Anthropic’s Unreleased Claude Mythos Finds Critical Linux and Browser Zero-Days, Sparks $100 Million Defense Initiative

Anthropic’s Unreleased Claude Mythos Finds Critical Linux and Browser Zero-Days, Sparks $100 Million Defense Initiative

N
News Editor 01
2026-07-09 00:32:17
Anthropic says its unreleased Claude Mythos model autonomously uncovered thousands of serious zero-day vulnerabilities across major operating systems and browsers, prompting the launch of Project Glasswing with up to $100 million in AI credits for defenders.
AnthropicAICybersecurityZero-DayOpen-Source Security

Anthropic has revealed that Claude Mythos, an unreleased preview model restricted to a small set of partners, demonstrated an unusually strong ability to discover severe software flaws across major operating systems and web browsers. According to the company’s disclosed results, the model identified thousands of high-severity zero-day vulnerabilities and did so at a pace that Anthropic says exceeds both prior AI systems and many traditional human-led workflows. In response, the company announced Project Glasswing, a defensive cybersecurity coalition backed by up to $100 million in Mythos usage credits for security teams and institutions focused on critical software infrastructure.

A major jump in cyber capability

Anthropic framed Claude Mythos as one of its largest single-model capability jumps to date. The company said the model finished training before being publicly announced on April 7, 2026, after internal details had reportedly leaked in late March through a misconfigured content management system that exposed roughly 3,000 internal files. Despite the attention, Anthropic has not released Mythos to the public and has not made it available through its general API. Instead, access remains tightly controlled because the model proved capable of not only finding unknown bugs but also exploiting them in ways that raised immediate security concerns.

On published benchmarks, Mythos posted results that materially outperformed Claude Opus 4.6. It scored 83.1% on Cybergym, versus 66.6% for Opus 4.6. On SWE-bench Verified, Mythos reached 93.9%, compared with 80.8% for its predecessor. On SWE-bench Pro, it achieved 77.8% against 53.4%, a gain of 24.4 percentage points. On Humanity’s Last Exam without tools, it scored 56.8%, ahead of Opus 4.6’s 40.0%. Anthropic said these improvements were not the result of narrow cybersecurity fine-tuning. Instead, it attributed the gains to broader improvements in reasoning, multi-step planning, and autonomous agent behavior.

How Mythos reportedly finds vulnerabilities

Anthropic described a workflow in which Claude Mythos receives a target codebase inside an isolated container, reads source code, forms hypotheses about memory-safety or logic flaws, compiles and executes software, uses debugging tools such as Address Sanitizer, prioritizes files by likelihood of vulnerability, and then produces bug reports backed by working proof-of-concept exploits. The implication is that the model can carry out large portions of a vulnerability research cycle with limited human intervention, especially in environments where the software and toolchain are already prepared for testing.

Some of the examples cited in the report are especially notable because they involve bugs that had persisted for years or even decades. One case involved an OpenBSD TCP SACK vulnerability that had reportedly existed for 27 years. The flaw was described as a subtle integer overflow allowing a remote attacker to crash any responding host by crafting malicious packets. According to reporting cited by the source material, Mythos discovered the issue autonomously after around 1,000 runs, at a total cost of less than $20,000. Another example involved a 16-year-old FFmpeg H.264 bug that had survived more than 5 million automated tests and multiple audits before Mythos identified it.

Browser exploitation and Linux privilege escalation

The browser-related findings drew particular attention. In tests on the JavaScript engine in Firefox 147, Mythos reportedly generated 181 complete shell exploits and 29 register-control cases. In the same testing set, Claude Opus 4.6 generated only two shell exploits. That contrast suggests not just stronger bug-finding ability but a significantly more effective path from identifying a weakness to constructing a practical exploit.

Anthropic also said Mythos built working privilege-escalation chains in the Linux kernel, moving from ordinary user permissions to root access on servers. In one disclosed workflow, the model filtered 100 recent CVEs down to 40 exploitable candidates and then successfully exploited more than half of them. While the company did not publish full technical details for unresolved issues, the examples underscore why Anthropic has chosen to keep the system under controlled access rather than broad deployment.

To evaluate the quality of the model’s findings, human validators reviewed 198 vulnerability reports submitted by Mythos. Anthropic said reviewers agreed with the model’s severity ratings in 89% of cases, and in 98% of cases the rating was within one severity level of the human assessment. That level of agreement suggests the system is not merely generating large volumes of speculative output, but is also relatively consistent in estimating the impact of discovered flaws.

Disclosure constraints and the Glasswing response

Anthropic acknowledged that these kinds of AI systems reduce the barriers to both vulnerability discovery and exploitation. For that reason, the company said fewer than 1% of the bugs identified so far have been fully remediated, and it is coordinating responsible disclosure before more technical information is published. Its process includes posting SHA-3 cryptographic commitments for unresolved issues and following a 90-day plus 45-day disclosure timeline before releasing complete details. Among the bugs already referenced in disclosure is FreeBSD NFS server RCE CVE-2026-4747, a 17-year-old flaw that reportedly grants unauthenticated full root access.

Project Glasswing, launched alongside the Mythos announcement, is Anthropic’s attempt to steer advanced offensive-capable AI toward defense before similar tools become widely available. The founding partners named in the report include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Anthropic also said access would be extended to more than 40 additional critical software organizations, broadening the coalition’s potential role in hardening important digital infrastructure.

Beyond credits for AI usage, Anthropic committed $4 million to open-source security. Of that total, $2.5 million will go to Alpha-Omega via OpenSSF under the Linux Foundation, while another $1.5 million is earmarked for the Apache Software Foundation. The funding signals that Anthropic sees open-source software as both a strategic dependency and a high-priority surface for AI-assisted defensive work.

Why the company is limiting access

Anthropic said the near-term risk is that equivalent capabilities could eventually spread to state-backed groups and criminal organizations before defenders have fully integrated similar tools into their own workflows. The company specifically warned about the potential misuse of advanced cyber-capable AI by actors linked to China, Iran, North Korea, and Russia, as well as cybercriminal groups. In Anthropic’s view, the industry may be entering a period of transitional turbulence in which offensive discovery becomes cheaper and faster before large-scale defensive adaptation catches up.

To address that problem, Anthropic said future versions of Claude Opus will include stronger safeguards designed to detect and block dangerous cybersecurity outputs. It also plans to introduce a cybersecurity verification program so that access to more sensitive capabilities can be granted to vetted security professionals under stricter controls. The company expects to publish a public report within 90 days summarizing partner findings and documenting vulnerabilities that have since been fixed.

For now, the Claude Mythos story highlights a growing tension at the frontier of AI and cybersecurity: the same systems that can dramatically improve defense may also compress the time and cost required to uncover and weaponize software flaws. Anthropic’s answer is controlled deployment, coordinated disclosure, and a large-scale alliance model aimed at helping defenders move first. Whether that approach is sufficient will depend not only on the quality of Mythos itself, but also on how quickly the wider software ecosystem can patch longstanding weaknesses now that AI appears capable of finding them far more efficiently than before.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.