Click any tag below to further narrow down your results
Links
Anthropic’s new Claude Mythos Preview model can autonomously find and exploit zero-day and N-day vulnerabilities across major OSes and browsers. In testing, it produced sophisticated exploits—from JIT heap sprays to multi-packet ROP chains—and outperformed prior models by a wide margin. Project Glasswing will share these capabilities with select partners to shore up defenses before wider release.
- Claude Mythos Preview autonomously found and exploited a 27-year-old OpenBSD bug and chained four browser flaws into a JIT heap spray exploit, plus RCE on FreeBSD's NFS server via a 20-gadget ROP chain split across packets
- On Firefox JS engine trials, it produced 181 working shell exploits versus Opus 4.6's 2 successes in hundreds of attempts
- On OSS-Fuzz benchmarks (~7,000 entry points), it achieved full control-flow hijack (tier 5) on ten patched targets, where prior models never exceeded a single tier 3 crash
- These exploitation abilities emerged as a side effect of general code reasoning improvements, not targeted exploit training, prompting Anthropic to share the model early with defenders via Project Glasswing
Anthropic is holding back its new AI model, Claude Mythos Preview, and teaming up with over 40 tech firms to hunt and patch security flaws in critical software. The company says the model can autonomously find zero-day vulnerabilities that have eluded researchers for decades, raising fresh concerns about AI-driven cyberattacks.
- Anthropic is withholding public release of Claude Mythos Preview and instead giving early access to ~40 companies (Apple, Amazon, Microsoft, Google, Cisco, Broadcom, Linux Foundation) under "Project Glasswing," backed by up to $100 million in usage credits, to find and patch critical software vulnerabilities first.
- The model has reportedly found a 27-year-old vulnerability in OpenBSD and a flaw in video software that survived five million automated scans, using simple prompts to autonomously hunt zero-days.
- Anthropic frames this as a security "reckoning" while simultaneously racing toward projected revenue of $30 billion this year, mirroring the tension of building powerful AI it also warns could enable dangerous cyberattacks.