Anthropic says its Mythos model autonomously found thousands of previously unknown zero-day vulnerabilities and produced working exploits on first attempts in more than 83% of cases. About 40 vetted organisations given access under Project Glasswing are now urging pooled, AI-driven defences to patch widely used software at scale — a push sharpened after a vendor-related breach exposed a preview on launch day.

Limited rollout, large capabilities Anthropic opened Mythos to a tightly controlled cohort through Project Glasswing rather than releasing it publicly. The aim was defensive: the company invited major cloud, hardware and security vendors and some financial firms to test the model's ability to find and fix bugs before adversaries could weaponize them. Anthropic described internal tests in which Mythos autonomously discovered thousands of previously unknown zero-day vulnerabilities across major operating systems and web browsers. According to Anthropic, when asked to craft working exploits the model succeeded on first attempts in more than 83% of cases. In one test it chained multiple flaws to escape both renderer and operating system sandboxes — a task that typically requires months of expert work. Launch partners named in company materials and reporting include: - Amazon Web Services - Apple - Broadcom - Cisco - CrowdStrike - Google - JPMorgan Chase - the Linux Foundation - Microsoft - Nvidia - Palo Alto Networks Anthropic also pledged up to US$100 million in Mythos usage credits and US$4 million in donations to open-source security organisations to support defensive efforts. Vendor breach raises access and control questions On the same day Anthropic unveiled Project Glasswing, a small group of users reportedly gained unauthorised entry to the Mythos preview by guessing the model's URL in a third-party vendor environment and then used it regularly. Anthropic said it's investigating the access and has found no evidence that the event affected its core systems. Reporting indicates that an individual employed by a contractor working with Anthropic may have helped the breach. The incident underlines the difficulty of limiting access to powerful tools through partner environments rather than through hardened technical controls and air-gapped systems. Security lawyers and industry officials say the episode shows how quickly defensive plans can be complicated if controls fail. "You don't want to be the organization that falls behind when you're dealing with attackers that can exploit the fact that you've fallen behind at scale and at speed," said Justin Herring, partner at Mayer Brown and former cyber official at the New York Department of Financial Services. Companies pressing for pooled defences and shared playbooks Executives and cyber teams inside the organisations with Mythos access are increasingly treating the model as a collective resource to protect shared infrastructure. Anthropic designed Project Glasswing to let a group of vetted partners test the model on widely used software and cloud platforms so patches can be developed and pushed before attackers find the same flaws. Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, urged defenders to adopt AI now rather than cede ground to attackers. "If we don't use it, the attackers will," she said, arguing that security teams need to include AI tools in their set of tools to keep up. Jen Easterly, former director of the Cybersecurity and Infrastructure Security Agency, framed the issue as strategic. She said cyber and AI have become inseparable and that boards and CEOs can't treat AI strategy and cyber strategy as separate conversations. "You can't have effective cyber capabilities without AI," she said. If partners treat Mythos as a shared defensive scanner, it could compress the window between discovery and patching — shortening the time attackers have to weaponize flaws and making coordinated updates more effective. The vendor breach, however, highlights the trade-off: concentrating powerful exploit knowledge among a small group can heighten access-control and oversight risks if partner environments aren't tightly secured.

Related Articles

Anthropic has pledged up to US$100 million in Mythos usage credits and US$4 million in donations to open-source security groups; partner firms, regulators and governments are pressing for coordinated, AI-driven defences to accelerate patching at scale and blunt attackers' asymmetric advantage.

This article was created with AI assistance.