Anthropic's Unreleased Claude Mythos AI Uncovers Decades-Old Linux and OpenBSD Bugs, Launches Project Glasswing

Anthropic's Unreleased Claude Mythos AI Uncovers Decades-Old Linux and OpenBSD Bugs, Launches Project Glasswing

N
News Editor 01
2026-07-09 00:34:15
Anthropic's Claude Mythos Preview autonomously discovered thousands of zero-day vulnerabilities across major OS and browsers, including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw. The company launches Project Glasswing, a defensive coalition backed by up to $100 million in AI credits.
AnthropicClaude Mythoszero-day vulnerabilitycybersecurityProject Glasswing

Anthropic officially announced its unreleased AI model, Claude Mythos Preview, on April 7, 2026, revealing breakthrough cybersecurity benchmark scores and the autonomous discovery of thousands of zero-day vulnerabilities across all major operating systems and web browsers. The development prompted Anthropic to launch Project Glasswing, a defensive cybersecurity coalition supported by 11 founding partners and up to $100 million in Mythos usage credits.

Claude Mythos: A Leap in AI Capability

Anthropic describes Claude Mythos as the largest single-model capability leap in frontier AI history. On the Cybergym benchmark, Mythos scored 83.1%, compared to Claude Opus 4.6's 66.6%. On SWE-bench Verified, it achieved 93.9% versus 80.8%, and on SWE-bench Pro, 77.8% versus 53.4% — a 24-point gap. On Humanity's Last Exam without tools, it reached 56.8% versus 40.0% for its predecessor. These gains stem from broader advances in reasoning, multi-step planning, and autonomous agent behavior, not specialized cybersecurity training.

The model operates by reading target source code inside an isolated container, forming hypotheses about memory safety defects, compiling and running the software, using debuggers like Address Sanitizer, ranking files by vulnerability likelihood, and producing validated bug reports with functional proof-of-concept exploits.

Discoveries That Humans Missed for Decades

Among the most striking findings: a 27-year-old OpenBSD TCP SACK integer overflow that allows a remote attacker to crash any host via malicious packets — discovered autonomously after roughly 1,000 runs at a total cost under $20,000. A 16-year-old FFmpeg H.264 bug survived over five million automated tests and multiple audits before Mythos detected it.

In browser testing, Mythos generated 181 complete shell exploits and 29 register control cases against Firefox 147's JavaScript engine, while Claude Opus 4.6 produced only two shell exploits. The model also built functional privilege escalation chains from user to root in the Linux kernel, filtering 100 recent CVEs down to 40 exploitable candidates and successfully exploiting more than half.

Human validators reviewed 198 of the model's vulnerability reports and agreed with its severity assessments in 89% of cases, with 98% agreement within a single severity level.

Project Glasswing: Turning Offense into Defense

To manage the dual-use risk of such powerful capabilities, Anthropic launched Project Glasswing on April 7, 2026. Founding partners include Amazon Web Services, Apple, Broadcom, Cisco, Crowdstrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Access is extended to over 40 additional critical software organizations.

Anthropic committed $4 million in donations to open-source security: $2.5 million to Alpha-Omega via OpenSSF through the Linux Foundation, and $1.5 million to the Apache Software Foundation. The company acknowledged that AI tools like Mythos lower the barrier for vulnerability discovery and exploitation, warning of near-term risks from state actors in China, Iran, North Korea, Russia, and criminal groups if similar capabilities spread unchecked.

As of the announcement, less than 1% of identified bugs have been fully patched. Anthropic is coordinating responsible disclosure, publishing SHA-3 cryptographic commitments for unpatched issues and adhering to a 90-plus-45-day timeline before releasing full details. The 17-year-old FreeBSD NFS server remote code execution bug (CVE-2026-4747), granting full unauthenticated root access, is among examples already in disclosure.

Future versions of Claude Opus will include safeguards to detect and block dangerous cybersecurity outputs, and Anthropic plans to introduce a cyber vetting program for verified security professionals. A public report on partner findings and patched vulnerabilities is expected within 90 days.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.