Don’t do SECURITY. Do business SECURELY.
Threat intel

Anthropic withholds Claude Mythos model over its hacking capabilities

Anthropic says its Claude Mythos Preview model can find serious software flaws at scale and gives access only to selected defenders through Project Glasswing.

AI company Anthropic announced Claude Mythos Preview, a model it said was so effective at finding and exploiting software vulnerabilities that it would not release it to the public. Instead it launched Project Glasswing, giving restricted access to organisations that maintain critical software.

What happened

  • Launch partners included AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks, with over 40 more organisations given access.
  • Anthropic said the model had found thousands of zero-day vulnerabilities, including a 27-year-old flaw in OpenBSD and serious Linux kernel bugs.
  • It committed US$100m in usage credits and US$4m in donations to open source security organisations.
  • Finance ministries, central banks, and regulators in several countries held meetings with banks about the implications.

Why it mattered

It was the clearest sign yet that frontier AI could shift the balance between attackers and defenders, and it put pressure on organisations to fix vulnerabilities much faster.

Lessons for organisations

Assume vulnerabilities in widely used software will be found and exploited faster, so shorten patching cycles and reduce internet exposure. Consider how AI tools can help your own teams find and fix flaws first.

Sources: Anthropic, Euronews

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights