12 Sources
[1]
Anthropic to release Mythos-class models to the public
Anthropic has revealed its intention to one day release models that match the performance of its Mythos bug-finding AI to the public, once it can make them safe. In case you came in late, in early April Anthropic announced it had developed a model called Mythos that is so good at finding security
[2]
Anthropic confirms Claude Mythos-class models will roll out to the public
Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software. Mythos was announced in April as a restricted model and was made available only to select companies, including security
[3]
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is an effort led
[4]
Anthropic says Mythos has already found more than 10,000 vulnerabilities - Engadget
The company has published an update about Project Glasswing, a month after its launch. Anthropic has published an initial report for Project Glasswing, the cybersecurity initiative it launched in April that aims to prevent AI cyberattacks with, well, AI. The initiative is powered by Claude Mythos
[5]
Anthropic's restricted Claude Mythos model may be coming to Claude Code
Anthropic appears to be preparing for the public rollout of "Mythos," which was announced in April as a restricted model that poses major security risks to private and public software. On April 7, Anthropic announced the Mythos in early preview and called it a new frontier model with strikingly
[6]
Anthropic's Claude Mythos might get public release
Anthropic has announced plans to eventually release a public version of Mythos, its AI model with advanced cybersecurity capabilities. First, the AI company needs to develop adequate safeguards, which, by its own admission, don't yet exist. The company revealed in an update to Project Glasswing,
[7]
'After one month, most partners have each found hundreds of critical- or high-severity vulnerabilities': Anthropic claims Mythos has found over ten thousand major security vulnerabilities across 'the most systemically important software in the world'
* Anthropic reported Mythos Preview uncovered over 10,000 high‑ and critical‑severity vulnerabilities in under two months, with Cloudflare alone finding 2,000 bugs * Independent validation confirmed 90% of assessed findings as real, though critics argue the breakthrough may stem from massive
[8]
A Complete Breakdown of the Claude Mythos 1 Leak and Features
The recent leak of Claude Mythos 1 has provided a rare look at Anthropic's advanced AI model, sparking discussions about its potential applications and implications. In a detailed hands-on review, World of AI examines the leaked outputs, including standout examples like solving Erdos Problem 90, a
[9]
Expansion Of Mythos-Level LLMs Makes Exploitability The Key Focus: CISO
The expected spread of frontier AI capabilities for vulnerability discovery such as Anthropic's Claude Mythos means that organizations will need to prioritize patching based on the exploitability of software flaws, Optiv's Rob Gregory tells CRN. The expected spread of frontier AI capabilities for
[10]
Anthropic's Project Glasswing Finds 'More Than 10,000' Critical Bugs, Expands To Additional Partners
Anthropic shared a sweeping update on Project Glasswing, saying its artificial intelligence-assisted security testing effort has already uncovered "more than 10,000 high-or critical-severity vulnerabilities" across widely used software systems. Several partner organizations reported that they saw
[11]
Anthropic Says Mythos Has Uncovered More Than 10K Vulnerabilities | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. That's according to a report issued last week by the artificial intelligence
[12]
Anthropic's Claude Mythos Briefly Surfaces Online After Restricted Access Claims
Project Glasswing has become the main reason Claude Mythos is receiving attention. In one month, more than 50 major developers and infrastructure partners reportedly worked with Claude Mythos Preview. The model helped identify over 10,000 high-severity or critical software vulnerabilities. Reports
Share
Copy Link
Anthropic revealed plans to release its restricted Mythos AI model to the public once adequate safeguards are developed. Through Project Glasswing, the model has already uncovered more than 10,000 high-severity flaws across critical software infrastructure in just one month, overwhelming security teams with the sheer volume of bugs requiring patches.
Anthropic has confirmed its intention to release Mythos-class AI models to the general public in the coming weeks, marking a significant shift from its April decision to restrict access due to severe security risks
2
. The company announced it is making swift progress on developing safeguards strong enough to prevent misuse of the Claude Mythos model, which demonstrates major improvements in code reasoning and autonomy far beyond its current flagship model, Opus 4.82
. However, Anthropic acknowledges that "at present, no company -- including Anthropic -- has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm"1
.
Source: PYMNTS
The restricted model, announced in early April, was withheld from public release because of its striking ability to automatically develop functional cyberattacks at a highly professional level
5
. The company warned that the advantage could belong to attackers in the short term if frontier labs aren't careful about releases, though defenders are expected to benefit more efficiently in the long term2
.Through Project Glasswing, Anthropic's cybersecurity initiative launched in April, the Mythos AI has discovered more than 10,000 high- or critical-severity vulnerabilities in just one month
4
. The company used Mythos to scan more than 1,000 open-source projects that collectively underpin much of the internet infrastructure, identifying 6,202 high-or-critical-severity vulnerabilities out of 23,019 total flaws . Of the 1,752 high-or-critical-rated vulnerabilities that went through Anthropic's validation process, 90.6 percent (1,587) proved to be valid flaws, with 62.4 percent (1,094) confirmed as either high-or-critical-severity1
.Partners participating in Project Glasswing have experienced dramatic improvements in bug-finding capabilities. Cloudflare discovered 2,000 bugs, including 400 classified as high or critical in severity
4
. Mozilla reported finding and fixing 271 vulnerabilities in Firefox, representing a tenfold increase compared to what it found in an older browser version using another Claude model4
. The company noted that partners' rate of bug-finding has increased by more than a factor of ten4
.
Source: TechRadar
Among the most significant discoveries, Mythos identified a critical flaw in wolfSSL (CVE-2026-5194, CVSS score: 9.1), a cryptography library used by billions of devices worldwide
3
. Mythos Preview constructed an exploit that would allow an attacker to forge certificates, enabling them to host fake websites for banks or email providers that would appear perfectly legitimate to end users1
. Developers have already patched wolfSSL, and Anthropic plans to deliver a full technical analysis in the coming weeks1
.The model's utility extends beyond finding high-severity flaws in software. In one case, a Glasswing partner bank leveraged the AI model to detect and prevent a fraudulent $1.5 million wire transfer after a threat actor breached a customer's email account and made spoof phone calls
3
. Security research firm XBOW has described Mythos Preview as "a major advance" that's "substantially better than prior models at finding vulnerability candidates" and "adept at analyzing source code with a security mindset"3
.Related Stories
The flood of AI-driven exploits discovered by Mythos is adding to an already overloaded security ecosystem
1
. Of the 530 high-or-critical-severity bugs reported, only 75 have been patched, with 65 receiving public advisories1
. Anthropic attributes this low fix rate to being early in the 90-day window outlined in its Coordinated Vulnerability Disclosure policy, though maintainers have told the company they're severely capacity constrained1
.
Source: The Register
Several maintainers have asked Anthropic to slow down its rate of disclosures because they need more time to design patches
1
. The company acknowledged that "the relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity"3
. Microsoft has noted that the number of new patches it expects to release monthly will "continue trending larger for some time," driven by bugs found through Mythos Preview3
.Anthropic plans to work with critical partners, including US and allied governments, to expand Project Glasswing to additional partners before the general release
1
. The initiative currently works with approximately 50 organizational partners, including Amazon Web Services, Apple, CrowdStrike, Google, JPMorganChase, NVIDIA, and Palo Alto Networks4
. The mere existence of Mythos has sparked international responses, with Japan's government ordering a sweeping security review and Indian authorities demanding a patching spree at financial institutions1
.The company has launched a Cyber Verification Program that allows security professionals to use its models without guardrails for legitimate purposes such as vulnerability research, penetration testing, and red teaming
3
. This approach mirrors OpenAI's Daybreak program, which allows defenders to leverage GPT-5.5-Cyber for specialized workflows3
. Anthropic is urging software developers to shorten their patch cycles and make security fixes available more rapidly, while network defenders should shorten patch testing and deployment timelines3
. References to the claude-mythos-1-preview model have briefly appeared in the public versions of Claude Code and Claude Security, suggesting preparations for broader rollout .Summarized by
Navi
[1]
[2]
[5]
27 Mar 2026•Technology

14 Apr 2026•Technology

14 May 2026•Technology

1
Policy and Regulation

2
Technology

3
Technology
