Anthropic previews Mythos, claims it found thousands of zero-day vulnerabilities in cybersecurity initiative
Anthropic unveiled a preview of Mythos, a frontier model it claims is the most powerful in its Claude lineup, for use in Project Glasswing—a cybersecurity initiative with 40+ partner organizations. According to Anthropic, Mythos identified thousands of zero-day vulnerabilities, many critical and up to two decades old, during early testing. The model will not be made generally available and is restricted to defensive security work by vetted partners.
Anthropic Previews Mythos Frontier Model for Cybersecurity Initiative
Anthropio on Tuesday released a limited preview of Mythos, claiming it as the most powerful model in its Claude AI lineup, exclusively for cybersecurity applications through a new program called Project Glasswing.
The model will be deployed by more than 40 partner organizations—including Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks—for defensive security work and vulnerability identification in first-party and open-source software systems.
Vulnerability Claims
According to Anthropic, Mythos identified "thousands of zero-day vulnerabilities, many of them critical" within weeks of initial testing. The company claims many of these vulnerabilities date back one to two decades, suggesting the model can surface long-undetected security issues across established codebases.
While the model was not specifically trained for cybersecurity work, Anthropic positions it as a general-purpose frontier model with "strong agentic coding and reasoning skills" suitable for complex tasks including agent-building and coding-related security analysis.
Limited Availability and Governance
Anthropio made clear that Mythos will not be made available to the general public. Partner organizations participating in Project Glasswing are expected to share their findings with the broader tech industry to advance collective cybersecurity knowledge.
The company also claims to be in "ongoing discussions" with federal officials regarding Mythos deployment. These discussions occur amid an active legal dispute between Anthropic and the Trump administration, which labeled the company a supply-chain risk after Anthropic refused to enable autonomous targeting or surveillance capabilities.
Background and Leak Context
Details about Mythos emerged following a data security incident last month in which a draft blog post and related documentation were left accessible in an unsecured cache. The leak, which Anthropic attributed to "human error," contained the model's original codename: "Capybara."
The exposed documentation stated that the model was "larger and more intelligent than our Opus models" and described it as "by far the most powerful AI model we've ever developed." The leak also noted potential dual-use risks, acknowledging that adversaries could theoretically weaponize the model to discover vulnerabilities rather than patch them.
This incident compounds recent operational security challenges. In March, Anthropic accidentally exposed nearly 2,000 source code files and over half a million lines of code through a mistake in the Claude Code software package version 2.1.88. The subsequent cleanup effort inadvertently triggered mass removal of thousands of code repositories on GitHub.
What This Means
Anthropio is positioning Mythos as a specialized frontier model for high-stakes defensive security applications rather than general-purpose use. The restricted preview with vetted partners resembles a staged rollout approach common for models with dual-use risk potential. The vulnerability claims, if independently verified, would represent meaningful security impact; however, the lack of public benchmarks or third-party validation means claims about discovery rates remain unverified. The ongoing federal discussions and legal disputes add complexity to what appears to be a deliberate, security-conscious deployment strategy for its most powerful model to date.
Related Articles
Anthropic Reverses Course, Will Let Enterprise Customers Store Retention Data on Their Own Cloud
Anthropic is revising its 30-day data retention policy after enterprise pushback, allowing regulated-industry customers to store the required data on their own cloud infrastructure instead of Anthropic's servers. The changes, built with more than 100 customers, are set to roll out this fall.
Anthropic SDK v0.124.0 Moves Files and Skills APIs to General Availability, Adds Computer Use and Browser Use Toolsets
Anthropic released v0.124.0 of its Python SDK, graduating the Files and Skills APIs to general availability and introducing new computer use and browser use toolsets. The release is available now on GitHub.
Anthropic Claims Claude Agents Beat Industry Hit Rates in Autonomous Protein Design Trials
Anthropic published two experiments showing Claude models autonomously running open-source protein design software end-to-end, claiming hit rates of 26.8% against an industry baseline of 10-15%. Independent verification of the results is still pending.
Anthropic Expands Claude Cowork to Mobile for All Paid Plans
Anthropic announced that Claude Cowork, its workspace-focused feature, is now available on mobile and web for all paid plans. The rollout began last month exclusively on Anthropic's most expensive tier before expanding today.
Comments
Loading...