Rubrik said it overhauled its internal code review and vulnerability triage pipeline after gaining access to Anthropic’s Mythos Preview through Project Glasswing and finding that the model could identify complex vulnerability chains across large codebases faster than the company’s existing security workflows could process them. The volume of findings created an immediate bottleneck in prioritization and remediation, prompting Rubrik to abandon plans to simply add more human reviewers.
Instead, the company built an automation-focused harness around the model to inject business and security context, manage tool calls and checkpoints, and iteratively narrow broad results into prioritized issues for engineers. Rubrik said it limited automated remediation to narrowly defined vulnerability classes where machine-generated fixes were reliable, while routing critical or less-certain findings to human engineers, reflecting a broader challenge seen in Glasswing deployments, where partners have reportedly identified more than 10,000 high- or critical-severity vulnerabilities but still struggle to patch them across sectors including technology, power, water, and healthcare.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Anthropic expanded Project Glasswing in June to roughly 150 organizations across 15 countries. Access to Mythos Preview was limited to vetted partners invited into the program.
Rubrik decided not to fully automate vulnerability remediation and restricted automated fixes to a tightly scoped set of predefined vulnerability classes. Findings outside those classes were routed to engineers for human judgment and final remediation.
Rubrik built a software harness around Mythos to manage tool calls, checkpoints, and added business and security context, effectively rebuilding its code review pipeline. It also used iterative targeted scanning passes to reduce noise and route higher-priority findings to engineers.
Faced with the volume of findings, Rubrik initially considered adding more human reviewers but concluded that human-driven remediation could not keep pace with AI-speed discovery. The company chose to overhaul its process instead of primarily expanding manual review capacity.
After joining the program, Rubrik assembled a dedicated multi-functional engineering and infosec team to handle threat discovery and remediation around Mythos. The team was tasked with building supporting processes rather than relying on the model alone.
Using Mythos Preview, Rubrik scanned its own codebase and identified complex vulnerability chains and a large volume of potential security issues that its usual tools and methods had missed. The initial use included whole-repository scanning before more targeted passes.
Rubrik joined Anthropic's Project Glasswing and received access to the Mythos Preview model for early use. The company then began applying the model to its own software security workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.