Anthropic's Claude Mythos Finds Over 10,000 Vulnerabilities in Project Glasswing

Anthropic says its unreleased Claude Mythos model found more than 10,000 high-severity vulnerabilities across partner codebases in Project Glasswing, including a 17-year-old FreeBSD flaw it exploited autonomously. The program is expanding to about 150 organizations in 15-plus countries.

Anthropic's Claude Mythos Finds Over 10,000 Vulnerabilities in Project Glasswing
Anthropic's Project Glasswing pairs the Claude Mythos model with major security partners. Image: Anthropic

Key Points

  • Anthropic's unreleased Claude Mythos model found 10,000+ high- or critical-severity flaws.
  • Partners include AWS, Apple, Google, Microsoft, NVIDIA, JPMorganChase and the Linux Foundation.
  • Mythos autonomously found and exploited a 17-year-old FreeBSD flaw, CVE-2026-4747.
  • Project Glasswing is expanding to about 150 organizations across more than 15 countries.

Anthropic says an unreleased model now finds and exploits software vulnerabilities better than nearly any human. Through Project Glasswing, the company and its partners have identified more than 10,000 high- or critical-severity flaws in widely used software, using a frontier model it calls Claude Mythos — a capability the security industry has spent years bracing for.

The partner list is the tell. AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, NVIDIA, Palo Alto Networks and the Linux Foundation signed on as the named partners in a program of roughly 50 organizations — competitors who rarely share a security effort, joined by the calculation that a catastrophic exploit in any of their codebases is a shared problem. "For most partners, we estimate that a major attack could affect more than 100 million people," Anthropic wrote.

The headline demonstration: Mythos autonomously located and then exploited a remote-code-execution bug in FreeBSD that had sat undiscovered for 17 years, now triaged as CVE-2026-4747. The same capability that lets a defender clear a 17-year-old flaw in an afternoon lets an attacker weaponize the next one before a patch exists. Anthropic is racing to put the tool in defenders' hands first; nothing guarantees the order holds, and the company has been blunt that the same model class is exactly what a well-resourced attacker would want.

The program is now scaling to about 150 organizations across more than 15 countries, reaching into power, water, healthcare and communications infrastructure — the systems where a single unpatched bug stops being an IT ticket and becomes a public-safety event. It lands in the same stretch the industry has spent arguing over what AI coding tools are worth, from SpaceX's $60 billion bid for Cursor to Meta's custom AI silicon. Glasswing is the same class of technology pointed at a harder question than developer productivity: whether the people defending critical systems can stay ahead of the people attacking them. For now Anthropic controls who gets access — but Mythos is a preview of a capability that will not stay scarce.

Anthropic pointed the same Claude Mythos research line at a different problem in July, when Claude Mythos Preview found new attacks against the HAWK post-quantum signature scheme and a reduced-round version of AES.

Source: Anthropic, TechCrunch, The Hacker News

Comments

Get tomorrow's roundup. Free.

One email each morning. Sneakers, sports, culture, tech.

Link copied