IBM sdx crop
– FinkAvenue/Getty Images

IBM is the latest named partner in Anthropic's Project Glasswing cybersecurity venture, as an exec from the tech giant is tipped to lead the Cybersecurity and Infrastructure Security Agency (CISA).

IBM has been using its place in Project Glasswing to detect and address vulnerabilities in widely used software and making its insights available to the wider community. These findings were made with Anthropic's Claude Mythos Preview general-purpose large language model (LLM) that has a particular skill for cybersecurity tasks.

Anthropic exclusively lent Claude Mythos Preview to an elite group of vendors, including Amazon Web Services (AWS), Broadcom, Cisco, Google, Microsoft, Nvidia, and Palo Alto Networks. Recent days have revealed the participation of telecom operators Verizon and AT&T, as well as web giant Cloudflare.

Those members have used the autonomous platform to reportedly find “thousands” of high-severity vulnerabilities across every major operating system and web browser.

"As part of Project Glasswing, we've been hardening our own products and contributing fixes back to the open-source community. The collaboration makes the entire ecosystem stronger," Rob Thomas, IBM's SVP for software and chief commercial officer, noted.

The company framed the move as part of a broader enterprise security push for the AI era, saying adversaries are increasingly weaponizing AI against the systems organizations depend on.

CISA chatter

IBM's announcement comes as rumors abound that Tom Parker, global lead at IBM Security, is in the running to take over CISA.

According to Dark Reading, Parker is reportedly being eyed for the director role by new Department of Homeland Security (DHS) Secretary, Markwayne Mullin. While DHS has yet to comment on the rumor, Parker told the the title he had not had any “direct engagement” with the administration on regarding the role, but would welcome the conversation to explore "strengthening the security and resilience of the nation's most critical infrastructure and building operationally robust partnerships with American cyber businesses."

Parker previously consulted for CISA predecessor the United States Computer Emergency Readiness Team (US-CERT), and served on the DHS cyber advisory committee during the George W. Bush administration.

Parker also co-founded red-teaming firm FusionX in 2010, which was subsequently sold to Accenture in 2015; digital asset visibility startup Hubble, which was acquired by NetSPI in 2024; and has led on security for AIG, Securicon, Mu Dynamics (now part of Spirent Communications), and Verizon Business.

CISA is currently under the command of acting director Nick Andersen after Jen Easterly stepped down from the director role last year. Efforts to announce a replacement have been fraught by Senate objections. These have included efforts from Sen. Ron Wyden (D-Oregon) who objected to CISA’s refusal to release a report on security vulnerabilities in the telecom sector following the infamous Salt Typhoon attack of 2024.