Skip to content
Research

Cybersecurity

Claude Mythos and the End of Security Through Obscurity: What Anthropic's Vulnerability-Finding AI Means for Every Software Team

Amulet Research
6 min read

On April 7, 2026, Anthropic announced Project Glasswing — a coalition including AWS, Microsoft, Google, Apple, CrowdStrike, Cisco, Palo Alto Networks, NVIDIA, Broadcom, JPMorganChase, and the Linux Foundation. The centrepiece: Claude Mythos Preview, an unreleased frontier model that has autonomously discovered thousands of zero-day vulnerabilities in every major operating system and every major web browser.

This is not a research paper about theoretical risk. Mythos Preview found a 27-year-old vulnerability in OpenBSD — one of the most security-hardened systems ever built. It found a 16-year-old bug in FFmpeg that automated testing tools had hit five million times without flagging. It autonomously chained multiple Linux kernel vulnerabilities into a full privilege escalation exploit.

The implications are structural, not incremental.


What Actually Happened

Mythos Preview is a general-purpose frontier model. Anthropic didn't explicitly train it for security exploitation — the capabilities emerged from improvements in code reasoning and agentic autonomy. On CyberGym benchmarks, it scores 83.1% on vulnerability reproduction versus 66.6% for Claude Opus 4.6. On SWE-bench Verified, it hits 77.8% versus 53.4%.

The practical difference is starker than benchmarks suggest. When researchers at Anthropic pointed Mythos at Firefox's JavaScript engine and asked it to develop working exploits from vulnerabilities it had previously found, it succeeded 181 times across several hundred attempts. Opus 4.6 managed two.

Non-security engineers at Anthropic asked the model to find remote code execution vulnerabilities overnight. They woke up to complete, working exploits.

Anthropic is not releasing this model publicly. Access is limited to Glasswing partners and over 40 additional organisations maintaining critical software infrastructure. The pricing for participants after the initial $100M in usage credits: $25/$125 per million input/output tokens.


Why This Changes the Threat Calculus

Three dynamics shift simultaneously.

1. The expertise floor collapses

Finding exploitable vulnerabilities in hardened systems has historically required world-class talent — a few hundred people globally. Mythos-class models compress that expertise into an API call. The question is no longer whether sophisticated exploits will proliferate, but how fast, and who gets access first.

2. The time-to-exploit window closes

CrowdStrike's statement in the Glasswing announcement put it directly: "The window between a vulnerability being discovered and being exploited by an adversary has collapsed — what once took months now happens in minutes with AI." Patch cadence that was adequate in 2024 is now dangerously slow.

3. Historical security debt gets repriced

Software that has "survived decades of review" is not safe — it's untested against this class of capability. Mythos found bugs that five million fuzzer runs missed. The assumption that well-audited code is reasonably secure needs revision.


The Defender's Advantage Is Conditional and Temporary

Anthropic's framing is deliberately optimistic: defenders should benefit more than attackers in the long run. Their logic tracks with history — fuzzers initially worried the security community, but AFL and OSS-Fuzz became critical defensive infrastructure. The same pattern could hold for AI-augmented vulnerability discovery.

But Anthropic is careful to flag the transition period. Their Red Team blog states: "In the short term, this could be attackers, if frontier labs aren't careful about how they release these models." The asymmetry is real: defenders need to find and fix every vulnerability; attackers need to find one.

The Glasswing coalition is an attempt to buy time — give defenders a head start with restricted access before similar capabilities become broadly available. Whether that window is six months or eighteen is an open question. Model capabilities are advancing rapidly, and Anthropic's own statement notes that "it will not be long before such capabilities proliferate."


Concrete Implications for Security Teams

Patch velocity becomes existential

If AI models can autonomously discover and exploit zero-days in hours, the standard 30-90 day patch cycle is a liability. Organisations need to compress time-to-patch or accept that known-vulnerable systems will be exploited faster than they can respond.

Automated security scanning needs to upgrade, fast

Traditional SAST/DAST tools are not designed to reason about vulnerabilities the way Mythos does. The model doesn't just pattern-match known vulnerability types — it reads code, forms hypotheses, writes test cases, debugs, and iterates. Security tooling vendors will need to integrate model-driven analysis or risk obsolescence.

Memory-unsafe codebases are repriced

Mythos's strongest results are against C/C++ systems. The already-strong argument for migrating critical infrastructure to memory-safe languages (Rust, Go) becomes significantly more urgent. The US government has been pushing this for two years; Mythos provides the concrete threat model.

Open-source security becomes a boardroom concern

Anthropic committed $4M to open-source security organisations and is offering credits via a Claude for Open Source program. This is acknowledgement that open-source maintainers — often under-resourced volunteers — are responsible for software that underpins nearly all modern systems. Enterprises that depend on open-source components need to fund their security or accept the compounding risk.

Red teaming budgets go up, hiring gets harder

Organisations that were previously too small or too niche to justify formal red teaming now have a reason — and potentially the tooling — to conduct it. But the best human security researchers become even more valuable as the people who can direct, validate, and build on top of AI-generated findings.


Where Agentic AI Platforms Fit

This is where the landscape gets commercially interesting for companies building agentic systems.

If AI agents are going to operate with increasing autonomy — executing code, accessing APIs, managing infrastructure, handling sensitive data — the security requirements for those agents are about to be tested by a class of threat that didn't exist twelve months ago. Every agentic platform that touches enterprise infrastructure needs to answer: what happens when a Mythos-class model is pointed at your agent's execution environment?

For platforms like Amulet that are building agentic AI for sensitive work — with Australian data residency posture, auditability, and Essential Eight-aligned operating controls — the Glasswing announcement reframes the value proposition. It's not just about whether your AI is smart. It's about whether your AI's runtime, data handling, and integration surface can withstand probing by something that finds zero-days in OpenBSD.

The companies that treat security as infrastructure rather than a feature checkbox will have a meaningful moat. That was already true. Mythos makes it urgent.


What Happens Next

Anthropic committed to publishing a public report within 90 days on what Glasswing has found and fixed. That report — expected around early July 2026 — will be the first real data point on how effectively a coordinated AI-augmented defence effort works at scale.

In the meantime, the practical question for every CTO and CISO is not whether to react, but how fast. The vulnerability surface of your systems hasn't changed. The cost of discovering it has dropped by orders of magnitude.


Where Amulet Fits

Most businesses do not need the most dangerous model in the world. They need an agent they can trust with real work. That means secure execution, strong auditability, data sovereignty, and workflows built for business outcomes, not demos.

If you are thinking through what agentic AI looks like inside a real company, Amulet is building for that future.

A practical next step

Put AI to work with the operating boundary visible.

Approvals, evidence and the rollout path should be mapped to the real workflow.

Explore Delivery