Rubrik Gets Anthropic Mythos Access for Vulnerability Testing
Rubrik said on June 2 that it had received access to Anthropic's Claude Mythos Research Preview through Project Glasswing and planned to use it across its enterprise platform and product portfolio to identify, assess, and remediate software vulnerabilities. The announcement described a testing program, not completed findings; Rubrik disclosed no vulnerability count or test results.
Rubrik announced on June 2, 2026, that Anthropic had granted it access to Claude Mythos Research Preview through Project Glasswing. The security company said it planned to apply the model across its enterprise platform and product portfolio to identify, assess, and help remediate software vulnerabilities.
What Rubrik announced
The announcement is an early-access and testing commitment, not a report of completed findings. Rubrik said Mythos would be used against its codebase and broader software environment to look for weaknesses before attackers could exploit them. It framed the work as part of a cyber-resilience program intended to improve the security of products used for data protection and recovery.
SecurityBrief independently reported the plan on June 3 and described Project Glasswing as a program that gives selected operators of critical software infrastructure access to advanced vulnerability-discovery and remediation models. Both accounts describe intended use. Neither publishes the test scope, methodology, affected components, vulnerability severity, remediation rate, or results.
What remains unproven
Rubrik did not disclose any vulnerabilities found by Mythos, say that production systems had been scanned, or provide a schedule for releasing results. Readers should therefore treat the announcement as a deployment plan rather than evidence that the model has already improved Rubrik's security posture.
The practical value will depend on how the company validates model findings, prevents unsafe proof-of-concept execution, routes reports to maintainers, measures false positives, and verifies that patches close the reported weakness without creating regressions. Those controls matter because vulnerability discovery can move faster than remediation.
For security teams, the event is useful as a case study in how a major software vendor intends to operationalize a restricted frontier model. The stronger evidence will come later: reproducible disclosures, independently verified fixes, and metrics that separate discovered issues from duplicates, low-severity findings, and model errors.
Key Points
- 1Rubrik received access to Claude Mythos Research Preview through Project Glasswing and said it planned to apply the model across its platform and product portfolio.
- 2The June 2 announcement disclosed no completed scan, vulnerability count, severity breakdown, remediation rate, or test results.
- 3Practitioner value will depend on validation, safe execution, disclosure, patch verification, and false-positive controls rather than access to the model alone.
Scoring Rationale
Rubrik's planned use of a restricted frontier model is relevant to software-security teams evaluating AI-assisted vulnerability programs. The impact is moderate because the announcement provides no completed findings, methodology, remediation metrics, or independently verified security outcome.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

