Vulnerabilities Neutral 5 Based on a press release

Checkmarx Taps Claude Mythos 5 as 80% of Exploits Hit Day-Zero

Checkmarx joins Anthropic's Project Glasswing to use Claude Mythos 5 for vulnerability detection, responding to J.P. Morgan data showing 80% of exploitations now happen on or before disclosure. The vendor will share what it learns with the security community.

· 4 min read ·

Beat this week

Last 7 days · Vulnerabilities

4 stories
7.3 avg impact
25% positive
50% negative
vs prior 7 days New New vs empty prior window

Impact not comparable yet. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 25 percentage points.

  • 25% positive
  • 25% neutral
  • 50% negative

This story sits in Vulnerabilities — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

5 impact
Neutralsentiment
4min read
  1. Checkmarx joins Anthropic's Project Glasswing to use Claude Mythos 5 for vulnerability detection, responding to J.P.
  2. Morgan data showing 80% of exploitations now happen on or before disclosure.
  3. The vendor will share what it learns with the security community.

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Checkmarx announced on Sept. 3, 2026 that it is participating in Anthropic's Project Glasswing.
  2. 2Project Glasswing gives select security organizations access to Anthropic's Mythos for defensive cybersecurity work.
  3. 3Checkmarx will use Claude Mythos 5 to strengthen its vulnerability detection and share learnings industry-wide.
  4. 4A J.P. Morgan July 2026 'Patchmageddon' analysis found roughly 80% of exploitations occur on or before the day a vulnerability becomes public.
  5. 5CEO Sandeep Johri said frontier models are surfacing risk that has gone undetected for years.
  6. 6Checkmarx operates Checkmarx Zero, a research arm focused on threat intelligence and product innovation.

We've watched frontier models surface risk that's gone undetected for years, faster than most organizations can keep up. Project Glasswing is one part of how we're working to close that gap and a chance to share what we learn so the rest of the industry can close it too.

Sandeep Johri CEO, Checkmarx

Press release announcing participation in Anthropic's Project Glasswing

Analysis

For security teams, the J.P. Morgan statistic that 80% of exploitations occur on or before the day a vulnerability becomes public is a stark reminder that patch cycles are already too slow. Checkmarx's move to deploy Claude Mythos 5 inside Anthropic's Project Glasswing is an attempt to find latent codebase risk before it reaches the exploitation window.

On September 3, 2026, Checkmarx announced — in a press release carried by GlobeNewswire and syndicated through regional outlets — that it is joining Anthropic's Project Glasswing, an initiative that grants select security organizations access to Anthropic's Mythos environment for defensive cybersecurity work. The announcement is a claim by Checkmarx and has not been independently verified by the outlets carrying it; nevertheless it signals a convergence between application security and frontier AI. Checkmarx says it will use Claude Mythos 5, Anthropic's newest model, to strengthen its vulnerability detection capabilities and to share findings with the wider security community.

Checkmarx's move to deploy Claude Mythos 5 inside Anthropic's Project Glasswing is an attempt to find latent codebase risk before it reaches the exploitation window.

The context Checkmarx cites is one of accelerating exploitation timelines. It points to a July 2026 J.P. Morgan Eye on the Market analysis — titled 'Patchmageddon' — that found roughly 80% of exploitations now occur on or before the day a vulnerability becomes public. That statistic underscores the collapsing patching window: by the time an organization becomes aware of a CVE or security flaw, attackers may already be weaponizing it. Traditional application security tooling, which depends on signature updates, scheduled scans, and manual triage, is ill-suited to that tempo. Checkmarx argues that frontier AI models can now surface categories of risk that have sat latent in codebases for years, ahead of conventional scanning cycles.

If the company's claims hold, the Project Glasswing participation could reframe vulnerability management from reactive patching to proactive discovery of dormant risk classes. Checkmarx is not simply licensing an AI feature; it is embedding a frontier model into its research workflow and committing to share what it learns with the industry. CEO Sandeep Johri's statement — 'We've watched frontier models surface risk that's gone undetected for years, faster than most organizations can keep up' — frames the effort as both a product enhancement and an industry-wide public good. The company's Checkmarx Zero research arm provides the internal mechanism for pairing threat intelligence with product innovation.

For the security industry, this announcement represents one of the first concrete cases of a major application security vendor publicly hitching its R&D to a frontier model in a defensive capacity. Anthropic's Project Glasswing appears designed to test Mythos and Claude models in high-stakes, real-world settings while limiting access to select partners. The project's name evokes an observational layer, suggesting a controlled data-sharing environment. Checkmarx's participation may give Anthropic valuable feedback on model performance against live codebases, while Checkmarx gains a differentiated detection capability.

Still, significant caveats apply. The announcement is promotional and forward-looking: it describes intended use, not independently measured outcomes. There are no disclosed benchmarks, no peer-reviewed comparisons between Claude Mythos 5 and existing scanners, and no timeline for when industry-learned improvements will materialize. The 80% statistic from J.P. Morgan is a market research conclusion, not a peer-reviewed study, though it aligns with broader security narratives around zero-day and same-day exploitation. For security teams, the immediate impact is limited — Checkmarx has not shipped a product update as of this announcement, and Anthropic's Mythos access remains restricted.

What to Watch

From a market perspective, the move intensifies competition among AI labs and security vendors. If frontier models can reliably find vulnerabilities that escape SAST, DAST, and SCA tools, the economics of application security could shift toward AI-augmented platforms. Incumbent security vendors may feel pressure to secure access to frontier models before such capabilities become table stakes. Conversely, if claims outpace results, the announcement will be remembered as another AI-security marketing event.

The forward-looking question is whether Project Glasswing evolves into a durable industry consortium or remains a selective beta. Checkmarx's public commitment to share findings creates an expectation of transparency that will be tested by subsequent disclosures. Security leaders should watch for concrete detection metrics, case studies of latent vulnerabilities found by Claude Mythos 5, and expansion of the Project Glasswing cohort. Until then, the announcement is best read as a credible signal of intent from a two-decade-old application security vendor aligning itself with frontier AI — not yet proof that the patch-and-pray era is over.

Timeline

Timeline

  1. J.P. Morgan publishes 'Patchmageddon' analysis

  2. Checkmarx announces participation in Project Glasswing

Cite This Page

"Checkmarx Taps Claude Mythos 5 as 80% of Exploits Hit Day-Zero." Cyber Intelligence Brief, September 4, 2026. https://getcyberbrief.com/story/checkmarx-anthropic-project-glasswing-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.