Anthropic plans public release of Mythos AI after discovering 10,000+ security vulnerabilities

Reviewed byNidhi Govil

12 Sources

Share

Anthropic revealed plans to release its restricted Mythos AI model to the public once adequate safeguards are developed. Through Project Glasswing, the model has already uncovered more than 10,000 high-severity flaws across critical software infrastructure in just one month, overwhelming security teams with the sheer volume of bugs requiring patches.

Anthropic Commits to Public Release of Mythos-Class AI Models

Anthropic has confirmed its intention to release Mythos-class AI models to the general public in the coming weeks, marking a significant shift from its April decision to restrict access due to severe security risks

2

. The company announced it is making swift progress on developing safeguards strong enough to prevent misuse of the Claude Mythos model, which demonstrates major improvements in code reasoning and autonomy far beyond its current flagship model, Opus 4.8

2

. However, Anthropic acknowledges that "at present, no company -- including Anthropic -- has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm"

1

.

Source: PYMNTS

Source: PYMNTS

The restricted model, announced in early April, was withheld from public release because of its striking ability to automatically develop functional cyberattacks at a highly professional level

5

. The company warned that the advantage could belong to attackers in the short term if frontier labs aren't careful about releases, though defenders are expected to benefit more efficiently in the long term

2

.

Project Glasswing Uncovers Massive Scale of Security Vulnerabilities

Through Project Glasswing, Anthropic's cybersecurity initiative launched in April, the Mythos AI has discovered more than 10,000 high- or critical-severity vulnerabilities in just one month

4

. The company used Mythos to scan more than 1,000 open-source projects that collectively underpin much of the internet infrastructure, identifying 6,202 high-or-critical-severity vulnerabilities out of 23,019 total flaws . Of the 1,752 high-or-critical-rated vulnerabilities that went through Anthropic's validation process, 90.6 percent (1,587) proved to be valid flaws, with 62.4 percent (1,094) confirmed as either high-or-critical-severity

1

.

Partners participating in Project Glasswing have experienced dramatic improvements in bug-finding capabilities. Cloudflare discovered 2,000 bugs, including 400 classified as high or critical in severity

4

. Mozilla reported finding and fixing 271 vulnerabilities in Firefox, representing a tenfold increase compared to what it found in an older browser version using another Claude model

4

. The company noted that partners' rate of bug-finding has increased by more than a factor of ten

4

.

Source: TechRadar

Source: TechRadar

Critical Flaws Discovered in Widely-Used Software

Among the most significant discoveries, Mythos identified a critical flaw in wolfSSL (CVE-2026-5194, CVSS score: 9.1), a cryptography library used by billions of devices worldwide

3

. Mythos Preview constructed an exploit that would allow an attacker to forge certificates, enabling them to host fake websites for banks or email providers that would appear perfectly legitimate to end users

1

. Developers have already patched wolfSSL, and Anthropic plans to deliver a full technical analysis in the coming weeks

1

.

The model's utility extends beyond finding high-severity flaws in software. In one case, a Glasswing partner bank leveraged the AI model to detect and prevent a fraudulent $1.5 million wire transfer after a threat actor breached a customer's email account and made spoof phone calls

3

. Security research firm XBOW has described Mythos Preview as "a major advance" that's "substantially better than prior models at finding vulnerability candidates" and "adept at analyzing source code with a security mindset"

3

.

Overwhelming Security Ecosystem Faces Patch Crisis

The flood of AI-driven exploits discovered by Mythos is adding to an already overloaded security ecosystem

1

. Of the 530 high-or-critical-severity bugs reported, only 75 have been patched, with 65 receiving public advisories

1

. Anthropic attributes this low fix rate to being early in the 90-day window outlined in its Coordinated Vulnerability Disclosure policy, though maintainers have told the company they're severely capacity constrained

1

.

Source: The Register

Source: The Register

Several maintainers have asked Anthropic to slow down its rate of disclosures because they need more time to design patches

1

. The company acknowledged that "the relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity"

3

. Microsoft has noted that the number of new patches it expects to release monthly will "continue trending larger for some time," driven by bugs found through Mythos Preview

3

.

Expanding Access Through Government Partnerships and Cybersecurity Measures

Anthropic plans to work with critical partners, including US and allied governments, to expand Project Glasswing to additional partners before the general release

1

. The initiative currently works with approximately 50 organizational partners, including Amazon Web Services, Apple, CrowdStrike, Google, JPMorganChase, NVIDIA, and Palo Alto Networks

4

. The mere existence of Mythos has sparked international responses, with Japan's government ordering a sweeping security review and Indian authorities demanding a patching spree at financial institutions

1

.

The company has launched a Cyber Verification Program that allows security professionals to use its models without guardrails for legitimate purposes such as vulnerability research, penetration testing, and red teaming

3

. This approach mirrors OpenAI's Daybreak program, which allows defenders to leverage GPT-5.5-Cyber for specialized workflows

3

. Anthropic is urging software developers to shorten their patch cycles and make security fixes available more rapidly, while network defenders should shorten patch testing and deployment timelines

3

. References to the claude-mythos-1-preview model have briefly appeared in the public versions of Claude Code and Claude Security, suggesting preparations for broader rollout .

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved