Anthropic previews Mythos, claims it found thousands of zero-day vulnerabilities in cybersecurity initiative
Anthropic unveiled a preview of Mythos, a frontier model it claims is the most powerful in its Claude lineup, for use in Project Glasswing—a cybersecurity initiative with 40+ partner organizations. According to Anthropic, Mythos identified thousands of zero-day vulnerabilities, many critical and up to two decades old, during early testing. The model will not be made generally available and is restricted to defensive security work by vetted partners.
Anthropic Previews Mythos Frontier Model for Cybersecurity Initiative
Anthropio on Tuesday released a limited preview of Mythos, claiming it as the most powerful model in its Claude AI lineup, exclusively for cybersecurity applications through a new program called Project Glasswing.
The model will be deployed by more than 40 partner organizations—including Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks—for defensive security work and vulnerability identification in first-party and open-source software systems.
Vulnerability Claims
According to Anthropic, Mythos identified "thousands of zero-day vulnerabilities, many of them critical" within weeks of initial testing. The company claims many of these vulnerabilities date back one to two decades, suggesting the model can surface long-undetected security issues across established codebases.
While the model was not specifically trained for cybersecurity work, Anthropic positions it as a general-purpose frontier model with "strong agentic coding and reasoning skills" suitable for complex tasks including agent-building and coding-related security analysis.
Limited Availability and Governance
Anthropio made clear that Mythos will not be made available to the general public. Partner organizations participating in Project Glasswing are expected to share their findings with the broader tech industry to advance collective cybersecurity knowledge.
The company also claims to be in "ongoing discussions" with federal officials regarding Mythos deployment. These discussions occur amid an active legal dispute between Anthropic and the Trump administration, which labeled the company a supply-chain risk after Anthropic refused to enable autonomous targeting or surveillance capabilities.
Background and Leak Context
Details about Mythos emerged following a data security incident last month in which a draft blog post and related documentation were left accessible in an unsecured cache. The leak, which Anthropic attributed to "human error," contained the model's original codename: "Capybara."
The exposed documentation stated that the model was "larger and more intelligent than our Opus models" and described it as "by far the most powerful AI model we've ever developed." The leak also noted potential dual-use risks, acknowledging that adversaries could theoretically weaponize the model to discover vulnerabilities rather than patch them.
This incident compounds recent operational security challenges. In March, Anthropic accidentally exposed nearly 2,000 source code files and over half a million lines of code through a mistake in the Claude Code software package version 2.1.88. The subsequent cleanup effort inadvertently triggered mass removal of thousands of code repositories on GitHub.
What This Means
Anthropio is positioning Mythos as a specialized frontier model for high-stakes defensive security applications rather than general-purpose use. The restricted preview with vetted partners resembles a staged rollout approach common for models with dual-use risk potential. The vulnerability claims, if independently verified, would represent meaningful security impact; however, the lack of public benchmarks or third-party validation means claims about discovery rates remain unverified. The ongoing federal discussions and legal disputes add complexity to what appears to be a deliberate, security-conscious deployment strategy for its most powerful model to date.
Related Articles
Anthropic unveils Claude Mythos model, finds thousands of OS vulnerabilities via Project Glasswing
Anthropic has unveiled Claude Mythos, a new AI model designed for cybersecurity that has already discovered thousands of high-severity vulnerabilities in every major operating system and web browser. The model is being distributed as a preview to over 40 organizations and major technology partners including Apple, Google, Microsoft, and Amazon Web Services through Project Glasswing, a coordinated cybersecurity initiative.
Anthropic withholds Mythos Preview model due to advanced hacking capabilities
Anthropic is rolling out its Mythos Preview model only to a handpicked group of 40 tech and cybersecurity companies, withholding public release due to the model's sophisticated ability to find tens of thousands of vulnerabilities and autonomously create working exploits. The model found bugs in every major operating system and web browser during testing, including vulnerabilities decades old and undetected by human security researchers.
Anthropic Python SDK v0.90.0 adds Claude Mythos preview support
Anthropic released version 0.90.0 of its Python SDK on April 7, 2026, adding support for the claude-mythos-preview model. The update also includes a bug fix for query parameter merging in the client.
AMD AI director reports Claude Code performance degradation since March update
Stella Laurenzo, director of AI at AMD, filed a GitHub issue documenting significant performance degradation in Claude Code since early March, specifically following the deployment of thinking content redaction in version 2.1.69. Analysis of 6,852 sessions with 234,760 tool calls shows stop-hook violations increased from zero to 10 per day, while code-reading behavior dropped from 6.6 reads to 2 reads per session.
Comments
Loading...