Running critical infrastructure means dealing with a cybersecurity challenge that is getting more complicated. This is especially true as AI development accelerates and makes it harder to fix problems before they are exploited. Nozomi Networks, a leading industrial cybersecurity firm, has recently joined Anthropic’s Project Glasswing. The initiative aims to find flaws before attackers can use them. It will focus on operational technology (OT), industrial systems, and cyber-physical environments, all of which face unique security challenges due to their complex setups.
As AI becomes more integrated into business operations, the conversation around customer experiences is evolving. The systems that support these experiences, including cloud platforms, connected devices, and physical infrastructure, now have to deal with a more dangerous cyber landscape. This is not just a technical problem. Many of the systems in use today were built years or even decades ago. They must operate under strict safety rules and physical limitations, which can make applying updates or patches difficult, if not impossible.
Expanding the Reach of Project Glasswing
Nozomi Networks is one of many organizations now involved in Project Glasswing. Last month, the initiative added around 150 organizations from more than 15 countries. These groups used the Claude Mythos Preview model, a large language model developed by Anthropic, to uncover more than 10,000 high- and critical-severity vulnerabilities. This large number shows the potential of AI to detect hidden weaknesses in complex systems.
Even though the U.S. government removed export restrictions on Mythos-class models at the end of June, the model is not available to the general public. Only pre-vetted organizations through Project Glasswing and approved cybersecurity partnerships can access it. This controlled release helps ensure responsible and effective use in the cybersecurity field.
Nozomi Networks is using Project Glasswing to apply advanced AI models to find vulnerabilities in operational technology (OT) and Internet of Things (IoT) systems. The company is using the initiative to strengthen its own cybersecurity efforts. It is also sharing its findings and insights with Anthropic’s research team and the larger cybersecurity community. The company believes that AI models like Mythos are on the verge of transforming how vulnerabilities are found and addressed.
'They can help defenders find risks faster and at greater scale,' Nozomi said. While AI offers new ways to discover vulnerabilities, the company has warned about a growing gap between identifying these issues and managing the actual risks. Moreno Carullo, Founder and Chief Technical Officer at Nozomi, pointed out that OT and industrial control systems need a different strategy than traditional enterprise IT. These systems often have long lifecycles and face patching restrictions, making it hard to respond in the same way as regular IT systems.
In industrial settings, priorities often center on safety and system availability rather than fast software updates. An energy facility, manufacturing plant, or transportation system cannot stop operations just to install a software patch, as that could lead to service disruptions or safety issues. Carullo explained that finding a flaw in a SCADA system or a safety instrumented system is not as simple as spotting a CVE that can be patched. The impacts of these flaws often go beyond just data loss and can include physical damage.
Quincy Castro, Chief Information Security Officer (CISO) at ChainGuard, pointed out another key problem: many organizations still use outdated technology. This technology may be hard or impossible to update. This creates a growing mismatch between the speed at which vulnerabilities are found and how slowly they can be addressed. The issue is especially serious in critical infrastructure environments, where even small disruptions can have large effects.
As AI continues to improve the ability to detect vulnerabilities, traditional methods for addressing them are struggling to keep up. The cybersecurity field now faces pressure to rethink how risk is managed in these vital systems. Through its involvement in Project Glasswing, Nozomi Networks is helping lead this effort, with a focus on AI-driven vulnerability discovery in operational technology and Internet of Things systems.

