Anthropic's Unreleased AI Claude Mythos Uncovers Decades-Old Zero-Day Flaws in Linux and OpenBSD

Anthropic's Unreleased AI Claude Mythos Uncovers Decades-Old Zero-Day Flaws in Linux and OpenBSD

N
News Editor 01
2026-07-09 00:30:14
Anthropic's unreleased Claude Mythos Preview AI achieved 83.1% on Cybergym, autonomously discovering thousands of zero-day vulnerabilities including a 27-year-old OpenBSD TCP SACK bug and a 16-year-old FFmpeg error. The company launched Project Glasswing with $100M in AI credits for defenders.
AnthropicClaude Mythoszero-day vulnerabilitycybersecurityAI safety

On April 9, 2026, Anthropic revealed that its unreleased Claude Mythos Preview AI model has achieved a breakthrough in autonomous vulnerability discovery. Scoring 83.1% on the Cybergym cybersecurity benchmark, the model identified thousands of zero-day vulnerabilities across all major operating systems and web browsers. Most notably, it uncovered a 27-year-old integer overflow in OpenBSD's TCP SACK handler and a 16-year-old H.264 bug in FFmpeg—flaws that had survived millions of automated tests and multiple human audits.

Capability Leap: From $80K to $20K Cost for Zero-Day Discovery

Claude Mythos represents the largest single-model capability jump in frontier AI history, according to Anthropic. Compared to its predecessor Claude Opus 4.6, Mythos scored 93.9% vs. 80.8% on SWE-bench Verified, 77.8% vs. 53.4% on SWE-bench Pro, and 56.8% vs. 40.0% on Humanity's Last Exam without tools. The model does not require specialized cybersecurity training; its gains come from improved reasoning, multi-step planning, and autonomous agent behavior.

In practical tests, Mythos generated 181 full shell exploits and 29 register control cases against Firefox 147's JavaScript engine, while Opus 4.6 produced only 2 shell exploits. It also built functional Linux kernel privilege escalation chains from user to root, filtering 100 recent CVEs down to 40 exploitable candidates and successfully exploiting more than half. Human validators reviewed 198 vulnerability reports and agreed with the model's severity ratings in 89% of cases, with 98% agreement within one severity level.

The 27-year-old OpenBSD bug: a subtle integer overflow allowing remote attackers to crash any host via malicious packets. Mythos found it after approximately 1,000 runs at a total cost under $20,000. The 16-year-old FFmpeg error had survived over five million automated tests and multiple audits before detection.

Project Glasswing: $100M Credit Pool with 11 Founding Partners

To turn these capabilities toward defense, Anthropic launched Project Glasswing on April 7, 2026, committing up to $100 million in Mythos usage credits for defenders. Founding partners include Amazon Web Services, Apple, Broadcom, Cisco, Crowdstrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks, plus over 40 additional critical software organizations. The company also donated $4 million to open-source security: $2.5 million to Alpha-Omega via OpenSSF and $1.5 million to Apache Software Foundation.

Currently, less than 1% of identified bugs have been fully patched. Anthropic follows responsible disclosure with SHA-3 cryptographic commitments and a 90-plus-45-day window before publishing full details. Already disclosed is CVE-2026-4747, a 17-year-old unauthenticated root remote code execution in FreeBSD's NFS server.

Anthropic acknowledged that AI tools like Mythos lower barriers for vulnerability discovery and exploitation, warning of short-term risks from state actors (China, Iran, North Korea, Russia) and criminal groups. The company plans to embed cybersecurity safeguards in future Claude Opus versions and introduce a cyber-vetting program for verified security professionals. A public report on partner findings and remediated vulnerabilities is expected within 90 days.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.