Project Glasswing at Black Hat 2026: Will Anthropic Present and What to Watch For

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
Black Hat USA has been the stage for the most consequential vulnerability research disclosures for nearly 30 years. Project Glasswing, Anthropic's AI-powered coordinated vulnerability disclosure program, produced 9 CVEs, over 10,000 security findings across 200+ partner organizations, and demonstrated autonomous zero-day discovery in 2026. This is precisely the class of research that Black Hat selects for Briefings. Here is the context practitioners need before the schedule drops.
Black Hat as the Premier Vulnerability Disclosure Venue
Black Hat USA was founded in 1997 by Jeff Moss (Mudge) and has been operated by Informa Tech since its acquisition from CMP Media. Its reputation rests on a consistent pattern: the most technically significant vulnerability research of any given year appears at Black Hat first. Stuxnet analysis reached a public audience at Black Hat. iOS jailbreak techniques that forced Apple to rearchitect its security model were presented at Black Hat. LTE network vulnerabilities exposing carrier-level surveillance appeared at Black Hat. The conference's peer review process, while imperfect, selects for novelty, technical rigor, and practical impact at a level that most venues do not reach.
The 2026 AI Security Research Context
The 2024 and 2025 Black Hat conferences saw AI security emerge as a significant track. By 2026, it is the dominant research theme. The shift is not hype. Autonomous AI systems demonstrated the ability to discover and exploit vulnerabilities in real software at scale in 2025 and 2026. The research being submitted to Black Hat 2026 reflects practitioners and researchers who spent the past year building, testing, and documenting AI-assisted attack capabilities. The 2026 AI security track is the highest-signal it has been at any security conference.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Why Glasswing Research Is a Natural Black Hat Fit
Project Glasswing processed over 10,000 security findings, established CVD partnerships with 200+ organizations, and produced 9 CVEs from autonomous AI analysis. The bug classes Glasswing has found, including browser vulnerabilities, OS-level issues, hypervisor flaws, and cryptographic implementation errors, are the same categories that have defined landmark Black Hat talks for decades. Presenting autonomous AI vulnerability discovery at Black Hat would follow the conference's pattern exactly: novel technique, real-world impact, practitioner-applicable findings. Whether Anthropic submits directly or collaborating researchers present Glasswing-related work, the research baseline will be present in the 2026 AI security track.
What an Anthropic Black Hat Talk Might Look Like
A Glasswing or Mythos-related Black Hat presentation would most likely include a live demonstration component: an AI system identifying a vulnerability in a real target in real time, with the exploit chain explained step by step. Methodologically, it would cover how the system was prompted, what its reasoning process looked like at each stage, where human researchers intervened versus where the AI operated autonomously, and what the resulting CVE disclosure process required. New CVE disclosures at the time of the talk would be typical. The Mythos benchmark data (21/41 ExploitBench V8 ACEs; no other model above zero) gives any such presentation a concrete quantitative frame that Black Hat audiences respond to.
Other AI Security Research to Watch
Beyond Glasswing-adjacent research, the 2026 Black Hat AI security track will likely feature: XBOW and similar autonomous offensive security tools that have emerged in the past year; LLM-assisted fuzzing frameworks with real CVE results; prompt injection attacks demonstrated against production AI deployments; AI-generated malware analysis and evasion techniques; and AI system auditing methodology for practitioners who need to assess their own AI deployments. Each of these areas has generated significant research activity in 2025 and 2026 and is well-suited to Black Hat's format.
How to Follow Black Hat Announcements
The Black Hat 2026 Briefings schedule is expected in late June or early July 2026. Monitor blackhat.com/us-26/briefings/ for the full session list. For Glasswing and Anthropic-related research specifically, watch Anthropic's security blog and the LinkedIn profiles of researchers named in Glasswing-related publications. Decryption Digest covers AI security research developments daily and will report any Black Hat schedule announcements relevant to AI vulnerability research as they are made.
Preparing to Absorb and Apply What You Hear
The highest-value outcome of a Black Hat Briefings session is operational change within days of returning. For AI vulnerability research specifically, that means: understanding the bug classes being targeted so your patch prioritization reflects current autonomous discovery capabilities; evaluating whether your detection tooling would catch exploitation of the vulnerabilities being discussed; and assessing whether AI-assisted attack techniques in the research are already present in campaigns targeting your industry. Read the Mythos Brief at decryptiondigest.com/mythos-brief before Black Hat to build the foundational context that makes the 2026 AI security track immediately applicable rather than conceptually interesting.
Get the Full Research Brief Before You Arrive
The resources below are available to Decryption Digest subscribers and will help you arrive at Black Hat with the Glasswing and Mythos context already in place.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
Project Glasswing is the biggest security research story of 2026, and Black Hat is the most likely venue for its next major public presentation. Get the full research context now at decryptiondigest.com/mythos-brief. And if you want to be in the room when the next chapter drops, enter to win a full Briefings pass at decryptiondigest.com/blackhat-2026.
Frequently asked questions
Is Anthropic presenting at Black Hat 2026?
Anthropic has not publicly confirmed a Black Hat USA 2026 presentation as of this writing. However, Project Glasswing's research outputs (9 CVEs, 10,000+ findings, autonomous zero-day discovery) are exactly the class of research Black Hat selects for Briefings. Monitor the official schedule release in late June or July 2026 for confirmation.
What AI security research will be at Black Hat 2026?
Black Hat 2026's AI security track is expected to include autonomous vulnerability discovery research, LLM exploit agent demonstrations, prompt injection at infrastructure scale, AI system auditing methodology, and offensive use of AI in attack chains. The Glasswing and Mythos research context makes the 2026 AI track the highest-signal it has ever been.
How do I follow Black Hat talk announcements?
Monitor the Black Hat USA 2026 Briefings page at blackhat.com/us-26/briefings/ for the schedule release in late June or early July. Follow Anthropic's official blog and security researchers working on AI vulnerability research for independent announcements. Subscribe to Decryption Digest for daily coverage of any Black Hat-related research announcements.
What is the most important AI security research of 2026?
Project Glasswing (9 CVEs, 10,000+ findings, 200+ CVD partners) and Claude Mythos (21/41 ExploitBench V8 ACEs, no other model above zero; 10.5x ExploitGym improvement; $35M SCONE-Bench benchmark) represent the most significant AI security research programs of 2026. Both demonstrate autonomous AI operating at the frontier of vulnerability research.
Can I watch Black Hat talks remotely?
Remote attendance options vary by year. Most Briefings sessions are not streamed or made publicly available during the conference. Some researchers publish slides and papers independently after the conference. Informa Tech occasionally offers virtual access options, but coverage is typically limited compared to in-person attendance.
How can practitioners without a Briefings pass follow Glasswing-related research announcements during Black Hat week?
Practitioners without a Briefings pass can track Glasswing-related announcements through three parallel channels during conference week. First, follow confirmed Black Hat 2026 speakers on LinkedIn and social platforms before the conference: most researchers post their key findings and slide decks within 24 hours of their session, giving you the core content without live access. Second, monitor security journalism from outlets including Dark Reading, Ars Technica, and The Register, whose embedded reporters publish disclosure summaries within hours of each Briefing. Third, subscribe to the Decryption Digest daily briefing, which covers the most operationally significant Black Hat disclosures each morning during conference week with practitioner-actionable context. For Glasswing-specific content, any new CVE assignments or Anthropic research announcements will appear simultaneously on the Anthropic blog and NVD, which are publicly accessible regardless of conference pass status.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
