, control, or safety functions.
Alternatives such as replicated, virtualized, or simulated systems allow organizations to evaluate testing methods without risking production environments. When live testing is necessary, it should ideally occur during planned outages or maintenance periods.
These considerations are especially relevant to AI-assisted vulnerability research. While models can analyze software for weaknesses, identifying a vulnerability and testing or remediating it are separate activities. Models cannot determine how operators should examine or modify affected equipment.
Remediation adds another layer of complexity. Finding a vulnerability does not guarantee that a patch can be immediately installed—especially in environments where equipment must remain online or updates require testing with specialized hardware.
NIST describes patch management as a multi-step process that includes identifying, prioritizing, acquiring, installing, and verifying updates. OT operators must carry out these steps while accounting for system availability and safety.
Operators may need to test vendor updates, schedule installations, and confirm that changes do not disrupt industrial processes. When immediate patching is not possible, compensating controls can be evaluated based on the affected system and operational requirements.
Project Glasswing is exploring how AI developers, software providers, infrastructure operators, and security specialists can use advanced models for defensive vulnerability research. Anthropic has positioned the initiative around identifying and addressing weaknesses in critical software.
Nozomi will contribute OT, IoT, and CPS expertise while applying these models within its platform. The company also plans to contribute research insights and share relevant findings with the broader cybersecurity community.
—
### FAQ
**What is Project Glasswing?**
Project Glasswing is an initiative led by Anthropic that uses artificial intelligence to identify software vulnerabilities in critical infrastructure and connected systems. It brings together software companies, infrastructure providers, and security specialists to use AI models—such as Claude Mythos Preview—for vulnerability discovery and assessment.
**Which companies are participating in Project Glasswing?**
Participants include software companies, infrastructure providers, and security firms. Notable members include Nozomi Networks and Dragos, both of which specialize in operational technology (OT) and industrial cybersecurity.
**What role does Nozomi Networks play in Project Glasswing?**
Nozomi Networks contributes expertise in OT, IoT, and cyber-physical systems. It applies advanced AI models within its platform to discover vulnerabilities, contributes findings to Anthropic’s research, and plans to share relevant results with the cybersecurity community.
**What is Claude Mythos Preview?**
Claude Mythos Preview is an AI model developed by Anthropic to examine software for vulnerabilities. It helps assess how frontier AI models perform against critical systems and has already identified tens of thousands of high- and critical-severity findings in participating organizations’ codebases.
**Does Project Glasswing involve testing live production systems?**
No. The initiative primarily focuses on vendor-controlled software and testing in controlled environments. It does not currently involve direct testing of live customer equipment or production networks.
**How does operational context affect vulnerability prioritization in OT environments?**
In OT environments, factors such as equipment lifecycle, maintenance windows, system complexity, and safety impact must be considered alongside technical severity. Vulnerabilities are prioritized based on location, process support, connectivity, and potential operational impact.
**How does Nozomi use AI in its cybersecurity platform?**
Nozomi uses AI and machine learning to analyze industrial network communications, process variables, assets, and network relationships. This enables advanced threat detection and vulnerability analysis tailored to OT, IoT, and critical infrastructure environments.
**What are the next steps for Project Glasswing?**
The project continues to explore how AI developers, software providers, infrastructure operators, and security specialists can collaboratively use advanced models for defensive vulnerability research. The goal is to identify and address weaknesses in critical software while ensuring responsible disclosure and remediation.
—
**Conclusion**
Nozomi Networks’ participation in Anthropic’s Project Glasswing marks a significant step in applying artificial intelligence to the challenge of securing critical infrastructure. By integrating OT, IoT, and cyber-physical systems expertise into AI-driven vulnerability discovery, Nozomi is helping to bridge the gap between cutting-edge AI research and real-world industrial security needs.
While the initiative shows great promise in uncovering hidden vulnerabilities at scale, it also underscores the importance of human validation, operational context, and careful remediation planning—especially in environments where system uptime and safety are paramount. As Project Glasswing continues to evolve, collaboration between AI developers, security experts, and infrastructure operators will be essential to building a more secure and resilient digital-physical world.



