Black Duck Joins Anthropic Project to Secure Critical Software With AI
Black Duck, a provider of application security and software supply chain security solutions, has joined Anthropic’s Project Glasswing, an industry initiative focused on applying AI to defensive cybersecurity for critical software infrastructure.
As part of the project, Black Duck plans to integrate Anthropic’s Mythos technology across its application security portfolio. The combination will pair AI-assisted vulnerability discovery with Black Duck’s deterministic security testing, remediation processes, risk prioritization, and compliance controls.
Black Duck positions deterministic testing as a way to establish whether vulnerabilities are present, while AI reasoning can help determine their significance and assist with remediation. That combination is intended to accelerate vulnerability management without eliminating the auditability and governance requirements common in enterprise security programs.
The collaboration comes as AI affects both sides of application security. Developers increasingly use AI-generated code, while attackers can use similar technology to accelerate vulnerability research and exploit development. Black Duck Chief Product and Technology Officer Dipto Chakravarty said the increased speed of vulnerability discovery makes transparency and auditability particularly important for enterprise security teams.
For security and development organizations, the initiative reflects a broader shift toward incorporating AI directly into application security testing rather than treating it as a separate assistant. The practical challenge will be balancing faster AI-driven analysis with deterministic verification, human oversight and compliance controls before automated findings or fixes reach production systems.
Posted by Pure AI Editors on 09/08/2026