Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ai-platform-securityai-enabled-threat-activityindustrial-control-system-vulnerabilityopen-source-dependency-vulnerability

Anthropic Mythos Raises Alarm With Rapid Gains in AI Cyber Capability

Updated 2d agoFirst seen May 14, 202610 sources

Anthropic’s Claude Mythos Preview has been rolled out to a limited set of major technology and infrastructure firms under Project Glasswing, where partners including Amazon, Apple, Microsoft, Cisco, CrowdStrike, Palo Alto Networks, Broadcom, and the Linux Foundation are using it for defensive security work such as vulnerability discovery in first-party and open-source software. Anthropic said the model found thousands of high-severity and zero-day vulnerabilities, while Mozilla reported Mythos identified 271 Firefox flaws, far above the 22 bugs previously found with an earlier Anthropic model. Mozilla said the findings suggest AI-assisted code reasoning is approaching the breadth of elite human vulnerability research, even if the bugs themselves were still understandable to human experts.

Separate findings from the UK’s AI Security Institute (AISI) indicate that frontier models’ autonomous cyber capabilities are advancing faster than earlier forecasts and that common evaluation methods may be understating their performance. AISI reported the 80%-reliability cyber time horizon has been doubling every 4.7 months since late 2024, with Claude Mythos Preview and GPT-5.5 outperforming that trend, and said Mythos became the first model to complete both evaluated enterprise cyber ranges, including the previously unsolved industrial-control scenario Cooling Tower. AISI also found that larger inference budgets—up to 50 million tokens or 1,000 turns—unlock materially higher success rates on difficult cyber tasks, reinforcing concerns that increasingly capable AI systems could strengthen defenders while also lowering the barrier to advanced offensive cyber operations if access is not tightly controlled.

Share:
Anthropic Mythos Raises Alarm With Rapid Gains in AI Cyber Capability
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 2, 202629d ago

Anthropic expands Project Glasswing to 150+ organizations in 15+ countries

Anthropic announced a major expansion of Project Glasswing, extending Claude Mythos access to roughly 150 additional organizations across more than 15 countries. The expanded partner set includes critical infrastructure and widely relied-on technology organizations in sectors such as power, water, healthcare, communications, and hardware.

Anthropic scales Claude Mythos to critical infrastructure in 15+ countries | TechCrunch
May 14, 20262mo ago

AISI reports Mythos and GPT-5.5 surpass prior cyber capability trend

AISI reported that Claude Mythos Preview and GPT-5.5 had recently exceeded the institute's prior cyber capability trendline, with both models achieving near-100% success on the longest tasks in its limited test suite. In simulated enterprise attack environments, Mythos also became the first model to complete both evaluated cyber ranges, including the previously unsolved 'Cooling Tower' industrial control system scenario.

May 13, 20262mo ago

AISI observes faster-than-expected gains in AI cyber task performance

Since late 2024, the UK AI Security Institute said the 80%-reliability cyber time horizon for frontier models had been doubling every 4.7 months, faster than its earlier projection of 8 months from November 2025. This trend later became the basis for AISI's warning that cyber-capable AI was advancing more quickly than expected.

Apr 28, 20262mo ago

White House convenes meeting on Mythos cybersecurity concerns

A White House meeting chaired by National Cyber Director Sean Cairncross was expected to bring together technology and cybersecurity firms to discuss AI, cybersecurity, and concerns about Anthropic's Mythos model and its advanced hacking potential. The report also said Anthropic CEO Dario Amodei had recently met senior administration officials about the model.

White House meets with tech, cyber firms over Mythos concerns - POLITICO
Apr 22, 20262mo ago

Mozilla says Mythos found 271 Firefox 150 vulnerabilities

Mozilla disclosed that testing Anthropic's Mythos on Firefox 150 produced 271 vulnerability findings, far more than the 22 bugs previously found with Anthropic's Opus 4.6 on Firefox 148. Mozilla said the result showed AI-assisted code reasoning could materially improve defensive software security.

Apr 7, 20263mo ago

U.S. tech firms discuss Mythos national security implications with administration

Following Mythos's demonstrated vulnerability-finding capability, leading technology companies privately discussed its national security implications with the Trump administration. The discussions centered on the risks of misuse and the need to protect critical infrastructure.

Anthropic launches Project Glasswing with limited Mythos preview

Anthropic announced a restricted preview of Claude Mythos Preview under Project Glasswing, giving about 40 major technology and infrastructure organizations access for defensive cybersecurity work. Named partners included firms such as Amazon, Apple, Microsoft, Cisco, CrowdStrike, Palo Alto Networks, Broadcom, and the Linux Foundation.

Anthropic's Mythos finds thousands of severe software vulnerabilities

In the month before its April 2026 announcement, Anthropic said Claude Mythos Preview identified thousands of high-severity and zero-day vulnerabilities across major operating systems, browsers, and other software. The company presented this as evidence of a major advance in AI-assisted defensive security.

Mar 5, 20264mo ago

AISI publishes findings that larger inference budgets boost cyber eval success

AISI and Irregular reported that frontier models released around November 2025 achieved higher success rates on cyber tasks when allowed much larger token, turn, time, or cost budgets. The March 5 publication said some previously unsolved tasks were solved for the first time only under expanded evaluation budgets.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

41 LINKEDOpen in app
Affected products
1 linked
Firefox
Organizations
39 linked
MozillaAnthropicLinux FoundationCisco SystemsAmazon Web ServicesPalo Alto NetworksSamsung ElectronicsOktaCloudflareCrowdStrikeOpenaiAppleSK HynixBroadcomMicrosoft CorporationSK TelecomNew York Stock ExchangeGoogleNvidiaProCircularTechCrunchFinancial TimesTikTokMeta PlatformsGitHubCobaltJPMorgan ChaseForbesBloombergFortuneExabeamPoliticoThe AtlanticThe New York Times CompanyThe Daily BeastGizmodoIrregularModel Evaluation and Threat ResearchBluesky PBLLC
Breaches
1 linked
ANTHROPIC-2026-04
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.