Anthropic's most advanced AI model has already identified thousands of cybersecurity vulnerabilities across all major operating systems and web browsers. The company chose not to release it publicly, instead discreetly providing it to the organizations responsible for maintaining critical internet infrastructure.
That model is Claude Mythos Preview, and the initiative is known as Project Glasswing.
The launch partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks.
Beyond this core group, Anthropic has granted access to over 40 additional organizations that develop or maintain essential software infrastructure. Anthropic is committing up to $100 million in usage credits for Mythos Preview as part of this effort, along with $4 million in direct donations to open-source security organizations.
A model that outgrew its own benchmarks
Mythos Preview was not specifically trained for cybersecurity tasks. Anthropic stated that its capabilities "emerged as a downstream consequence of general improvements in code, reasoning, and autonomy," noting that the same advancements that make the model better at patching vulnerabilities also enhance its ability to exploit them.
This last point is significant. Mythos Preview has improved to the point where it largely saturates existing security benchmarks, compelling Anthropic to shift its focus to novel real-world tasks–specifically, zero-day vulnerabilities. These are flaws previously unknown to the software's developers.
Among the discoveries: a 27-year-old bug in OpenBSD, an operating system renowned for its strong security. In another instance, the model autonomously identified and exploited a 17-year-old remote code execution vulnerability in FreeBSD–CVE-2026-4747–which allows an unauthenticated user anywhere on the internet to gain complete control of a server running NFS. No human was involved in the discovery or exploitation after the initial prompt to find the bug.
Nicholas Carlini from Anthropic's research team described the model's ability to chain vulnerabilities together: "This model can create exploits by combining three, four, or sometimes five vulnerabilities in sequence to achieve a highly sophisticated outcome. I've found more bugs in the last couple of weeks than I have in the rest of my career combined."
Why is it not being released?
"We do not plan to make Claude Mythos Preview generally available due to its cybersecurity capabilities," said Newton Cheng, Frontier Red Team Cyber Lead at Anthropic. "Given the rapid pace of AI progress, it won't be long before such capabilities proliferate, potentially reaching actors who are not committed to deploying them safely. The fallout–for economies, public safety, and national security–could be severe."
This concern is not hypothetical. Anthropic had previously disclosed what it described as the first documented case of a cyberattack largely executed by AI–a Chinese state-sponsored group that used AI agents to autonomously infiltrate roughly 30 global targets, with AI handling the majority of tactical operations independently.
The company has also privately briefed senior US government officials on Mythos Preview's full capabilities. The intelligence community is now actively assessing how the model could reshape both offensive and defensive hacking operations.
The open-source problem
One aspect of Project Glasswing that extends beyond the headline coalition is its focus on open-source software. Jim Zemlin, CEO of the Linux Foundation, stated plainly: "In the past, security expertise has been a luxury reserved for organizations with large security teams. Open-source maintainers, whose software underpins much of the world's critical infrastructure, have historically been left to figure out security on their own."
Anthropic has donated $2.5 million to Alpha-Omega and OpenSSF through the Linux Foundation, and $1.5 million to the Apache Software Foundation–providing maintainers of critical open-source codebases access to AI-powered cybersecurity vulnerability scanning at a scale previously out of reach.
What comes next
Anthropic says its long-term goal is to deploy Mythos-class models at scale, but only when new safeguards are firmly in place. The company plans to introduce these new safeguards first with an upcoming Claude Opus model, allowing it to refine them with a model that does not pose the same level of risk as Mythos Preview.
The competitive landscape is already shifting around this development. When OpenAI released GPT-5.3-Codex in February, the company called it the first model it had classified as high-capability for cybersecurity tasks under its Preparedness Framework. Anthropic's move with Glasswing signals that leading AI labs view controlled deployment–not open release–as the emerging standard for models at this capability level.
Whether that standard holds as these capabilities become more widespread is, at this point, an open question that no single initiative can definitively answer.
See Also: Anthropic’s refusal to arm AI is exactly why the UK wants it
Want to learn more about AI and big data from industry leaders? Check out the AI & Big Data Expo taking place in Amsterdam, California, and London. This comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Anthropic Enters AI Legal Tech Market as Competition IntensifiesAnthropic unveiled a suite of new chatbot capabilities on Tuesday, aimed at delivering automated support to legal practices. These enhancements expand upon Claude for Legal, the firm-specific platform introduced earlier this year, by adding specializ
OpenAI Closes Gap With Anthropic Among Business Users, New Data ShowsWith OpenAI and Anthropic still distant from their anticipated IPOs and the release of detailed financial reports, we must turn to alternative indicators to gauge their business performance. Ramp, a corporate credit card and expense management platfo
2026 Latest Best Top-rated AI SERP Analysis Tools for Search Strategy are curated by XIX.AI through rigorous real-world tests and weekly updated rankings. These powerful tools help you unlock hidden optimization opportunities, boost content performance, and gain a competitive edge in search. Discover your perfect tool to elevate your search strategy today. Explore now!
2026 Latest Best Top-rated AI Anomaly Detection Tools for KPI Monitoring in SaaS and Ecommerce teams! XIX.AI has curated a powerful, game-changing collection based on rigorous real-world tests and weekly updated rankings. You’ll find detailed free vs paid comparison insights to help you identify the must-try solution that boosts productivity and unlocks your AI edge. Explore now!
2026 Latest Best Top-Rated AI Outline Generators for Long-Form SEO Articles, meticulously curated by XIX.AI. These powerful tools offer game-changing assistance in creating high-quality content quickly, boosting writing efficiency significantly. Get a free vs paid comparison along with real-world tests and detailed rankings to help you find the must-try option that suits your needs. Explore now to unlock your AI edge.
2026 Latest Best AI Study Tools for Homework and Exam Prep! XIX.AI curates a top-rated list of powerful, game-changing tools that help students boost productivity, streamline homework completion, and ace exams through real-world tests. Get a free vs paid comparison, detailed rankings, and must-try options to unlock your AI edge. Explore now!
2026 Latest Best AI Vocal Demo Tools for Songwriters, Hook Creators, and Multi-Language Content Teams! XIX.AI has curated a top-rated list of powerful game-changing tools that go through rigorous real-world tests. You’ll find detailed free vs paid comparison data, comprehensive rankings, and must-try options to help you boost writing efficiency and unlock your creative potential. Explore now to discover your perfect tool for all your content needs!
2026 Latest Best Top-rated AI Competitive Research Tools for Small Businesses! XIX.AI has curated a highly powerful game-changing collection, updated weekly with rigorous real-world tests and detailed rankings. You can find a comprehensive free vs paid comparison to help you identify the must-try tools that boost your productivity and give you a competitive edge. Explore now to discover your perfect tool!
Anthropic's move to keep their top-tier AI under wraps after spotting thousands of OS and browser bugs is pretty bold. It shows they're prioritizing quality over the hype cycle, but I wonder if this 'discreet release' strategy will actually speed up real-world fixes or just create more confusion for enterprises waiting for a public rollout. Either way, it's a fascinating case study in AI safety vs. speed.
By clicking "Accept All Cookies", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.Privacy Policy Notice
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings.However, blocking some types of cookies may impact your experience of the site and the services we are able to offer. Privacy PolicyStatement
Manage Preferences
Strictly Necessary Cookie
Always Active
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.