Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Cohesity pairs frontier AI models with human engineers and QA teams to remediate vulnerabilities at speed, while maintaining high quality.
In May 2026, Cohesity joined Anthropic's Project Glasswing and gained access to Claude Mythos Preview on June 5. The goal was practical: use the strongest coding and reasoning models for defense before comparable capabilities become routine on the attack side.
We gave the models a broad assignment. We tested them against the products we ship and operate—our SaaS services and our on-premises products.
Below is what we've learned, how we're responding, and what these changes mean for our approach to vulnerability management.
Our security teams used Mythos Preview, and other models, to assess our product source code, our compiled binaries, and running applications. This found vulnerabilities we had not previously identified.
The models reached into areas our existing tooling and manual review had not fully covered, and they did it quickly enough to change how we triage and validate issues. Using these frontier models, we were able to identify a greater number of existing vulnerabilities in a significantly shorter time than if we had used traditional tools. Our security engineering team also developed a sophisticated harness to test these models effectively throughout our secure software development lifecycle. This work runs alongside our existing static analysis, dependency scanning, and third-party penetration testing.
Cohesity has adopted AI throughout our secure software development lifecycle. AI enhances our existing code base, develops quality assurance test cases, and automates our triage and remediation process for third-party and native code vulnerabilities.
Engineering teams also used the models during remediation and extensive testing to help reason through fixes, identify related failure modes, and quickly deliver effective patches.
Security updates have shipped across Cohesity’s product lines, and the updates will continue in upcoming releases.
Project Glasswing only works if participants share what they learn. Anthropic said it will report public lessons from the program, and participants are comparing notes as the work progresses.
We worked closely with some of our top customers who were also part of Project Glasswing. They helped to test our binaries, in parallel with our testing of the source code.
In addition to these efforts, we collaborated with other top cybersecurity companies in Project Glasswing, including Palo Alto Networks, CrowdStrike, and Zscaler to understand their experiences and learn from each other how to action the Mythos findings.
In support of the office of the U.S. National Cyber Director’s efforts, we communicated our findings and shared our approach. We are also actively involved with the White House’s Gold Eagle initiative—a cybersecurity vulnerability coordination effort. Collaboration with top global brands that rely on Cohesity for the cyber resilience of their data, as well as with leading democratic governments, will continue to guide our strategy.
Vulnerability research has historically depended on a small number of people with deep expertise and enough time to chase weak signals. Mythos-class models connect minor vulnerabilities into attack chains, generating proof-of-concept code, testing hypotheses, and exploring more of the attack surface than traditional efforts could cover in the same period.
The same capability that helps us find and validate vulnerabilities before they are exploited also helps an attacker find and weaponize vulnerabilities faster. The result is a shorter window between "the vulnerability exists" and "we’ve been breached."
The recent Hugging Face OpenAI incident reminds us that the shift is no longer theoretical. AI-orchestrated, fully automated offensive attacks are real. “We believe this is a watershed moment for computer security as an industry,” Michael Dalton, a member of OpenAI’s technical staff, said recently at Black Hat 2026.
Our customers depend on our data security solutions as their last line of defense. So, we owe it to them to ensure that we have the most secure code.
Over the past 60 days, we’ve scanned our entire product portfolio with Mythos and other frontier AI models to find previously undiscovered vulnerabilities. Our security team built a strong harness, with sound automation tools, that allows us to use a wide range of frontier AI models for security testing and remediation, including:
We are also the only company in our space to sign both the Open Secure AI Alliance and the Open Weights and American AI Leadership initiative, alongside companies including NVIDIA and Microsoft. We expect both these initiatives to play a prominent role in the future of frontier AI models and cybersecurity.
We’ve held several customer briefings, under NDA, about our findings from being part of Project Glasswing. If you’re a Cohesity customer and your CIO and CISO would like a custom briefing from our security experts, just contact us.
A note on scope and process: Cohesity conducted this work in a controlled environment against our own code. Every vulnerability surfaced by this effort has been or is being triaged, validated, and remediated through Cohesity's standard vulnerability management and responsible disclosure process.
Written By
Brian Spanswick
Chief Information Officer, Chief Information Security Officer