AI News AI资讯 1d ago Updated 9h ago 更新于 9小时前 46

Anthropic scales Project Glasswing to 150 partners across 15 countries to hunt critical software flaws Anthropic 将 Project Glasswing 扩展至 15 个国家的 150 个合作伙伴,以查找关键软件漏洞

Anthropic just turned Project Glasswing from a research partnership into a global security operation, onboarding 150 organizations across 15 countries to deploy its Claude Mythos Preview model for finding critical vulnerabilities in infrastructure software. The immediate result is a staggering 10,000+ serious flaws already identified. This sounds like a net positive for digital security—a powerful AI being used to find and fix weaknesses before they’re exploited. But the twist in the business mo Anthropic公司近日将“玻璃翼项目”从研究合作升级为全球安全行动,在15个国家吸纳150个组织机构,部署其Claude Mythos Preview模型,专门用于检测基础软件中的关键漏洞。目前直接成果已十分惊人——超过1万处严重缺陷被陆续发现。这听起来对数字安全领域是个纯粹利好:强大的人工智能正被用于在漏洞被利用前主动发现并修复弱点。但这种商业模式的潜在转折,却揭示出更为复杂且可能引发争议的现实。

70
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

Anthropic just turned Project Glasswing from a research partnership into a global security operation, onboarding 150 organizations across 15 countries to deploy its Claude Mythos Preview model for finding critical vulnerabilities in infrastructure software. The immediate result is a staggering 10,000+ serious flaws already identified. This sounds like a net positive for digital security—a powerful AI being used to find and fix weaknesses before they’re exploited. But the twist in the business model reveals a more complicated, and potentially problematic, reality.

The core of the project is a classic bug bounty structure, supercharged by AI. Partners use the specialized model to scan their own systems, presumably uncovering deep-seated issues that human auditors might miss. The scale is impressive, and the speed is undeniable. Finding 10,000 serious vulnerabilities is a testament to the model’s capability. However, the news also announces that Anthropic is selling a commercial product called Claude Security to help fix these very flaws. This creates a perfect closed loop: identify the disease, then sell the cure.

From a pure business strategy, it’s brilliant. You create a market by demonstrating a massive, previously hidden need, and then you position your product as the necessary solution. It’s the kind of vertical integration that would make a classic monopolist proud. But for a company that built its brand on AI safety, the ethical optics are murky. Are we witnessing the creation of a new, AI-driven dependency in cybersecurity? The message becomes: your infrastructure is riddled with vulnerabilities you can't possibly find on your own, but our tool can find them, and our other tool can fix them. Pay up.

One could argue Anthropic is just filling a gap. Security is always a cat-and-mouse game, and using AI for defense is a logical evolution. But the "both sides of the problem" dynamic risks perverting incentives. If your primary revenue comes from both diagnosing and treating a chronic condition, do you have a vested interest in the condition remaining widespread? This isn't suggesting deliberate malfeasance, but it is a classic conflict of interest that demands scrutiny. The model’s power makes the potential conflict sharper.

Furthermore, the focus on "critical infrastructure" is a loaded term. It implies power grids, healthcare systems, financial networks. A tool with this level of access and capability becomes a crown jewel not just for its owner, but for any attacker who might compromise it. The project's security itself becomes a paramount concern. The announcement mentions partners, but not the safeguards around the model or the vast data it processes.

Ultimately, Anthropic is no longer just a frontier AI lab; it’s becoming an active player in the global cybersecurity market. The expansion of Project Glasswing demonstrates undeniable technical prowess. But in wrapping that prowess in a commercial package that profits from the very insecurity it reveals, Anthropic is walking a tightrope. It's a high-stakes move that could redefine proactive security—or it could simply create the next great AI-powered vendor lock-in. The 10,000 flaws are a symptom; the business model is the condition we should be diagnosing more closely.

Anthropic公司近日将“玻璃翼项目”从研究合作升级为全球安全行动,在15个国家吸纳150个组织机构,部署其Claude Mythos Preview模型,专门用于检测基础软件中的关键漏洞。目前直接成果已十分惊人——超过1万处严重缺陷被陆续发现。这听起来对数字安全领域是个纯粹利好:强大的人工智能正被用于在漏洞被利用前主动发现并修复弱点。但这种商业模式的潜在转折,却揭示出更为复杂且可能引发争议的现实。

Anthropic公司近日将“玻璃翼项目”从研究合作升级为全球安全行动,在15个国家吸纳150个组织机构,部署其Claude Mythos Preview模型,专门用于检测基础软件中的关键漏洞。目前直接成果已十分惊人——超过1万处严重缺陷被陆续发现。这听起来对数字安全领域是个纯粹利好:强大的人工智能正被用于在漏洞被利用前主动发现并修复弱点。但这种商业模式的潜在转折,却揭示出更为复杂且可能引发争议的现实。

项目核心是典型的漏洞赏金机制与人工智能的深度融合。合作机构使用专用模型扫描自有系统,能够发现那些人类审计员可能疏漏的深层次问题。其覆盖规模令人瞩目,检测效率更是毋庸置疑。发现万量级严重漏洞充分证明了该模型的能力。但相关报道同时透露,Anthropic正在销售名为“Claude Security”的商用产品,专门用于修复这些漏洞。由此形成了一个完美的商业闭环:先诊断病症,再出售解药。

从纯粹商业战略角度看,这是精妙的设计。通过揭示市场中庞大而隐蔽的需求缺口,顺势将自家产品定位为必备解决方案。这种垂直整合策略足以让传统垄断企业引以为傲。然而对于以人工智能安全立命的公司而言,这种模式的伦理观感却显得模糊不清。我们是否正在目睹网络安全领域形成新的AI驱动型依赖?其潜在信息昭然若揭:你们的基础架构遍布自己无法发现的漏洞,但我们的工具能找到它们,我们的另一款工具可以修复它们——请付费吧。

也有人认为Anthropic只是在填补市场空白。安全防御本就是场永恒的猫鼠游戏,运用人工智能进行防护是符合逻辑的技术演进。但这种“既当裁判又当运动员”的...

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude 安全 安全 大模型 大模型 闭源 闭源 产品发布 产品发布
Share: 分享到: