Skip to content
Research

Security & Compliance

Mythos and zero-day reports: an action checklist for software owners

Amulet AI
3 min read

A report of newly discovered vulnerabilities is a reason to check your software and supplier notices, not proof that your business has been compromised. We recommend giving a named security owner questions about each asset rather than demanding the same action on every system.

What was reported

Anthropic's 7 April 2026 Project Glasswing announcement said Mythos Preview had identified previously unknown vulnerabilities and described selected organisations using the model for defensive security work. That is attributed developer evidence, not a scan of your environment.1

The company published an initial update on 22 May 2026. It explained that public vulnerability disclosure lags discovery while issues are verified and patched. This is an available follow-up; the earlier future-looking expectation of a July report is not retained as if it were still ahead.20

Ask these questions now

This operational checklist is a recommendation, not a completed security test:

  • Do we operate the affected product and version, or does a supplier operate it for us?
  • Is there a relevant official advisory, and what does it say about exposure, severity and exploitation?
  • Is a vendor update or mitigation available? Who can approve and carry it out?
  • What evidence will show it is installed or effective on the actual asset?
  • If it cannot be applied promptly, who approves the exception, compensating controls and next review?
  • Who confirms the business service still works after the change, and who owns recovery if it does not?

Use the vendor's instructions and your applicable security requirements. ASD's Essential Eight model distinguishes requirements by system and vulnerability conditions and calls for a risk-based implementation with documented exceptions. It does not support a universal patch deadline inferred from a model announcement.6

Avoid two shortcuts

Do not replace a tested patch process with an unverified AI security tool. If you evaluate one, define the authorised scope and have a qualified security professional validate its findings. Require evidence for a generated finding, and review and relevant testing for a generated fix.

Do not assume that a vendor saying an issue is fixed means every copy in your organisation has been updated. Ask for the actual asset-level result and preserve failures instead of closing the record early.

The no-new-tool option is to improve the asset register, advisory monitoring and installation verification you already use. For a fuller framework, see the Mythos cybersecurity decision guide.

For operational workflow scoping alongside your security provider, talk with Amulet.

Evidence checked on 15 September 2026; original publication date retained. Prepared with AI assistance. Amulet AI is responsible for this proposed correction. No worldwide expertise estimate, universal scanner limitation, Amulet security guarantee or client test result is claimed.

Sources

[1] https://www.anthropic.com/glasswing — Project Glasswing: Securing critical software for the AI era
[6] https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model — Essential Eight maturity model
[20] https://www.anthropic.com/research/glasswing-initial-update — Project Glasswing: An initial update

A practical next step

Put AI to work with the operating boundary visible.

Approvals, evidence and the rollout path should be mapped to the real workflow.

Explore Delivery