On April 7, 2026, Anthropic unveiled Claude Mythos, a new frontier AI model, alongside Project Glasswing, a defensive initiative to mitigate its risks.
Claude Mythos: The “Zero-Day Machine”
Claude Mythos (specifically the Mythos Preview version) is a reasoning-oriented AI model described by Anthropic as a “watershed moment” for cybersecurity. It possesses an “unprecedented” ability to autonomously identify and exploit software vulnerabilities at machine speed.
Capabilities: Mythos can read code, hypothesize attack vectors, and generate working exploits without human intervention. In testing, it achieved a 72% exploit success rate.
Vulnerability Discovery: The model autonomously discovered thousands of high-severity zero-day vulnerabilities across major operating systems and web browsers.
Notable Finds:
- An estimated 27-year-old remote code execution (RCE) flaw in OpenBSD
- A 16-year-old vulnerability in FFmpeg that had eluded automated testing tools despite 5 million previous checks
- 271 vulnerabilities identified in Firefox 150, though Mozilla characterized these as discoverable by “elite human researchers” rather than entirely superhuman
Project Glasswing: A Defensive Coalition
Due to the significant potential for misuse by threat actors, Anthropic decided not to publicly release Claude Mythos. Instead, they launched Project Glasswing, a consortium involving 12 major tech giants and over 40 organizations.
Partners: Key partners include AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, and the Linux Foundation.
Mission: Glasswing aims to leverage Mythos for defensive purposes, allowing partners to scan their own infrastructure and open-source projects for vulnerabilities and patch them proactively.
Funding: Anthropic committed 4 million in donations to open-source security organizations to support independent maintainers.
Cybersecurity Implications
The advent of Mythos-class models has ignited debate about an impending “AI Vulnerability Storm”:
- Collapsing Patch Windows: Experts warn that the time available for patching vulnerabilities before they are exploited is shrinking dramatically, from weeks to mere hours.
- Dual-Use Risk: Despite Glasswing’s defensive focus, concerns persist that similar AI capabilities could emerge in open-source or adversary-controlled models, potentially overwhelming traditional, human-paced security responses.
- Unauthorized Access: Shortly after its announcement, reports indicated unauthorized access to Mythos Preview via a third-party vendor (Mercor) following a data breach, highlighting the challenges of securing such powerful technologies.